# AWS Secrets Manager

> AWS Secrets Manager stores, retrieves and automatically rotates database credentials, API keys and other secrets, encrypted with AWS KMS.

- Source: https://www.itwonderlab.com/aws-secrets-manager/
- Published: 2026-10-05
- Updated: 2026-10-05
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

**AWS Secrets Manager** is a managed service to store and retrieve secrets such as database passwords, API keys and tokens, so they do not have to be written in the code, in configuration files or in the Terraform state.

### Key concepts

- **Secret**: a value (text or JSON) with a name, encrypted with a [KMS](https://www.itwonderlab.com/aws-kms/) key. It keeps versions, identified by the labels `AWSCURRENT` and `AWSPREVIOUS`.
- **Automatic rotation**: a [Lambda](https://www.itwonderlab.com/aws-lambda/) function changes the password periodically in the secret and in the database. Rotation is built in for [RDS](https://www.itwonderlab.com/aws-rds/), Aurora, Redshift and DocumentDB.
- **Access control** with [IAM](https://www.itwonderlab.com/aws-iam/) policies and, optionally, resource policies, including cross-account access. Every read is logged in [CloudTrail](https://www.itwonderlab.com/aws-cloudtrail/).
- **Managed master passwords**: RDS can create and rotate the admin password of a database in Secrets Manager without anyone seeing it.
- **Replication** of secrets to other Regions.
- **Secrets Manager or Parameter Store?** [Systems Manager Parameter Store](https://www.itwonderlab.com/aws-systems-manager/) is cheaper for configuration values and simple secrets. Secrets Manager adds rotation, replication and cross-account sharing.

### Pricing

A charge per secret per month plus a charge per 10,000 API calls. See the [Secrets Manager pricing](https://aws.amazon.com/secrets-manager/pricing/).

### With Terraform

The resources are `aws_secretsmanager_secret`, `aws_secretsmanager_secret_version` and `aws_secretsmanager_secret_rotation`. The data sources `aws_secretsmanager_secret_version` read a value. Be aware that values read or written by Terraform end up in the **state file**: use `manage_master_user_password = true` in `aws_db_instance`, which keeps the password out of the state, and protect and encrypt the state.

See tutorials:

-   [AWS with Terraform: The Essential Guide (13/21) – AWS RDS](https://www.itwonderlab.com/aws-terraform-tutorial-aws-rds/)
-   [AWS with Terraform Tutorial: Terraform Backends (19)](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-backends/)
