* s3_bucket: Allow empty encryption_key_id with aws:kms to use KMS master key * Add idempotency check and cleanup example, dont require encryption_key_id