I\'m trying to create an IAM role that will be used to launch a CloudFormation stack. Part of the CloudFormation stack will create a KMS key and alias, however I don\'t want