Hacker News new | ask | show | jobs
by randomv 3107 days ago
It uses the GenerateDataKey API against a single master key.

At the client side, yes, could send an SNS notification, or otherwise go indirectly via a Lambda.

Or, alternatively, stream CloudTrail logs through Lambda to achieve a similar result.