diff --git a/dhall-secret.cabal b/dhall-secret.cabal
--- a/dhall-secret.cabal
+++ b/dhall-secret.cabal
@@ -1,190 +1,104 @@
 cabal-version:      3.0
--- The cabal-version field refers to the version of the .cabal specification,
--- and can be different from the cabal-install (the tool) version and the
--- Cabal (the library) version you are using. As such, the Cabal (the library)
--- version used must be equal or greater than the version stated in this field.
--- Starting from the specification version 2.2, the cabal-version field must be
--- the first thing in the cabal file.
-
--- Initial package description 'dhall-secret' generated by
--- 'cabal init'. For further documentation, see:
---   http://haskell.org/cabal/users-guide/
---
--- The name of the package.
 name:               dhall-secret
-
--- The package version.
--- See the Haskell package versioning policy (PVP) for standards
--- guiding when and how versions should be incremented.
--- https://pvp.haskell.org
--- PVP summary:     +-+------- breaking API changes
---                  | | +----- non-breaking API additions
---                  | | | +--- code changes with no API change
-version:            0.5.53
-
--- A short (one-line) description of the package.
-synopsis:           Encrypt Decrypt Dhall expressions
-
--- A longer description of the package.
-description: A simple tool to manage secrets in Dhall configuration
--- URL for the project homepage or repository.
-homepage:           https://github.com/jcouyang/dhall-secret
-
--- The license under which the package is released.
+version:            0.6.63
 license:            BSD-3-Clause
-
--- The file containing the license text.
 license-file:       LICENSE
-
--- The package author(s).
-author:             Jichao Ouyang
-
--- An email address to which users can send suggestions, bug reports, and patches.
 maintainer:         oyanglulu@gmail.com
-
--- A copyright notice.
--- copyright:
+author:             Jichao Ouyang
+homepage:           https://github.com/jcouyang/dhall-secret
+synopsis:           Encrypt Decrypt Dhall expressions
+description:        A simple tool to manage secrets in Dhall configuration
 category:           Data
 build-type:         Simple
-
--- Extra source files to be distributed with the package, such as examples, or a tutorial module.
 extra-source-files:
-        README.md
-        src/Type.dhall
-        test/*.key
-        test/*.dhall
-source-repository head
-  type: git
-  location: https://github.com/jcouyang/dhall-secret
+    README.md
+    src/Type.dhall
+    test/*.key
+    test/*.dhall
 
-common warnings
-    ghc-options: -Wall
+source-repository head
+    type:     git
+    location: https://github.com/jcouyang/dhall-secret
 
 library
-    -- Import common warning flags.
-    import:           warnings
-
-    -- Modules exported by the library.
     exposed-modules:
-          Dhall.Secret
-          Dhall.Secret.Age
-          Dhall.Secret.Aws
-          Dhall.Secret.IO
-          Dhall.Secret.Type
-    autogen-modules:
-        Paths_dhall_secret
-    -- Modules included in this library but not exported.
-    -- other-modules:
-
-    -- LANGUAGE extensions used by modules in this package.
-    -- other-extensions:
-
-    -- Other library packages from which modules are imported.
-    build-depends:    base >=4.14 && < 5
-                    , amazonka                           >= 1.6.1 && < 1.7
-                    , bytestring                         >= 0.10.12 && < 0.11
-                    , text                               >= 1.2.4 && < 1.3
-                    , unordered-containers               >= 0.2.19 && < 0.3
-                    , cryptonite                         >= 0.30 && < 0.31
-                    , memory                             >= 0.18.0 && < 0.19
-                    , pem                                >= 0.2.4 && < 0.3
-                    , lens                               >= 5.2 && < 5.3
-                    , amazonka-kms                       >= 1.6.1 && < 1.7
-                    , base64                             >= 0.3.1 && < 0.4
-                    , bech32                             >= 1.1.2 && < 1.2
-                    , dhall                              >= 1.41.2 && < 1.42
-
-    -- Directories containing source files.
-    hs-source-dirs:   src
-    other-modules:
-        Paths_dhall_secret
-
-    -- Base language which the package is written in.
-    default-language: Haskell2010
+        Dhall.Secret
+        Dhall.Secret.Age
+        Dhall.Secret.Aws
+        Dhall.Secret.IO
+        Dhall.Secret.Type
 
+    hs-source-dirs:     src
+    other-modules:      Paths_dhall_secret
+    autogen-modules:    Paths_dhall_secret
+    default-language:   Haskell2010
     default-extensions:
-      QuasiQuotes
-      TemplateHaskell
-      NamedFieldPuns
-      OverloadedStrings
-executable dhall-secret
-    -- Import common warning flags.
-    import:           warnings
-
-    -- .hs or .lhs file containing the Main module.
-    main-is:          Main.hs
-
-    -- Modules included in this executable, other than Main.
-    -- other-modules:
-
-    -- LANGUAGE extensions used by modules in this package.
-    -- other-extensions:
+        QuasiQuotes TemplateHaskell NamedFieldPuns OverloadedStrings
 
-    -- Other library packages from which modules are imported.
+    ghc-options:        -Wall
     build-depends:
-        base >=4.14 && < 5
-      , dhall-secret
-      , amazonka                           >= 1.6.1 && < 1.7
-      , bytestring                         >= 0.10.12 && < 0.11
-      , text                               >= 1.2.4 && < 1.3
-      , unordered-containers               >= 0.2.19 && < 0.3
-      , cryptonite                         >= 0.30 && < 0.31
-      , memory                             >= 0.18.0 && < 0.19
-      , pem                                >= 0.2.4 && < 0.3
-      , lens                               >= 5.2 && < 5.3
-      , amazonka-kms                       >= 1.6.1 && < 1.7
-      , base64                             >= 0.3.1 && < 0.4
-      , bech32                             >= 1.1.2 && < 1.2
-      , dhall                              >= 1.41.2 && < 1.42
-      , optparse-applicative >= 0.17.0 && < 0.18
-
-    -- Directories containing source files.
-    hs-source-dirs: app
-    other-modules:
-        Paths_dhall_secret
+        base >=4.18.2.1 && <4.19,
+        amazonka >=2.0 && <2.1,
+        bytestring >=0.11.5.3 && <0.12,
+        text >=2.0.2 && <2.1,
+        unordered-containers >=0.2.20 && <0.3,
+        cryptonite >=0.30 && <0.31,
+        memory >=0.18.0 && <0.19,
+        pem >=0.2.4 && <0.3,
+        lens >=5.3.2 && <5.4,
+        amazonka-kms >=2.0 && <2.1,
+        base64-bytestring >=1.2.1.0 && <1.3,
+        bech32 >=1.1.7 && <1.2,
+        dhall >=1.42.1 && <1.43
 
-    -- Base language which the package is written in.
+executable dhall-secret
+    main-is:          Main.hs
+    hs-source-dirs:   app
+    other-modules:    Paths_dhall_secret
+    autogen-modules:  Paths_dhall_secret
     default-language: Haskell2010
+    ghc-options:      -Wall
+    build-depends:
+        base >=4.18.2.1 && <4.19,
+        dhall-secret,
+        amazonka >=2.0 && <2.1,
+        bytestring >=0.11.5.3 && <0.12,
+        text >=2.0.2 && <2.1,
+        unordered-containers >=0.2.20 && <0.3,
+        cryptonite >=0.30 && <0.31,
+        memory >=0.18.0 && <0.19,
+        pem >=0.2.4 && <0.3,
+        lens >=5.3.2 && <5.4,
+        amazonka-kms >=2.0 && <2.1,
+        base64-bytestring >=1.2.1.0 && <1.3,
+        bech32 >=1.1.7 && <1.2,
+        dhall >=1.42.1 && <1.43,
+        optparse-applicative >=0.18.1.0 && <0.19
 
 test-suite dhall-secret-test
-    -- Import common warning flags.
-    import:           warnings
+    type:             exitcode-stdio-1.0
+    main-is:          Spec.hs
+    hs-source-dirs:   test
     other-modules:
         Paths_dhall_secret
         Age
-
-    -- Base language which the package is written in.
+    autogen-modules:
+        Paths_dhall_secret
     default-language: Haskell2010
-
-    -- Modules included in this executable, other than Main.
-    -- other-modules:
-
-    -- LANGUAGE extensions used by modules in this package.
-    -- other-extensions:
-
-    -- The interface type and version of the test suite.
-    type:             exitcode-stdio-1.0
-
-    -- Directories containing source files.
-    hs-source-dirs:   test
-
-    -- The entrypoint to the test suite.
-    main-is:          Spec.hs
-
-    -- Test dependencies.
+    ghc-options:      -Wall
     build-depends:
-        base >=4.14 && < 5
-      , dhall-secret
-      , HUnit
-      , amazonka                           >= 1.6.1 && < 1.7
-      , bytestring                         >= 0.10.12 && < 0.11
-      , text                               >= 1.2.4 && < 1.3
-      , unordered-containers               >= 0.2.19 && < 0.3
-      , cryptonite                         >= 0.30 && < 0.31
-      , memory                             >= 0.18.0 && < 0.19
-      , pem                                >= 0.2.4 && < 0.3
-      , lens                               >= 5.2 && < 5.3
-      , amazonka-kms                       >= 1.6.1 && < 1.7
-      , base64                             >= 0.3.1 && < 0.4
-      , bech32                             >= 1.1.2 && < 1.2
-      , dhall                              >= 1.41.2 && < 1.42
+        base >=4.18.2.1 && <4.19,
+        dhall-secret,
+        HUnit,
+        amazonka >=2.0 && <2.1,
+        bytestring >=0.11.5.3 && <0.12,
+        text >=2.0.2 && <2.1,
+        unordered-containers >=0.2.20 && <0.3,
+        cryptonite >=0.30 && <0.31,
+        memory >=0.18.0 && <0.19,
+        pem >=0.2.4 && <0.3,
+        lens >=5.3.2 && <5.4,
+        amazonka-kms >=2.0 && <2.1,
+        base64-bytestring >=1.2.1.0 && <1.3,
+        bech32 >=1.1.7 && <1.2,
+        dhall >=1.42.1 && <1.43
diff --git a/src/Dhall/Secret.hs b/src/Dhall/Secret.hs
--- a/src/Dhall/Secret.hs
+++ b/src/Dhall/Secret.hs
@@ -25,12 +25,11 @@
 import           Dhall.Secret.Type       (secretTypes)
 import           Dhall.Src               (Src)
 import           GHC.Exts                (toList)
-import           Network.AWS             (send)
-import           Network.AWS.KMS         (decEncryptionContext,
-                                          eEncryptionContext)
-import qualified Network.AWS.KMS         as KMS
-import           Network.AWS.KMS.Decrypt (drsKeyId, drsPlaintext)
-import           Network.AWS.KMS.Encrypt (ersCiphertextBlob, ersKeyId)
+import           Amazonka.KMS.Decrypt         (decrypt_encryptionContext,
+                                          )
+import qualified Amazonka.KMS         as KMS
+import           Amazonka.KMS.Decrypt (decryptResponse_keyId, decryptResponse_plaintext)
+import           Amazonka.KMS.Encrypt (encryptResponse_ciphertextBlob, encryptResponse_keyId, encrypt_encryptionContext)
 import           System.Environment      (getEnv)
 
 varName :: Expr s a
@@ -48,8 +47,8 @@
       Just ec@(RecordField _ (ListLit _ ecl) _ _)
       ) -> do
         let context = mconcat $ toList (dhallMapToHashMap <$> ecl)
-        eResp <- awsRun $ send $ KMS.encrypt kid (T.encodeUtf8 pt) & eEncryptionContext .~ context
-        case (eResp ^. ersKeyId, eResp ^. ersCiphertextBlob) of
+        eResp <- awsRun $ KMS.newEncrypt kid (T.encodeUtf8 pt) & encrypt_encryptionContext ?~ context
+        case (eResp ^. encryptResponse_keyId, eResp ^. encryptResponse_ciphertextBlob) of
           (Just _, Just cb) ->
             pure $
               App
@@ -87,8 +86,8 @@
     (Just (RecordField _ (TextLit (Chunks _ kid)) _ _), Just (RecordField _ (TextLit (Chunks _ cb)) _ _), Just ec@(RecordField _ (ListLit _ ecl) _ _)) -> do
       eResp <- case convertFromBase Base64 (T.encodeUtf8 cb) of
         Left e -> error (show e)
-        Right a -> awsRun $ send $ KMS.decrypt a & decEncryptionContext .~ mconcat (toList (dhallMapToHashMap <$> ecl))
-      case (eResp ^. drsKeyId, eResp ^. drsPlaintext) of
+        Right a -> awsRun $ KMS.newDecrypt a & decrypt_encryptionContext ?~ mconcat (toList (dhallMapToHashMap <$> ecl))
+      case (eResp ^. decryptResponse_keyId, eResp ^. decryptResponse_plaintext) of
         (Just _, Just pt) ->
           pure $ if dp'notypes opts then
            TextLit (Chunks [] (T.decodeUtf8 pt))
diff --git a/src/Dhall/Secret/Age.hs b/src/Dhall/Secret/Age.hs
--- a/src/Dhall/Secret/Age.hs
+++ b/src/Dhall/Secret/Age.hs
@@ -1,3 +1,4 @@
+{-# LANGUAGE OverloadedStrings #-}
 module Dhall.Secret.Age
   ( encrypt,
     decrypt,
@@ -7,7 +8,6 @@
     toRecipient,
   )
 where
-
 import qualified Codec.Binary.Bech32          as Bech32
 import qualified Crypto.Cipher.ChaChaPoly1305 as CC
 import           Crypto.Error                 (CryptoError (..),
@@ -23,7 +23,8 @@
 import           Data.ByteArray               (ByteArrayAccess, convert)
 import           Data.ByteString              (ByteString, intercalate)
 import qualified Data.ByteString              as BS
-import qualified Data.ByteString.Base64       as BS
+import qualified Data.ByteString.Char8              as BC
+import qualified Data.ByteString.Base64       as B64
 import           Data.Either                  (isRight)
 import           Data.List                    (find)
 import           Data.Maybe                   (fromMaybe)
@@ -132,13 +133,13 @@
   case BS.take 3 content of
     "---" ->
       let (mac', body) = BS.break isLF $ content
-       in Right $ (Header (reverse stz) (BS.decodeBase64Lenient $ BS.drop 4 mac'), BS.drop 1 body)
+       in Right $ (Header (reverse stz) (B64.decodeLenient $ BS.drop 4 mac'), BS.drop 1 body)
     "-> " ->
       let (recipients, rest1) = BS.break isLF $ BS.drop 3 content
           (fileKey, rest2) = BS.break isLF $ BS.drop 1 rest1
           (stztype, rest11) = BS.break isSpace recipients
           stzarg = BS.drop 1 rest11
-          st = Stanza {stzType = stztype, stzArgs = [stzarg], stzBody = BS.decodeBase64Lenient fileKey}
+          st = Stanza {stzType = stztype, stzArgs = [stzarg], stzBody = B64.decodeLenient fileKey}
        in parseHeader (Header (st : stz) mac) (BS.drop 1 rest2)
     _ -> Left "invalid headers"
   where
@@ -150,7 +151,7 @@
   where
     hasKey :: X25519Identity -> Stanza -> Either CryptoError ByteString
     hasKey (X25519Identity pk sec) stz = eitherCryptoError $ do
-      let theirPkBs = BS.decodeBase64Lenient $ head (stzArgs stz)
+      let theirPkBs = B64.decodeLenient $ head (stzArgs stz)
       theirPk <- X25519.publicKey theirPkBs
       let shareKey = X25519.dh theirPk sec
       let salt = (convert theirPk) <> (convert pk)
@@ -190,12 +191,12 @@
     st0 <- CC.initialize wrappingKey nonce
     let (e, st1) = CC.encrypt fileKey st0
     return $ e <> (convert $ CC.finalize st1)
-  pure Stanza {stzType = "X25519", stzBody = body, stzArgs = [BS.encodeBase64Unpadded' (convert ourPK)]}
+  pure Stanza {stzType = "X25519", stzBody = body, stzArgs = [encodeBase64Unpadded (convert ourPK)]}
 
 marshalStanza :: Stanza -> ByteString
 marshalStanza stanza =
   let prefix = "-> " :: ByteString
-      body = BS.encodeBase64Unpadded' $ stzBody stanza
+      body = encodeBase64Unpadded $ stzBody stanza
       argLine = prefix <> stzType stanza <> " " <> intercalate " " (stzArgs stanza) <> "\n"
    in argLine
         <> wrap64b body
@@ -204,7 +205,7 @@
 mkHeader :: ByteString -> [Stanza] -> ByteString
 mkHeader fileKey recipients =
   let (headerNoMac, mac) = mkHeaderMac fileKey recipients
-   in headerNoMac <> " " <> (BS.encodeBase64Unpadded' mac) <> "\n"
+   in headerNoMac <> " " <> (encodeBase64Unpadded mac) <> "\n"
 
 mkHeaderMac :: ByteString -> [Stanza] -> (ByteString, ByteString)
 mkHeaderMac fileKey recipients =
@@ -237,3 +238,6 @@
 
 payloadKey :: ByteString -> ByteString -> ByteString
 payloadKey nonce filekey = HKDF.expand (HKDF.extract nonce filekey :: PRK SHA256) ("payload" :: ByteString) 32
+
+encodeBase64Unpadded :: ByteString -> ByteString
+encodeBase64Unpadded = BC.takeWhile (/= '=') . B64.encode
diff --git a/src/Dhall/Secret/Aws.hs b/src/Dhall/Secret/Aws.hs
--- a/src/Dhall/Secret/Aws.hs
+++ b/src/Dhall/Secret/Aws.hs
@@ -1,24 +1,12 @@
+{-# LANGUAGE FlexibleContexts #-}
 module Dhall.Secret.Aws where
 
-import           Control.Lens             ((&), (.~))
-import           Data.Text                (pack)
-import           Network.AWS              (AWS, Credentials (Discover),
-                                           HasEnv (envLogger), LogLevel (Info),
-                                           envRegion, newEnv, newLogger, runAWS,
-                                           runResourceT)
-import           Network.AWS.Data         (fromText)
-import           System.Environment.Blank (getEnv)
+import Data.Typeable (Typeable)
+import         qualified  Amazonka
 import           System.IO                (stdout)
 
-awsRun :: Network.AWS.AWS b -> IO b
+awsRun ::  (Amazonka.AWSRequest a, Typeable a, Typeable (Amazonka.AWSResponse a)) => a -> IO (Amazonka.AWSResponse a)
 awsRun cmd = do
-  logger <- Network.AWS.newLogger Network.AWS.Info stdout
-  discover <- Network.AWS.newEnv Network.AWS.Discover
-  defaultRegion <- getEnv "AWS_REGION"
-  Network.AWS.runResourceT $ Network.AWS.runAWS (case (hush . fromText . pack) =<< defaultRegion of
-    Nothing     -> discover & Network.AWS.envLogger .~ logger
-    Just region -> discover & Network.AWS.envRegion .~ region & Network.AWS.envLogger .~ logger)
-    cmd
-  where
-    hush (Left _)  = Nothing
-    hush (Right x) = Just x
+  logger <- Amazonka.newLogger Amazonka.Info stdout
+  discover <- Amazonka.newEnv Amazonka.discover
+  Amazonka.runResourceT $ Amazonka.send (discover { Amazonka.logger =logger}) cmd
diff --git a/test/example02.dhall b/test/example02.dhall
--- a/test/example02.dhall
+++ b/test/example02.dhall
@@ -1,4 +1,4 @@
-let T = https://oyanglul.us/dhall-secret/Type.dhall
+let T = https://gh.1punch.dev/dhall-secret/Type.dhall
 
 in  { foo =
       { ageSecret =
