Set Up AWS Secrets Manager

Rotation included.

Overview

AWS Secrets Manager is the managed-secrets path with rotation built in. The four properties below are what justify its cost over rolling your own KMS-plus-DynamoDB story.

The approach

Three habits keep Secrets Manager operationally sound: rotation is the default, IAM controls access, and the rotation policy is documented per secret.

Why this compounds

Each rotated secret shrinks the blast radius of any credential leak. The compounding works because rotation lifetimes are measured in days or hours, not the years static credentials accumulate.