hiera-eyaml-kms <https://github.com/adenot/hiera-eyaml-kms> is a good solution that uses AWS KMS to manage encryption keys. EC2 instances can be provisioned with an IAM instance profile that grants access to the required keys.
-- You received this message because you are subscribed to the Google Groups "Puppet Users" group. To unsubscribe from this group and stop receiving emails from it, send an email to puppet-users+unsubscr...@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/puppet-users/261e20fe-604b-484b-b6e9-94b5550b3932%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.