How it works...
In this recipe, we stored credentials for our RDS database in Secrets Manager. For the secret type, we selected Credentials for RDS database. The following are the other secret types currently available in the console: Credentials for Redshift cluster, Credentials for DocumentDB database, Credentials for other database, and Other type of secrets (e.g. API key).
We enabled automatic key rotation with a duration of 30 days. We can also select 60 days or 90 days, or provide a custom period of time up to 365 days. I selected the DefaultEncryptionKey for this recipe. Instead, you can use a KMS key you created. We learned about KMS keys in Chapter 4, Key Management with KMS and CloudHSM.
After configuring a secret, our application ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access