AtfKms creates CMKs defaulting to key rotation on, aliased. DataStack writes kms/{baseName}/keyArn and keyId to SSM.
When to reach for it
Section titled “When to reach for it”Use it for encryption keys you own. Note: there is no DataStack hook to use a created key as a Dynamo/S3 encryptionKey today — wire that in raw CDK. See Storage & Encryption.
Composition
Section titled “Composition”Composed by DataStack (DATA_STACK_IDS.kms).
Props & API
Section titled “Props & API”AtfKms extends its CDK counterpart, and its props extend Omit<CdkProps> — every CDK prop the framework doesn’t own is available directly, with full autocomplete. The complete, always-current prop interface is generated from the source in the API reference. See also Axis IS CDK for the extend-never-wrap contract.
© 2026 Axis Tech. Powered by axis-tech.co.