Ellipse Gradient for Header

AWS Secrets Manager Integration Guide

Connect AWS Secrets Manager with enterprise workflows by retrieving, rotating, governing, and securely distributing secrets through its signed AWS service API and event ecosystem.

AWS Secrets Manager integration options at a glance

AWS Secrets Manager exposes a JSON service API over HTTPS for creating, retrieving, updating, rotating, listing, and deleting secrets. Requests generally require AWS Signature Version 4 authentication with IAM credentials, roles, or temporary STS credentials. Martini can consume these operations through a workflow using an AWS SDK or reusable custom JVM implementation where appropriate. Selected service and CloudTrail activity can be routed through Amazon EventBridge for event-driven processing, while scheduled workflows can poll metadata with ListSecrets or DescribeSecret. BatchGetSecretValue supports multi-secret retrieval, and AWS KMS, CloudWatch, and PrivateLink can provide related encryption, monitoring, and private-connectivity controls.

Integration pointSupported by AWS Secrets Manager?Common use casesHow Martini supports it
AWS JSON service API over HTTPSLimitedUse operations such as GetSecretValue, CreateSecret, PutSecretValue, DescribeSecret, ListSecrets, RotateSecret, and DeleteSecret to manage secrets and metadata. AWS does not describe this interface as a conventional REST resource API.Martini can consume the HTTPS API from workflows. An AWS SDK or reusable custom JVM implementation can help resolve credentials and perform SigV4 signing.
Authentication and authorizationYesIAM roles, IAM users, temporary STS credentials, IAM policies, resource-based policies, KMS permissions, and SigV4 govern access to secrets and operations.Martini can use securely configured AWS credentials or role-based runtime access and can apply least-privilege workflow boundaries.
EventBridge and CloudTrail eventsLimitedSelected Secrets Manager service events and CloudTrail API activity can be routed through Amazon EventBridge for event-driven processing. This is not a universal secret-change webhook.Martini can process events delivered through an approved AWS event delivery path and then retrieve current state before acting.
BatchGetSecretValueLimitedRetrieve multiple secrets in one batch operation where IAM permissions and service limits allow it. Individual retrieval failures still require explicit handling.Martini can orchestrate batch requests, validate partial results, and route failed or unauthorized secret lookups separately.
Scheduled synchronizationYesScheduled calls to ListSecrets, DescribeSecret, or ListSecretVersionIds can maintain an inventory or detect metadata and rotation changes.Martini scheduler-triggered workflows can paginate through results, compare checkpoints, and synchronize non-sensitive metadata.
AWS KMS encryptionYesSecrets can use AWS-managed or customer-managed KMS keys, with additional key permissions required for encrypted secret access.Martini workflows can operate within IAM and KMS authorization boundaries and classify KMS failures separately from missing-secret errors.
Private connectivityYesAWS PrivateLink interface VPC endpoints can provide private network access to Secrets Manager from supported VPC environments.Martini deployment and endpoint configuration can be aligned with the network path and region required by the AWS account.

How AWS Secrets Manager exposes data and business events

AWS Secrets Manager API

AWS Secrets Manager provides a JSON service API over HTTPS. Core operations include GetSecretValue, BatchGetSecretValue, CreateSecret, PutSecretValue, DescribeSecret, ListSecrets, RotateSecret, and version-management operations. Calls generally require SigV4 signing and IAM authorization.

Martini implementation pattern

Martini implementation pattern: Martini invokes the required AWS operation from a workflow using an AWS SDK or reusable custom JVM implementation where appropriate. The workflow resolves the region and credential context, retrieves or updates the resource, validates the response, and passes only the necessary fields to the next step.

Implementation sequence

Resolve the AWS region and IAM credential context
Create a SigV4-signed service request or invoke the AWS SDK
Call the required Secrets Manager operation
Validate authorization, KMS, and resource responses
Parse and map the result without exposing sensitive values
Apply bounded retries for throttling and transient failures

EventBridge and CloudTrail events

Secrets Manager does not provide a generic webhook for every secret update. Selected service events and CloudTrail API activity can be routed through Amazon EventBridge for event-driven processing, subject to the event coverage and account configuration.

Martini implementation pattern

Martini implementation pattern: Martini receives an approved event delivery, identifies the secret and event context, and retrieves current state before changing downstream systems. Because events can be duplicated or arrive out of order, the workflow uses idempotency and state verification rather than treating the notification as the complete secret value.

Implementation sequence

Receive the selected AWS event through the configured event path
Extract the secret identifier, event type, and event timestamp
Check the event against the last processed state
Retrieve the current secret metadata or version when authorized
Apply the downstream rotation or governance action once
Record non-sensitive processing status and correlation details

Scheduled synchronization

Scheduled workflows can call ListSecrets, DescribeSecret, or ListSecretVersionIds to build inventories, inspect rotation configuration, or detect changes. List operations may return paginated results and should not be treated as universal value-change notifications.

Martini implementation pattern

Martini implementation pattern: Martini starts a scheduled workflow, follows pagination tokens, maps metadata to a canonical inventory model, and reconciles it with a target such as ServiceNow or a governance database. Secret values are excluded unless a separate, explicitly authorized process requires them.

Implementation sequence

Start the workflow on the approved schedule
Retrieve the next page of secret metadata
Continue until the pagination token is exhausted
Map names, ARNs, tags, regions, and rotation status
Reconcile changes with the target inventory
Store a checkpoint and report non-sensitive failures

Common AWS Secrets Manager integration patterns

Pattern 1: Retrieve runtime credentials for downstream systems

When to use this pattern

Use this pattern when a Martini API or scheduled workflow must call a database, external API, or application using credentials stored in AWS Secrets Manager. The secret remains a runtime dependency rather than becoming part of the ordinary business payload.

Integration direction
AWS Secrets Manager
Martini
Downstream API or database
Example Mapping
AWS Secrets Manager FieldCanonical FieldTarget Field
SecretString.usernamecredential.usernameDownstream authentication username
SecretString.passwordcredential.passwordDownstream authentication password
SecretVersion.VersionStagescredential.versionStageCredential validation context
Martini implementation pattern

The workflow retrieves AWSCURRENT with GetSecretValue, parses and validates the SecretString JSON when applicable, calls the downstream system, and ensures the secret is not logged or returned in errors. Authentication failures, missing secrets, KMS failures, throttling, and transient errors are routed separately with bounded retries.

Martini capabilities used
  • workflows
  • API consumption
  • data mapping
  • JSON handling
  • business rules
  • error handling

Pattern 2: Orchestrate downstream secret rotation

When to use this pattern

Use this pattern when a rotated credential must be validated and propagated to a dependent application, database, or configuration process. AWS-native rotation may use Lambda; Martini coordinates downstream work rather than replacing the AWS rotation mechanism.

Integration direction
AWS Secrets Manager
Martini
Dependent application or database
Example Mapping
AWS Secrets Manager FieldCanonical FieldTarget Field
SecretVersion.VersionStagesrotation.stageCredential lifecycle state
Secret.LastChangedDaterotation.changedAtConfiguration update timestamp
RotationRules.AutomaticallyAfterDaysrotation.intervalDaysOperational policy
Martini implementation pattern

An EventBridge or CloudTrail event, or a controlled schedule, starts the workflow. Martini retrieves current state, validates the new credential against the dependent system, applies the update only when the state has changed, and records a non-sensitive result. Duplicate events and retries are handled idempotently.

Martini capabilities used
  • event-driven workflows
  • API consumption
  • data mapping
  • business rules
  • idempotency
  • error handling

Pattern 3: Expose controlled secret access through an API

When to use this pattern

Use this pattern only when approved internal consumers need mediated access to a limited secret or configuration subset. It expands the security boundary and should be subject to strict authorization, allowlists, auditing, and response filtering.

Integration direction
Internal application
Martini
AWS Secrets Manager
Example Mapping
AWS Secrets Manager FieldCanonical FieldTarget Field
requestedSecretsecret.identifierSecretId
requestedFieldsresponse.allowlistFiltered configuration response
caller.identityaccess.principalIAM or Martini authorization decision
Martini implementation pattern

Martini exposes an authenticated API, validates the caller and requested secret against an allowlist, retrieves the value through the AWS API, filters the response to approved fields, and suppresses sensitive content from logs. Authorization failures and missing resources are returned without disclosing secret details.

Martini capabilities used
  • API exposure
  • authentication and authorization
  • workflows
  • business rules
  • JSON handling
  • security controls

Pattern 4: Synchronize a non-sensitive secret inventory

When to use this pattern

Use this pattern for governance, ownership, rotation monitoring, and compliance reporting. The target receives metadata such as ARN, tags, region, and rotation status, never the actual secret value.

Integration direction
AWS Secrets Manager
Martini
ServiceNow or governance database
Example Mapping
AWS Secrets Manager FieldCanonical FieldTarget Field
Secret.Namesecret.nameConfiguration item name
Secret.ARNsecret.resourceIdExternal resource identifier
Tagssecret.ownershipOwner and environment fields
RotationEnabledsecret.rotationEnabledRotation compliance status
Martini implementation pattern

A scheduled Martini workflow pages through ListSecrets and related metadata operations, maps each Secret to the target model, compares checkpoints, and upserts only changed metadata. Pagination, throttling, duplicate runs, and target write failures are handled with checkpoints and retryable error routes.

Martini capabilities used
  • scheduled workflows
  • API consumption
  • pagination handling
  • data mapping
  • database or application integration
  • monitoring

Applications commonly integrated with AWS Secrets Manager

AWS Secrets Manager can be integrated with AWS workloads, data services, deployment platforms, and governance applications that need controlled access to credentials or secret metadata. Martini can orchestrate these flows without copying sensitive values into ordinary business payloads or inventory systems.

Application Scenario Direction Martini Pattern
AWS Lambda Store database passwords, API credentials, and rotation configuration used by functions and rotation workflows. AWS Secrets Manager → Martini → AWS Lambda A Martini workflow retrieves the current secret, validates or transforms the required fields, invokes Lambda or coordinates a downstream update, and suppresses secret values from logs and responses.
Amazon ECS Provide credentials to containerized workloads without embedding them in images or ordinary configuration files. AWS Secrets Manager → Martini → Amazon ECS Martini can retrieve or update secret metadata as part of deployment and runtime workflows, applying IAM-aware routing and recording only non-sensitive operational status.
Amazon EKS Supply credentials to Kubernetes workloads through AWS-integrated secret delivery patterns. AWS Secrets Manager → Martini → Amazon EKS A workflow can manage approved secret metadata or coordinate updates for EKS workloads, while the workload-side delivery mechanism remains responsible for mounting or injecting values.
Amazon RDS Store and rotate database credentials used by applications connecting to RDS databases. AWS Secrets Manager → Martini → Amazon RDS Martini retrieves the AWSCURRENT version, validates the credential against a controlled database operation, and orchestrates dependent configuration changes after rotation.
Amazon Redshift Manage warehouse credentials used by applications, data pipelines, and reporting services. AWS Secrets Manager → Martini → Amazon Redshift A workflow retrieves the required secret, uses it for an approved Redshift operation, and applies retry, masking, and authorization rules around the data pipeline.
Amazon DocumentDB Store and rotate credentials used by applications connecting to DocumentDB clusters. AWS Secrets Manager → Martini → Amazon DocumentDB Martini can coordinate retrieval and downstream credential propagation, using version staging labels and idempotent checks before applying changes.
GitHub Protect GitHub personal access tokens, app credentials, and webhook secrets used by deployment or integration workflows. GitHub → Martini → AWS Secrets Manager A Martini API or workflow can receive an approved credential-management request, validate ownership and scope, and write the secret with PutSecretValue while avoiding value exposure in logs.
ServiceNow Synchronize secret inventory metadata, ownership, rotation status, or compliance information with governance processes. AWS Secrets Manager → Martini → ServiceNow A scheduled workflow lists and describes secrets, excludes secret values, maps metadata to ServiceNow records, and handles pagination and reconciliation errors.

How to build a AWS Secrets Manager integration in Martini

Objective

Establish the AWS account, region, network path, and least-privilege authorization model before implementing workflow logic.

Instructions in Martini

  • Use an IAM role or temporary STS credentials where possible
  • Scope actions to required secret ARNs and KMS keys
  • Configure the region and private endpoint requirements
  • Keep AWS credentials and endpoint configuration in secure environment settings

Objective

Select an API, event, or schedule based on whether the workflow responds to a request, selected AWS activity, or periodic inventory requirement.

Instructions in Martini

  • Use an API trigger for controlled internal consumers
  • Process selected EventBridge or CloudTrail events when coverage is sufficient
  • Use a scheduler for inventory and controlled polling
  • Design for duplicate and out-of-order notifications

Objective

Call the appropriate AWS Secrets Manager operation and obtain only the secret or metadata required for the business process.

Instructions in Martini

  • Use GetSecretValue or BatchGetSecretValue for authorized value retrieval
  • Use DescribeSecret, ListSecrets, or ListSecretVersionIds for metadata workflows
  • Follow pagination tokens for list operations
  • Use AWSCURRENT and other staging labels rather than fixed version IDs

Objective

Coordinate AWS calls, downstream operations, state checks, and security controls as one maintainable Martini workflow.

Instructions in Martini

  • Separate secret retrieval from ordinary business payload processing
  • Validate current state before applying updates
  • Route authorization, KMS, missing-resource, validation, throttling, and transient errors distinctly
  • Use correlation identifiers without including secret contents

Objective

Convert SecretString JSON, SecretBinary, or metadata into the canonical model required by the target application.

Instructions in Martini

  • Parse SecretString only when the agreed schema requires it
  • Validate required fields and schema versions
  • Map tags, rotation status, ARNs, and timestamps to governance fields
  • Do not persist secret values in ordinary integration records

Objective

Enforce access, ownership, rotation, version, and target-update rules before changing downstream systems.

Instructions in Martini

  • Allow only approved secret identifiers and fields
  • Require the expected staging label or current-state condition
  • Make rotation and inventory updates idempotent
  • Filter secret values from logs, exceptions, and diagnostic responses

Common AWS Secrets Manager data objects used in integrations

ObjectTypical UseCommon target systemsMartini handling
SecretNamed resource containing secret metadata, ARN, tags, encryption configuration, rotation settings, and version information.ServiceNow, governance databases, AWS workloads, deployment systemsMartini retrieves and maps approved metadata while keeping the secret value out of inventory payloads and logs.
SecretVersionRepresents a specific value version identified by a version ID and staging labels such as AWSCURRENT, AWSPREVIOUS, or AWSPENDING.Rotation workflows, downstream applications, configuration storesMartini uses staging labels and current-state checks rather than assuming version IDs remain constant.
Secret valueSensitive payload returned as SecretString or SecretBinary for credentials, API keys, tokens, or configuration.Databases, APIs, Lambda, ECS, EKS, internal servicesMartini retrieves, parses, validates, and maps values only within the required workflow scope and excludes them from logs and error responses.
ResourcePolicyResource-based IAM policy attached to a secret, including cross-account access rules and trusted principals.AWS accounts, IAM governance processes, compliance repositoriesMartini can inspect or coordinate policy-related workflows while applying authorization and audit rules.
RotationRulesConfiguration controlling automatic secret rotation, including rotation schedule or interval.AWS Lambda rotation functions, governance systems, operational dashboardsMartini can read rotation configuration, coordinate downstream actions, and record non-sensitive status.
TagKey-value metadata used for ownership, environment classification, cost allocation, and access conventions.ServiceNow, governance databases, reporting systemsMartini maps tags into canonical governance fields and uses them for routing or reconciliation without retrieving secret contents.

Authentication and security considerations

IAM and SigV4

AWS Secrets Manager uses IAM authorization and generally requires AWS Signature Version 4 for direct service API calls. Martini integrations should prefer short-lived role-based or temporary credentials over long-lived access keys.

Least privilege

Scope actions such as GetSecretValue, DescribeSecret, or PutSecretValue to the required workflows, secret ARNs, regions, accounts, and KMS keys. Cross-account access may require resource-based and KMS key policies.

Secret handling

  • Do not write SecretString or SecretBinary values to workflow logs.
  • Do not include secret values in exceptions or diagnostic responses.
  • Use secure environment configuration for AWS credentials and endpoints.
  • Return only approved fields when exposing a controlled internal API.

Operational considerations for AWS Secrets Manager integrations

Versions and regions

Secrets are regional resources and may have multiple versions. Use staging labels such as AWSCURRENT and verify the account, region, and current state before applying downstream changes.

Pagination and batching

ListSecrets and ListSecretVersionIds may be paginated. BatchGetSecretValue can reduce request overhead but still requires per-secret authorization and partial-failure handling.

Retries and idempotency

Use bounded exponential backoff for throttling and transient service failures. Separate retryable failures from authorization, missing-resource, KMS, and validation errors, and make rotation and event handlers safe to repeat.

Events and testing

EventBridge and CloudTrail deliveries can be duplicated or arrive out of order. Test event coverage, schema changes, pagination, KMS permissions, rotation behavior, and the suppression of sensitive values in logs.

Why use Martini instead of scripts or point-to-point integrations?

Centralized orchestration

Martini coordinates AWS Secrets Manager calls with APIs, databases, applications, schedules, and event-driven workflows instead of scattering credential logic across scripts.

Reusable integration assets

Workflows, APIs, mappings, validation rules, and reusable services provide maintainable integration behavior for retrieval, rotation coordination, and inventory synchronization.

Controlled security boundaries

Martini can enforce authorization, allowlists, field filtering, retry policies, and error routing while keeping secret values out of ordinary payloads and operational logs.

Operational visibility

Centralized workflows make pagination, idempotency, correlation, monitoring, and deployment configuration easier to test and maintain than point-to-point implementations.

Frequently asked questions

How can AWS Secrets Manager be integrated with enterprise systems?

AWS Secrets Manager can be integrated through its JSON service API over HTTPS, AWS SDKs, SigV4-signed requests, scheduled metadata retrieval, and selected EventBridge or CloudTrail event flows. Enterprise workflows commonly retrieve credentials, coordinate rotation, or synchronize non-sensitive secret metadata with applications and governance systems.

Can Martini integrate with AWS Secrets Manager?

Yes. Martini can integrate with AWS Secrets Manager by consuming its HTTPS service API through an AWS SDK or reusable custom JVM implementation where appropriate. It can retrieve or update secrets, process selected AWS events, orchestrate rotation-related work, and synchronize metadata while enforcing secure handling.

Do I need a connector to integrate AWS Secrets Manager with Martini?

No. A dedicated AWS Secrets Manager connector is not required. Martini can use the confirmed AWS service API, AWS SDK-compatible implementation, SigV4 authentication, IAM roles or temporary credentials, and selected EventBridge or CloudTrail event mechanisms.

Is there any extra Lonti cost to integrate AWS Secrets Manager with Martini?

Lonti does not charge an additional per-connector or per-vendor fee to integrate AWS Secrets Manager. The integration is subject to the provisioned capacity of the Martini environment. Separate AWS, infrastructure, KMS, EventBridge, and other third-party costs may apply based on usage and deployment model.

Which AWS Secrets Manager integration methods should architects use?

Use the JSON service API over HTTPS or an AWS SDK for direct operations, with IAM and SigV4 authentication. Use BatchGetSecretValue for suitable multi-secret retrieval, EventBridge or CloudTrail for selected event-driven processing, and scheduled workflows for inventory or controlled polling.

Does AWS Secrets Manager provide webhooks or change events?

It does not provide a generic webhook for every secret value change. Selected service events and CloudTrail API activity can be routed through Amazon EventBridge, but coverage should be verified for the required event. Scheduled polling may be needed when event coverage is insufficient.

How should synchronization and secret versions be handled?

Use staging labels such as AWSCURRENT, AWSPREVIOUS, and AWSPENDING rather than relying on fixed version IDs. Inventory workflows should follow pagination tokens, compare checkpoints, and synchronize metadata without copying secret values. Rotation and event processing should be idempotent.

How does Martini handle AWS Secrets Manager errors and sensitive data?

Martini can classify authentication, authorization, KMS, missing-secret, validation, throttling, and transient AWS failures, then apply bounded retries with exponential backoff where appropriate. Secret values should be excluded from logs, exception messages, diagnostic responses, and unnecessary persistence. Martini can also expose a controlled API façade when strict authorization and response filtering are applied.