I am using elasticache ReplicationGroup with atRestEncryptionEnabled=true and kmsId of key created in same stack.
It seems like on every pulumi up (even when not changing anything at all) it identifies [diff: ~kmsKeyId] and decides to replace the replication group. I tested it many times and quite sure its consistent. Is it a known issue? I don't like the idea of ignoring the kmsId