provides an opinionated module to create a namespace based read role for an AWS account with access to KMS keys for the namespace and prefix; with the ability to restrict role assumption to corporate networks