I've made some changes to support KMS encryption. You can just provide a _kmsKeyId_ and it'll set everything up. Is this interesting enough to warrant a PR?