The policy [here](https://github.com/terraform-ibm-modules/terraform-ibm-icd-postgresql/blob/c32c49c15f29562e9b07a806301cf6b80a53d37c/main.tf#L37-L45) can be updated to scope it to the exact KMS key. For an example of the syntax, see https://github.com/terraform-ibm-modules/terraform-ibm-cos/pull/764