/Secrets Manager & Parameter Store
Concept Detail

Secrets Manager & Parameter Store

Difficulty: medium

Overview


AWS Secrets Manager:

  • Auto rotation for RDS, Redshift, DocumentDB. Custom rotation via Lambda.
  • Versioning: AWSCURRENT, AWSPENDING, AWSPREVIOUS labels.
  • Cross-account via resource policies.
  • Cost: $0.40/secret/month.

Parameter Store:

StandardAdvanced
Size4 KB8 KB
CostFree$0.05/param/month
TTL policiesNoYes

SecureString: Encrypted with KMS.

Hierarchy: /myapp/prod/db-password. GetParametersByPath retrieves all under a prefix.

Secrets Manager vs Parameter Store:

Secrets ManagerParameter Store
Cost$0.40/secretFree (standard)
Auto rotationBuilt-inManual (Lambda)
Best forDB creds, API keysConfig, flags, any secrets

Practice Linked Questions


medium

Q1. A developer stores an RDS database password in AWS Secrets Manager. The application retrieves it at startup. Six months later, the application breaks because the password changed. What Secrets Manager feature caused this?


Select one answer before revealing.

medium

Q2. A developer needs to store API keys, database passwords, and TLS certificates as configuration values accessible to Lambda functions. Some values are sensitive (must be encrypted); others are non-sensitive. Which service combination is recommended?


Select one answer before revealing.