For security purposes, use of the server side encryption flag would be very handy as another option to pass in. Wasn't sure on preferred mode of injection, but seems like a simple change.
http://docs.aws.amazon.com/cli/latest/reference/s3/sync.html
[--sse ]
[--sse-c ]
[--sse-c-key ]
[--sse-kms-key-id ]
[--sse-c-copy-source ]
[--sse-c-copy-source-key ]