Blenra LogoBlenra
Optimized for: Gemini / ChatGPT / Claude
#Security

Advanced AI Prompt for Scoped AWS KMS Key Policy for Multi-Account Access

Customize the variables below to instantly engineer your prompt.

Required Variables

advanced-ai-prompt-kms-key-policy-multi-account.txt
Act as a Cloud Cryptography Architect. Draft an advanced AWS KMS Key Policy that strictly separates administration from cryptographic usage. Grant the principal [KEY_ADMIN_ARN] full administrative rights (`kms:*`). Allow the external account [EXTERNAL_ACCOUNT_ID] to utilize the key for `kms:Encrypt` and `kms:Decrypt` operations, but *only* if the cryptographic request explicitly includes a specific `kms:EncryptionContext:[ENCRYPTION_CONTEXT_KEY]` that exactly matches '[VALUE]'. Explain in the comments how enforcing this Encryption Context mathematically ensures that even if the external account's IAM role is compromised, the KMS key cannot be utilized to decrypt ciphertexts without knowing the exact context string.

Example Text Output

"The AI generates a KMS policy JSON that uses 'kms:EncryptionContext' as a mandatory cryptographic guardrail."

More Cloud & DevOps Prompts

View all →

Frequently Asked Questions

What is the "Advanced AI Prompt for Scoped AWS KMS Key Policy for Multi-Account Access" prompt used for?

The AI generates a KMS policy JSON that uses 'kms:EncryptionContext' as a mandatory cryptographic guardrail.

Which AI tools work with this prompt?

This prompt is optimized for Gemini / ChatGPT / Claude, but works great with ChatGPT, Claude, Gemini, and other large language models. Simply copy it and paste it into your preferred AI tool.

How do I customize this prompt?

Use the variable fields above to fill in your specific details. The prompt will auto-update as you type, ready to copy instantly.

Is this prompt free?

Yes! All prompts on Blenra are free to copy and use immediately. No account required.