Reference¶
Facts, checked against the implementation.
- IAM actions — what each AWS KMS role must be granted, and what it must not be.
- Environment variables — what the integration tests read.
The Go API — types, functions, sentinel errors — is on pkg.go.dev, generated from the source and unable to drift from it. The AWS KMS provider's API is at pkg.go.dev.