Glossary

    Secrets Rotation

    Data Protection

    Secrets Rotation is the practice of automatically changing credentials on a regular schedule. AWS Secrets Manager provides native rotation support for many secret types.

    Native Rotation Support

    • RDS Databases: MySQL, PostgreSQL, MariaDB, Oracle, SQL Server, Aurora (single-user and alternating-user strategies)
    • Redshift: cluster admin passwords
    • DocumentDB: database passwords
    • Custom Secrets: Lambda rotation function for any secret type (API keys, OAuth tokens, SSH keys)

    Rotation Strategies

    • Single-user: update the password for one user; brief interruption during rotation
    • Alternating-user: maintain two users, rotate between them; zero downtime
    • Managed rotation (since 2024): managed rotation for RDS without Lambda functions

    Best Practices

    • Rotate every 30-90 days depending on sensitivity
    • Applications should always fetch secrets at runtime (not cache indefinitely)
    • Test rotation in non-production environments first
    • Monitor rotation failures with CloudWatch alarms

    Related AWS Services

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.