AWS Secrets Manager
E293783
AWS Secrets Manager is a managed cloud service for securely storing, rotating, and managing access to sensitive information such as API keys, passwords, and database credentials.
All labels observed (1)
| Label | Occurrences |
|---|---|
| AWS Secrets Manager canonical | 6 |
Statements (62)
| Predicate | Object |
|---|---|
| instanceOf |
AWS service
ⓘ
cloud service ⓘ secrets management service ⓘ |
| accessedBy |
AWS CLI
ⓘ
AWS SDKs ⓘ REST API ⓘ |
| billingModel | pay-as-you-go ⓘ |
| competitor |
Azure Key Vault
ⓘ
Google Secret Manager ⓘ HashiCorp Vault ⓘ |
| deploymentModel | managed service ⓘ |
| developer | Amazon Web Services ⓘ |
| hasFeature |
audit logging
ⓘ
fine-grained access control ⓘ integration with VPC endpoints ⓘ secret policy documents ⓘ secret replication across regions ⓘ secret rotation schedule ⓘ |
| integratesWith |
AWS CLI
ⓘ
AWS CloudFormation ⓘ AWS Identity and Access Management ⓘ AWS Key Management Service ⓘ AWS Lambda ⓘ AWS Management Console ⓘ AWS SDKs ⓘ Amazon DocumentDB ⓘ Amazon EC2 ⓘ Amazon ECS ⓘ Amazon Elastic Kubernetes Service ⓘ
surface form:
Amazon EKS
Amazon RDS ⓘ Amazon Redshift ⓘ |
| partOf |
AWS security services
ⓘ
Amazon Web Services ⓘ |
| provider | Amazon Web Services ⓘ |
| regionScope | available in multiple AWS regions ⓘ |
| securityGoal |
centralize secret management
ⓘ
protect sensitive configuration data ⓘ reduce hard-coding of secrets in code ⓘ |
| stores |
API keys
ⓘ
OAuth tokens ⓘ SSH keys ⓘ TLS certificates ⓘ database credentials ⓘ passwords ⓘ |
| supports |
CloudTrail logging of API calls
ⓘ
Amazon EventBridge ⓘ
surface form:
CloudWatch Events / EventBridge
CloudWatch metrics ⓘ access management for secrets ⓘ automatic rotation of secrets ⓘ cross-account access via resource-based policies ⓘ encryption at rest ⓘ encryption in transit ⓘ secret rotation using AWS Lambda ⓘ secure storage of secrets ⓘ tagging of secrets ⓘ versioning of secrets ⓘ |
| typicalUseCase |
managing database credentials for applications
ⓘ
rotating API keys automatically ⓘ storing third-party service credentials ⓘ |
| uses |
AWS KMS customer master keys
ⓘ
IAM policies ⓘ resource-based policies ⓘ |
Referenced by (6)
Full triples — surface form annotated when it differs from this entity's canonical label.