The docs for kms_key_id needed to be next to encrypt_boot. Shortened some of the kms_key_id error messages.