Skip to content

Developer portal

AWS KMS flip

Controlled alias and key lifecycle orchestration — no private key export.

Last updated: 2026-06-09

IAM roles

Use separate roles: read-only (aws-readonly-policy.json) and flip (aws-kms-flip-policy.json). Flip role denies Decrypt and GetPublicKey export.

Prod governance

  • Enterprise tier required for prod KMS flip
  • Two-person approval: approver ≠ submitter
  • 24h cooldown between prod KMS flips per tenant
  • Rollback: revert alias to previousKeyId in job result