SimAWSby ShahriarLabs
Search

AWS Secrets Manager

Secrets Manager

You need to store, retrieve, and automatically rotate database credentials, API keys, and private tokens securely.

Regional serviceConcept reference · no service console simulation

Reach for it when

  • Retrieving database passwords at application runtime rather than hardcoding them in configuration files.
  • Automatically rotating RDS database credentials every 30 days using built-in integration templates.
  • Sharing API tokens securely across multiple ECS containers and Lambda functions.

Do not reach for it when

  • Storing simple, non-sensitive configuration parameters like environment names — use Systems Manager Parameter Store instead.
  • Managing the cryptographic master keys used for low-level data encryption — use KMS instead.
  • Hosting a runtime configuration database that requires frequent sub-millisecond writes — use DynamoDB instead.

Alternatives, and how to choose

ServicePick it instead when
Parameter StoreChoose it when you need a low-cost or free service to store non-sensitive configuration settings.
KMSChoose it when you need to manage cryptographic keys rather than plaintext secret strings.

How you pay

The model
Pay a flat monthly fee per secret stored, plus fees per 10,000 secret API retrieval requests.
The line item that surprises people
Storing hundreds of individual microservice configurations as separate secrets will run up a high flat-rate monthly bill.

What trips people up

  • Retrieving secrets on every application request causes latency; you must implement local caching of secret values.
  • Deleting a secret immediately defaults to a recovery window; you cannot recreate a secret with the same name during this time.
  • Automatic rotation requires a Lambda function; if the Lambda fails or lacks network paths, rotation will silently fail.

Verify the live service

This page is a concept reference. Cost models are qualitative; confirm the current offering, Region and pricing before deploying.