Developer portal
AWS KMS flip
Controlled alias and key lifecycle orchestration — no private key export.
Last updated: 2026-06-09
IAM roles
Use separate roles: read-only (aws-readonly-policy.json) and flip (aws-kms-flip-policy.json). Flip role denies Decrypt and GetPublicKey export.
Prod governance
- Enterprise tier required for prod KMS flip
- Two-person approval: approver ≠ submitter
- 24h cooldown between prod KMS flips per tenant
- Rollback: revert alias to
previousKeyIdin job result
Found an issue? Report documentation feedback