``` const policyDoc = pulumi.all([kmsKey.arn, keyB...
# general
s
Copy code
const policyDoc = pulumi.all([kmsKey.arn, keyBucket.arn])
            .apply(([kmsARN, bucketARN]) => {
                const policy: aws.iam.PolicyDocument = {
                    Version: "2012-10-17",
                    Statement: [
                        {
                            Sid: "AllowEncryptDecrypt",
                            Effect: "Allow",
                            Action: [
                                "kms:Encrypt",
                            ],
                            Resource: [
                                kmsARN,    // This is a reified string
                            ],
                        },