Using AWS Console, the process to create an encrypted Aurora MySQL-compatible cluster using an un-encrypted snapshot is fairly simple.
You can't convert an unencrypted DB cluster to an encrypted one. However, you can restore an unencrypted snapshot to an encrypted Aurora DB cluster. To do this, specify a KMS key when you restore from the unencrypted snapshot.
However, when using CDK, there is no parameter to provide an encryption key for the class rds.DatabaseClusterFromSnapshot
What is the CDK based solution for this scenario?