Product boundary
Whether AWS-native identity, versions, rotation integration, and service placement outweigh multi-cloud portability and metered use.
AWS Secrets Manager stores secret values and versions and integrates access, monitoring, replication, and rotation within AWS. It does not rotate every target by itself, replace IAM design, or remove Lambda, KMS, network, region, recovery, and application availability decisions.12
For: Teams whose protected workloads, identities, and operational controls already live primarily in AWS
- Protected workloads are no longer AWS-centered
- A cross-platform control plane becomes necessary
- Rotation, KMS, regional, API, or migration cost changes the fit