#!/usr/bin/env bash BUCKET=abc/def REGION=us-east-1 PROFILE=my_profile for key in "vault-root" "vault-unseal-0" "vault-unseal-1" "vault-unseal-2" "vault-unseal-3" "vault-unseal-4" do aws s3 cp s3://${BUCKET}/${key} . --profile "$PROFILE" --region "$REGION" aws kms decrypt \ --region ${REGION} \ --profile ${PROFILE} \ --ciphertext-blob fileb://${key} \ --encryption-context Tool=bank-vaults \ --output text \ --query Plaintext | base64 -d > ${key}.txt rm ${key} done