Region Support for dr Command
Turns out that KMS keys are region specific, despite all keys being returned in non-region specific boto3 calls :/ This isn't an issue until you run into RDS and S3 resources residing in different regions with the
dr transfer subcommand.
The shared KMS key created will then reside in a region that makes it inaccessible to the resource you're trying to (re-)encrypt.
Create a KMS key in every region there are resources to recrypt, and ensure the recrypt methods use those region specific appropriate keys.