.png)
AWS Secrets Manager Integration Guide
Connect AWS Secrets Manager with enterprise workflows by retrieving, rotating, governing, and securely distributing secrets through its signed AWS service API and event ecosystem.
AWS Secrets Manager integration options at a glance
AWS Secrets Manager exposes a JSON service API over HTTPS for creating, retrieving, updating, rotating, listing, and deleting secrets. Requests generally require AWS Signature Version 4 authentication with IAM credentials, roles, or temporary STS credentials. Martini can consume these operations through a workflow using an AWS SDK or reusable custom JVM implementation where appropriate. Selected service and CloudTrail activity can be routed through Amazon EventBridge for event-driven processing, while scheduled workflows can poll metadata with ListSecrets or DescribeSecret. BatchGetSecretValue supports multi-secret retrieval, and AWS KMS, CloudWatch, and PrivateLink can provide related encryption, monitoring, and private-connectivity controls.
| Integration point | Supported by AWS Secrets Manager? | Common use cases | How Martini supports it |
|---|---|---|---|
| AWS JSON service API over HTTPS | Limited | Use operations such as GetSecretValue, CreateSecret, PutSecretValue, DescribeSecret, ListSecrets, RotateSecret, and DeleteSecret to manage secrets and metadata. AWS does not describe this interface as a conventional REST resource API. | Martini can consume the HTTPS API from workflows. An AWS SDK or reusable custom JVM implementation can help resolve credentials and perform SigV4 signing. |
| Authentication and authorization | Yes | IAM roles, IAM users, temporary STS credentials, IAM policies, resource-based policies, KMS permissions, and SigV4 govern access to secrets and operations. | Martini can use securely configured AWS credentials or role-based runtime access and can apply least-privilege workflow boundaries. |
| EventBridge and CloudTrail events | Limited | Selected Secrets Manager service events and CloudTrail API activity can be routed through Amazon EventBridge for event-driven processing. This is not a universal secret-change webhook. | Martini can process events delivered through an approved AWS event delivery path and then retrieve current state before acting. |
| BatchGetSecretValue | Limited | Retrieve multiple secrets in one batch operation where IAM permissions and service limits allow it. Individual retrieval failures still require explicit handling. | Martini can orchestrate batch requests, validate partial results, and route failed or unauthorized secret lookups separately. |
| Scheduled synchronization | Yes | Scheduled calls to ListSecrets, DescribeSecret, or ListSecretVersionIds can maintain an inventory or detect metadata and rotation changes. | Martini scheduler-triggered workflows can paginate through results, compare checkpoints, and synchronize non-sensitive metadata. |
| AWS KMS encryption | Yes | Secrets can use AWS-managed or customer-managed KMS keys, with additional key permissions required for encrypted secret access. | Martini workflows can operate within IAM and KMS authorization boundaries and classify KMS failures separately from missing-secret errors. |
| Private connectivity | Yes | AWS PrivateLink interface VPC endpoints can provide private network access to Secrets Manager from supported VPC environments. | Martini deployment and endpoint configuration can be aligned with the network path and region required by the AWS account. |
How AWS Secrets Manager exposes data and business events
AWS Secrets Manager API
AWS Secrets Manager provides a JSON service API over HTTPS. Core operations include GetSecretValue, BatchGetSecretValue, CreateSecret, PutSecretValue, DescribeSecret, ListSecrets, RotateSecret, and version-management operations. Calls generally require SigV4 signing and IAM authorization.
Martini implementation pattern
Martini implementation pattern: Martini invokes the required AWS operation from a workflow using an AWS SDK or reusable custom JVM implementation where appropriate. The workflow resolves the region and credential context, retrieves or updates the resource, validates the response, and passes only the necessary fields to the next step.
Implementation sequence
EventBridge and CloudTrail events
Secrets Manager does not provide a generic webhook for every secret update. Selected service events and CloudTrail API activity can be routed through Amazon EventBridge for event-driven processing, subject to the event coverage and account configuration.
Martini implementation pattern
Martini implementation pattern: Martini receives an approved event delivery, identifies the secret and event context, and retrieves current state before changing downstream systems. Because events can be duplicated or arrive out of order, the workflow uses idempotency and state verification rather than treating the notification as the complete secret value.
Implementation sequence
Scheduled synchronization
Scheduled workflows can call ListSecrets, DescribeSecret, or ListSecretVersionIds to build inventories, inspect rotation configuration, or detect changes. List operations may return paginated results and should not be treated as universal value-change notifications.
Martini implementation pattern
Martini implementation pattern: Martini starts a scheduled workflow, follows pagination tokens, maps metadata to a canonical inventory model, and reconciles it with a target such as ServiceNow or a governance database. Secret values are excluded unless a separate, explicitly authorized process requires them.
Implementation sequence
Common AWS Secrets Manager integration patterns
Pattern 1: Retrieve runtime credentials for downstream systems
When to use this pattern
Use this pattern when a Martini API or scheduled workflow must call a database, external API, or application using credentials stored in AWS Secrets Manager. The secret remains a runtime dependency rather than becoming part of the ordinary business payload.
Integration direction
Example Mapping
| AWS Secrets Manager Field | Canonical Field | Target Field |
|---|---|---|
| SecretString.username | credential.username | Downstream authentication username |
| SecretString.password | credential.password | Downstream authentication password |
| SecretVersion.VersionStages | credential.versionStage | Credential validation context |
Martini implementation pattern
The workflow retrieves AWSCURRENT with GetSecretValue, parses and validates the SecretString JSON when applicable, calls the downstream system, and ensures the secret is not logged or returned in errors. Authentication failures, missing secrets, KMS failures, throttling, and transient errors are routed separately with bounded retries.
Martini capabilities used
- workflows
- API consumption
- data mapping
- JSON handling
- business rules
- error handling
Pattern 2: Orchestrate downstream secret rotation
When to use this pattern
Use this pattern when a rotated credential must be validated and propagated to a dependent application, database, or configuration process. AWS-native rotation may use Lambda; Martini coordinates downstream work rather than replacing the AWS rotation mechanism.
Integration direction
Example Mapping
| AWS Secrets Manager Field | Canonical Field | Target Field |
|---|---|---|
| SecretVersion.VersionStages | rotation.stage | Credential lifecycle state |
| Secret.LastChangedDate | rotation.changedAt | Configuration update timestamp |
| RotationRules.AutomaticallyAfterDays | rotation.intervalDays | Operational policy |
Martini implementation pattern
An EventBridge or CloudTrail event, or a controlled schedule, starts the workflow. Martini retrieves current state, validates the new credential against the dependent system, applies the update only when the state has changed, and records a non-sensitive result. Duplicate events and retries are handled idempotently.
Martini capabilities used
- event-driven workflows
- API consumption
- data mapping
- business rules
- idempotency
- error handling
Pattern 3: Expose controlled secret access through an API
When to use this pattern
Use this pattern only when approved internal consumers need mediated access to a limited secret or configuration subset. It expands the security boundary and should be subject to strict authorization, allowlists, auditing, and response filtering.
Integration direction
Example Mapping
| AWS Secrets Manager Field | Canonical Field | Target Field |
|---|---|---|
| requestedSecret | secret.identifier | SecretId |
| requestedFields | response.allowlist | Filtered configuration response |
| caller.identity | access.principal | IAM or Martini authorization decision |
Martini implementation pattern
Martini exposes an authenticated API, validates the caller and requested secret against an allowlist, retrieves the value through the AWS API, filters the response to approved fields, and suppresses sensitive content from logs. Authorization failures and missing resources are returned without disclosing secret details.
Martini capabilities used
- API exposure
- authentication and authorization
- workflows
- business rules
- JSON handling
- security controls
Pattern 4: Synchronize a non-sensitive secret inventory
When to use this pattern
Use this pattern for governance, ownership, rotation monitoring, and compliance reporting. The target receives metadata such as ARN, tags, region, and rotation status, never the actual secret value.
Integration direction
Example Mapping
| AWS Secrets Manager Field | Canonical Field | Target Field |
|---|---|---|
| Secret.Name | secret.name | Configuration item name |
| Secret.ARN | secret.resourceId | External resource identifier |
| Tags | secret.ownership | Owner and environment fields |
| RotationEnabled | secret.rotationEnabled | Rotation compliance status |
Martini implementation pattern
A scheduled Martini workflow pages through ListSecrets and related metadata operations, maps each Secret to the target model, compares checkpoints, and upserts only changed metadata. Pagination, throttling, duplicate runs, and target write failures are handled with checkpoints and retryable error routes.
Martini capabilities used
- scheduled workflows
- API consumption
- pagination handling
- data mapping
- database or application integration
- monitoring
Applications commonly integrated with AWS Secrets Manager
AWS Secrets Manager can be integrated with AWS workloads, data services, deployment platforms, and governance applications that need controlled access to credentials or secret metadata. Martini can orchestrate these flows without copying sensitive values into ordinary business payloads or inventory systems.
| Application | Scenario | Direction | Martini Pattern |
|---|---|---|---|
| AWS Lambda | Store database passwords, API credentials, and rotation configuration used by functions and rotation workflows. | AWS Secrets Manager → Martini → AWS Lambda | A Martini workflow retrieves the current secret, validates or transforms the required fields, invokes Lambda or coordinates a downstream update, and suppresses secret values from logs and responses. |
| Amazon ECS | Provide credentials to containerized workloads without embedding them in images or ordinary configuration files. | AWS Secrets Manager → Martini → Amazon ECS | Martini can retrieve or update secret metadata as part of deployment and runtime workflows, applying IAM-aware routing and recording only non-sensitive operational status. |
| Amazon EKS | Supply credentials to Kubernetes workloads through AWS-integrated secret delivery patterns. | AWS Secrets Manager → Martini → Amazon EKS | A workflow can manage approved secret metadata or coordinate updates for EKS workloads, while the workload-side delivery mechanism remains responsible for mounting or injecting values. |
| Amazon RDS | Store and rotate database credentials used by applications connecting to RDS databases. | AWS Secrets Manager → Martini → Amazon RDS | Martini retrieves the AWSCURRENT version, validates the credential against a controlled database operation, and orchestrates dependent configuration changes after rotation. |
| Amazon Redshift | Manage warehouse credentials used by applications, data pipelines, and reporting services. | AWS Secrets Manager → Martini → Amazon Redshift | A workflow retrieves the required secret, uses it for an approved Redshift operation, and applies retry, masking, and authorization rules around the data pipeline. |
| Amazon DocumentDB | Store and rotate credentials used by applications connecting to DocumentDB clusters. | AWS Secrets Manager → Martini → Amazon DocumentDB | Martini can coordinate retrieval and downstream credential propagation, using version staging labels and idempotent checks before applying changes. |
| GitHub | Protect GitHub personal access tokens, app credentials, and webhook secrets used by deployment or integration workflows. | GitHub → Martini → AWS Secrets Manager | A Martini API or workflow can receive an approved credential-management request, validate ownership and scope, and write the secret with PutSecretValue while avoiding value exposure in logs. |
| ServiceNow | Synchronize secret inventory metadata, ownership, rotation status, or compliance information with governance processes. | AWS Secrets Manager → Martini → ServiceNow | A scheduled workflow lists and describes secrets, excludes secret values, maps metadata to ServiceNow records, and handles pagination and reconciliation errors. |
How to build a AWS Secrets Manager integration in Martini
Objective
Establish the AWS account, region, network path, and least-privilege authorization model before implementing workflow logic.
Instructions in Martini
- Use an IAM role or temporary STS credentials where possible
- Scope actions to required secret ARNs and KMS keys
- Configure the region and private endpoint requirements
- Keep AWS credentials and endpoint configuration in secure environment settings
Objective
Select an API, event, or schedule based on whether the workflow responds to a request, selected AWS activity, or periodic inventory requirement.
Instructions in Martini
- Use an API trigger for controlled internal consumers
- Process selected EventBridge or CloudTrail events when coverage is sufficient
- Use a scheduler for inventory and controlled polling
- Design for duplicate and out-of-order notifications
Objective
Call the appropriate AWS Secrets Manager operation and obtain only the secret or metadata required for the business process.
Instructions in Martini
- Use GetSecretValue or BatchGetSecretValue for authorized value retrieval
- Use DescribeSecret, ListSecrets, or ListSecretVersionIds for metadata workflows
- Follow pagination tokens for list operations
- Use AWSCURRENT and other staging labels rather than fixed version IDs
Objective
Coordinate AWS calls, downstream operations, state checks, and security controls as one maintainable Martini workflow.
Instructions in Martini
- Separate secret retrieval from ordinary business payload processing
- Validate current state before applying updates
- Route authorization, KMS, missing-resource, validation, throttling, and transient errors distinctly
- Use correlation identifiers without including secret contents
Objective
Convert SecretString JSON, SecretBinary, or metadata into the canonical model required by the target application.
Instructions in Martini
- Parse SecretString only when the agreed schema requires it
- Validate required fields and schema versions
- Map tags, rotation status, ARNs, and timestamps to governance fields
- Do not persist secret values in ordinary integration records
Objective
Enforce access, ownership, rotation, version, and target-update rules before changing downstream systems.
Instructions in Martini
- Allow only approved secret identifiers and fields
- Require the expected staging label or current-state condition
- Make rotation and inventory updates idempotent
- Filter secret values from logs, exceptions, and diagnostic responses
Common AWS Secrets Manager data objects used in integrations
| Object | Typical Use | Common target systems | Martini handling |
|---|---|---|---|
| Secret | Named resource containing secret metadata, ARN, tags, encryption configuration, rotation settings, and version information. | ServiceNow, governance databases, AWS workloads, deployment systems | Martini retrieves and maps approved metadata while keeping the secret value out of inventory payloads and logs. |
| SecretVersion | Represents a specific value version identified by a version ID and staging labels such as AWSCURRENT, AWSPREVIOUS, or AWSPENDING. | Rotation workflows, downstream applications, configuration stores | Martini uses staging labels and current-state checks rather than assuming version IDs remain constant. |
| Secret value | Sensitive payload returned as SecretString or SecretBinary for credentials, API keys, tokens, or configuration. | Databases, APIs, Lambda, ECS, EKS, internal services | Martini retrieves, parses, validates, and maps values only within the required workflow scope and excludes them from logs and error responses. |
| ResourcePolicy | Resource-based IAM policy attached to a secret, including cross-account access rules and trusted principals. | AWS accounts, IAM governance processes, compliance repositories | Martini can inspect or coordinate policy-related workflows while applying authorization and audit rules. |
| RotationRules | Configuration controlling automatic secret rotation, including rotation schedule or interval. | AWS Lambda rotation functions, governance systems, operational dashboards | Martini can read rotation configuration, coordinate downstream actions, and record non-sensitive status. |
| Tag | Key-value metadata used for ownership, environment classification, cost allocation, and access conventions. | ServiceNow, governance databases, reporting systems | Martini maps tags into canonical governance fields and uses them for routing or reconciliation without retrieving secret contents. |
Authentication and security considerations
IAM and SigV4
AWS Secrets Manager uses IAM authorization and generally requires AWS Signature Version 4 for direct service API calls. Martini integrations should prefer short-lived role-based or temporary credentials over long-lived access keys.
Least privilege
Scope actions such as GetSecretValue, DescribeSecret, or PutSecretValue to the required workflows, secret ARNs, regions, accounts, and KMS keys. Cross-account access may require resource-based and KMS key policies.
Secret handling
- Do not write SecretString or SecretBinary values to workflow logs.
- Do not include secret values in exceptions or diagnostic responses.
- Use secure environment configuration for AWS credentials and endpoints.
- Return only approved fields when exposing a controlled internal API.
Operational considerations for AWS Secrets Manager integrations
Versions and regions
Secrets are regional resources and may have multiple versions. Use staging labels such as AWSCURRENT and verify the account, region, and current state before applying downstream changes.
Pagination and batching
ListSecrets and ListSecretVersionIds may be paginated. BatchGetSecretValue can reduce request overhead but still requires per-secret authorization and partial-failure handling.
Retries and idempotency
Use bounded exponential backoff for throttling and transient service failures. Separate retryable failures from authorization, missing-resource, KMS, and validation errors, and make rotation and event handlers safe to repeat.
Events and testing
EventBridge and CloudTrail deliveries can be duplicated or arrive out of order. Test event coverage, schema changes, pagination, KMS permissions, rotation behavior, and the suppression of sensitive values in logs.
Why use Martini instead of scripts or point-to-point integrations?
Centralized orchestration
Martini coordinates AWS Secrets Manager calls with APIs, databases, applications, schedules, and event-driven workflows instead of scattering credential logic across scripts.
Reusable integration assets
Workflows, APIs, mappings, validation rules, and reusable services provide maintainable integration behavior for retrieval, rotation coordination, and inventory synchronization.
Controlled security boundaries
Martini can enforce authorization, allowlists, field filtering, retry policies, and error routing while keeping secret values out of ordinary payloads and operational logs.
Operational visibility
Centralized workflows make pagination, idempotency, correlation, monitoring, and deployment configuration easier to test and maintain than point-to-point implementations.
Frequently asked questions
AWS Secrets Manager can be integrated through its JSON service API over HTTPS, AWS SDKs, SigV4-signed requests, scheduled metadata retrieval, and selected EventBridge or CloudTrail event flows. Enterprise workflows commonly retrieve credentials, coordinate rotation, or synchronize non-sensitive secret metadata with applications and governance systems.
Yes. Martini can integrate with AWS Secrets Manager by consuming its HTTPS service API through an AWS SDK or reusable custom JVM implementation where appropriate. It can retrieve or update secrets, process selected AWS events, orchestrate rotation-related work, and synchronize metadata while enforcing secure handling.
No. A dedicated AWS Secrets Manager connector is not required. Martini can use the confirmed AWS service API, AWS SDK-compatible implementation, SigV4 authentication, IAM roles or temporary credentials, and selected EventBridge or CloudTrail event mechanisms.
Lonti does not charge an additional per-connector or per-vendor fee to integrate AWS Secrets Manager. The integration is subject to the provisioned capacity of the Martini environment. Separate AWS, infrastructure, KMS, EventBridge, and other third-party costs may apply based on usage and deployment model.
Use the JSON service API over HTTPS or an AWS SDK for direct operations, with IAM and SigV4 authentication. Use BatchGetSecretValue for suitable multi-secret retrieval, EventBridge or CloudTrail for selected event-driven processing, and scheduled workflows for inventory or controlled polling.
It does not provide a generic webhook for every secret value change. Selected service events and CloudTrail API activity can be routed through Amazon EventBridge, but coverage should be verified for the required event. Scheduled polling may be needed when event coverage is insufficient.
Use staging labels such as AWSCURRENT, AWSPREVIOUS, and AWSPENDING rather than relying on fixed version IDs. Inventory workflows should follow pagination tokens, compare checkpoints, and synchronize metadata without copying secret values. Rotation and event processing should be idempotent.
Martini can classify authentication, authorization, KMS, missing-secret, validation, throttling, and transient AWS failures, then apply bounded retries with exponential backoff where appropriate. Secret values should be excluded from logs, exception messages, diagnostic responses, and unnecessary persistence. Martini can also expose a controlled API façade when strict authorization and response filtering are applied.
Related Martini documentation
Workflows
Data Handling
Connect AWS Secrets Manager with Martini
Use Martini to build secure, maintainable workflows for AWS Secrets Manager retrieval, rotation coordination, event processing, and non-sensitive metadata synchronization.