> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tensor9.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Systems Manager (SSM)

> Systems Manager (SSM) APIs with Cloud Adapter.

This page describes how Systems Manager (SSM) maps to services in the environment where the application runs. Some profiles adapt origin API calls; others translate infrastructure or document target-native behavior.

## Supported environments

| Environment        | Mapping |
| ------------------ | ------- |
| Akamai             | API     |
| Azure              | API     |
| Google Cloud       | API     |
| OCI                | API     |
| Private Kubernetes | API     |
| Scaleway           | API     |

API means the profile adapts origin API behavior. Infrastructure means the profile changes provisioned resources or documents a target-native alternative without promising an origin API endpoint. Check the operation and capability tables for the behavior your application depends on.

## How the targets compare

Each row compares a capability of Systems Manager (SSM) with its adaptation on each target.
A dash means this profile does not state the capability for that target.

### Cloud Adapter

| Capability                                                            | Systems Manager (SSM)               | Akamai, Private Kubernetes, and Scaleway · Kubernetes Secrets                                                                                            | Azure                                                                                                                                                   | Google Cloud · Google Parameter Manager                                                                                                        | Google Cloud · Secret Manager                                                                                                         | OCI                                                                                                                               | Scaleway · Scaleway Secret Manager                   |
| --------------------------------------------------------------------- | ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------- |
| API served · what your app calls                                      | Parameter Store API                 | the same API, served from durable adapter state                                                                                                          | the same API, served from durable adapter state                                                                                                         | the same API, served from durable adapter state                                                                                                | the same API, served from durable adapter state                                                                                       | the same API, served from durable adapter state                                                                                   | the same API, served against Scaleway Secret Manager |
| Where parameters live · the backing store                             | AWS-managed storage                 | durable parameter records + Kubernetes Secrets target copy                                                                                               | durable parameter records + Azure App Configuration target copy                                                                                         | durable parameter records + Google Parameter Manager target copy                                                                               | durable parameter records + Google Secret Manager target copy                                                                         | durable parameter records + OCI Vault target copy                                                                                 | -                                                    |
| Encryption at rest · SecureString handling                            | KMS-encrypted SecureString          | all three type markers are retained; protect durable state and configure Kubernetes storage encryption. Base64 encoding does not encrypt the target copy | String and StringList are supported; SecureString remains outside the App Configuration mapping. Direct Key Vault access is a separate application path | all three type markers are retained in durable state; Parameter Manager encrypts its provider copy at rest; sensitivity follows actual values  | all three type markers are retained in durable state; Secret Manager encrypts its provider copy at rest                               | all three type markers are retained in durable state; the configured OCI vault key encrypts the provider copy                     | -                                                    |
| Path hierarchies · by-path reads                                      | native                              | caller-scoped record queries; no per-value provider reads                                                                                                | caller-scoped record queries; no per-value provider reads                                                                                               | caller-scoped record queries; no per-value provider reads                                                                                      | caller-scoped record queries; no per-value provider reads                                                                             | caller-scoped record queries; no per-value provider reads                                                                         | -                                                    |
| Versions & labels · history                                           | 100-version history + labels        | only the latest value and increasing AWS version counter are retained; previous values and named labels are unsupported                                  | numeric history is retained; the adapter owns AWS version selection. Named SSM labels remain outside this mapping                                       | retained values and adapter-owned label references provide parameter history and named labels; Parameter Manager has no native version aliases | retained values and adapter-owned label references provide parameter history and named labels; native aliases do not decide AWS reads | -                                                                                                                                 | -                                                    |
| API coverage                                                          | full                                | partial                                                                                                                                                  | partial                                                                                                                                                 | partial                                                                                                                                        | partial                                                                                                                               | partial                                                                                                                           | partial                                              |
| Versions · history                                                    | 100-version history + labels        | -                                                                                                                                                        | -                                                                                                                                                       | -                                                                                                                                              | -                                                                                                                                     | numeric history is retained; the adapter owns AWS version identity and selection independently of native OCI versionNumber values | -                                                    |
| Delete semantics · DeleteParameter                                    | immediate delete                    | -                                                                                                                                                        | -                                                                                                                                                       | -                                                                                                                                              | -                                                                                                                                     | leaves AWS reads immediately; native secret cleanup is scheduled separately                                                       | -                                                    |
| Where parameters live · the backing store                             | AWS-managed parameter storage       | -                                                                                                                                                        | -                                                                                                                                                       | -                                                                                                                                              | -                                                                                                                                     | -                                                                                                                                 | one Scaleway secret per parameter                    |
| String and SecureString share one store · a change in both directions | two tiers, only one encrypted       | -                                                                                                                                                        | -                                                                                                                                                       | -                                                                                                                                              | -                                                                                                                                     | -                                                                                                                                 | one store, everything encrypted at rest              |
| A parameter's grant narrows to that parameter · not the whole store   | resource-level IAM on the parameter | -                                                                                                                                                        | -                                                                                                                                                       | -                                                                                                                                              | -                                                                                                                                     | -                                                                                                                                 | resource-level IAM on the secret                     |
| The parameter name is encoded, not folded · and it is not pretty      | /app/config/url                     | -                                                                                                                                                        | -                                                                                                                                                       | -                                                                                                                                              | -                                                                                                                                     | -                                                                                                                                 | \_2fapp\_2fconfig\_2furl                             |
| By-path reads filter in the adapter · a deliberate trade              | server-side path filtering          | -                                                                                                                                                        | -                                                                                                                                                       | -                                                                                                                                              | -                                                                                                                                     | -                                                                                                                                 | list 100 at a time, filter in the adapter            |

## On Akamai, Private Kubernetes, and Scaleway

### Kubernetes Secrets

| Operation                                                   | Area           | Support      | Depth        | Notes                                                                                                                                                        |
| ----------------------------------------------------------- | -------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Consumed parameters (read-only references)                  | Build & deploy | Supported    | Common       | a parameter the stack reads but does not own is supplied by the customer during installation; that supply path is distinct from runtime parameter management |
| Filters & discovery (DescribeParameters / ParameterFilters) | Discovery      | Partial      | Full surface | DescribeParameters serves paginated metadata without values; complete ParameterFilters behavior is outside the documented contract                           |
| Change notifications                                        | Events         | Out of scope | Full surface | parameter-change events are outside this mapping                                                                                                             |
| Batch reads (GetParameters)                                 | Parameters     | Supported    | Common       | reads caller-scoped parameter records and partitions found and missing names                                                                                 |
| Hierarchies & by-path reads (GetParametersByPath)           | Parameters     | Supported    | Common       | queries live adapter records by path, applies recursion rules, and returns paginated results; no provider value fetch per returned parameter                 |
| Parameter reads (GetParameter)                              | Parameters     | Supported    | Common       | reads the current value, type, and AWS version from the caller-scoped durable parameter record; the target copy is reconciled separately                     |
| Parameter writes & deletes                                  | Parameters     | Supported    | Common       | PutParameter creates or updates durable parameter state and reconciles the target; DeleteParameter withdraws reads while target cleanup proceeds separately  |
| Parameter policies & Advanced tier                          | Policies       | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                 |
| Public & shared parameters                                  | Scope          | Out of scope | Full surface | AWS-published public parameters and cross-account shared parameters are outside this mapping                                                                 |
| The wider Systems Manager suite                             | Scope          | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management, and documents remain out of scope                                               |
| Custom encryption keys (KeyId)                              | Types          | Out of scope | Most usage   | custom per-parameter AWS KMS keys are unsupported; protect durable adapter state and configure the target copy independently                                 |
| Parameter types (String / StringList / SecureString)        | Types          | Supported    | Common       | all three type markers are retained; protect durable state and configure Kubernetes storage encryption. Base64 encoding does not encrypt the target copy     |
| Reading ciphertext (WithDecryption=false)                   | Types          | Out of scope | Most usage   | SecureString reads require WithDecryption=true; the adapter does not return AWS KMS ciphertext                                                               |
| Versions & labels                                           | Versions       | Out of scope | Most usage   | only the latest value and increasing AWS version counter are retained; previous values and named labels are unsupported                                      |

#### Requests and durable parameter state

With Cloud Adapter, your application sends Parameter Store requests in its AWS SDK to the Tensor9 adapter. The adapter keeps a durable parameter record containing the name, type, current value, version counter, description, and tags. Reads use that record. A background worker reconciles its current value to Kubernetes Secrets.

`PutParameter` creates a parameter or updates it when `Overwrite=true`. An existing name with `Overwrite=false` returns `ParameterAlreadyExists`. Writes advance the AWS version counter and wait for target reconciliation within a bounded interval; a terminal target rejection is reported. `DeleteParameter` removes the parameter from reads while target cleanup proceeds separately.

Protect and back up the adapter's state as well as the target store. Direct provider edits do not update the AWS parameter record and can be overwritten during reconciliation. Existing AWS values and provider history are not automatically imported.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjNjQ3NDhiIj5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhOyBmb250LXNpemU6MTFweCI+S3ViZXJuZXRlcyBTZWNyZXRzPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjYzljZmQ4Ij5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4OyBmb250LXNpemU6MTFweCI+S3ViZXJuZXRlcyBTZWNyZXRzPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />
</div>

<p className="t9-caption">AWS parameter reads use durable adapter state. Target reconciliation and cleanup run separately.</p>

#### Batch reads, paths, and metadata

GetParameter and GetParameters read caller-scoped parameter records. Batch reads partition found and missing names. GetParametersByPath selects live records by path, applies recursion rules, and returns paginated results in name order. It does not fetch every matching value from the provider store, so the earlier direct-proxy per-parameter access cost is not the Max read path.

DescribeParameters returns paginated metadata, including names, types, versions, and descriptions, without parameter values. Complete ParameterFilters behavior is outside the documented contract. Tag operations update the parameter's metadata. These operations cover Parameter Store; Run Command, Session Manager, patching, state management, and documents remain outside the mapping.

#### Versions and labels

This mapping retains the latest value and its increasing version counter. Previous values and named SSM labels are unsupported. A counter records writes; it does not make old values readable. Choose a mapping with retained history when the application needs it.

#### Target storage and encryption

A Kubernetes Secret holds the reconciled current value in the customer cluster. The deployment's service account accesses the backing objects. AWS reads use durable parameter records, not a Kubernetes Secret lookup for each request; the parameter counter belongs to that record.

All three parameter type markers are preserved. Kubernetes Secret values are base64-encoded; base64 is not encryption. Configure Kubernetes access control and storage encryption, and protect the adapter's durable state and backups. This storage option stays inside the customer cluster, including disconnected deployments.

#### Limits and deployment

Custom per-parameter KMS keys, AWS ciphertext reads with WithDecryption=false, parameter policies, and the Advanced tier are unsupported. SecureString reads on a supporting mapping require WithDecryption=true. AWS-published public parameters, cross-account shared parameters, and parameter-change events are outside this mapping.

Load values through the Parameter Store API and verify reads, overwrite behavior, and deletion before switching the application. Deployment can also initialize stack-owned literal values from the release. The customer supplies parameters the stack only reads during installation; that secret-supply path is distinct from runtime parameter management.

Provider storage, access permissions, reconciliation, and durable-state availability affect operation. Historical direct-proxy measurements describe their recorded request path; they do not establish Max latency, throughput, or per-read provider charges.

## On Azure

### Azure App Configuration

| Operation                                                   | Area           | Support      | Depth        | Notes                                                                                                                                                        |
| ----------------------------------------------------------- | -------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Consumed parameters (read-only references)                  | Build & deploy | Supported    | Common       | a parameter the stack reads but does not own is supplied by the customer during installation; that supply path is distinct from runtime parameter management |
| Filters & discovery (DescribeParameters / ParameterFilters) | Discovery      | Partial      | Full surface | DescribeParameters serves paginated metadata without values; complete ParameterFilters behavior is outside the documented contract                           |
| Change notifications                                        | Events         | Out of scope | Full surface | parameter-change events are outside this mapping                                                                                                             |
| Batch reads (GetParameters)                                 | Parameters     | Supported    | Common       | reads caller-scoped parameter records and partitions found and missing names                                                                                 |
| Hierarchies & by-path reads (GetParametersByPath)           | Parameters     | Supported    | Common       | queries live adapter records by path, applies recursion rules, and returns paginated results; no provider value fetch per returned parameter                 |
| Parameter reads (GetParameter)                              | Parameters     | Supported    | Common       | reads the current value, type, and AWS version from the caller-scoped durable parameter record; the target copy is reconciled separately                     |
| Parameter writes & deletes                                  | Parameters     | Supported    | Common       | PutParameter creates or updates durable parameter state and reconciles the target; DeleteParameter withdraws reads while target cleanup proceeds separately  |
| Parameter policies & Advanced tier                          | Policies       | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                 |
| Public & shared parameters                                  | Scope          | Out of scope | Full surface | AWS-published public parameters and cross-account shared parameters are outside this mapping                                                                 |
| The wider Systems Manager suite                             | Scope          | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management, and documents remain out of scope                                               |
| Custom encryption keys (KeyId)                              | Types          | Out of scope | Most usage   | custom per-parameter AWS KMS keys are unsupported; protect durable adapter state and configure the target copy independently                                 |
| Parameter types (String / StringList / SecureString)        | Types          | Partial      | Common       | String and StringList are supported; SecureString remains outside the App Configuration mapping. Direct Key Vault access is a separate application path      |
| Reading ciphertext (WithDecryption=false)                   | Types          | Out of scope | Most usage   | SecureString reads require WithDecryption=true; the adapter does not return AWS KMS ciphertext                                                               |
| Versions & labels                                           | Versions       | Partial      | Most usage   | numeric history is retained; the adapter owns AWS version selection. Named SSM labels remain outside this mapping                                            |

#### Requests and durable parameter state

With Cloud Adapter, your application sends Parameter Store requests in its AWS SDK to the Tensor9 adapter. The adapter keeps a durable parameter record containing the name, type, current value, version counter, description, and tags. Reads use that record. A background worker reconciles its current value to Azure App Configuration.

`PutParameter` creates a parameter or updates it when `Overwrite=true`. An existing name with `Overwrite=false` returns `ParameterAlreadyExists`. Writes advance the AWS version counter and wait for target reconciliation within a bounded interval; a terminal target rejection is reported. `DeleteParameter` removes the parameter from reads while target cleanup proceeds separately.

Protect and back up the adapter's state as well as the target store. Direct provider edits do not update the AWS parameter record and can be overwritten during reconciliation. Existing AWS values and provider history are not automatically imported.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjNjQ3NDhiIj5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhOyBmb250LXNpemU6MTFweCI+QXp1cmUgQXBwIENvbmZpZ3VyYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+Y29uZmlndXJlZCB0YXJnZXQgY29weTwvdGV4dD4KPC9zdmc+" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjYzljZmQ4Ij5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4OyBmb250LXNpemU6MTFweCI+QXp1cmUgQXBwIENvbmZpZ3VyYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+Y29uZmlndXJlZCB0YXJnZXQgY29weTwvdGV4dD4KPC9zdmc+" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />
</div>

<p className="t9-caption">AWS parameter reads use durable adapter state. Target reconciliation and cleanup run separately.</p>

#### Batch reads, paths, and metadata

GetParameter and GetParameters read caller-scoped parameter records. Batch reads partition found and missing names. GetParametersByPath selects live records by path, applies recursion rules, and returns paginated results in name order. It does not fetch every matching value from the provider store, so the earlier direct-proxy per-parameter access cost is not the Max read path.

DescribeParameters returns paginated metadata, including names, types, versions, and descriptions, without parameter values. Complete ParameterFilters behavior is outside the documented contract. Tag operations update the parameter's metadata. These operations cover Parameter Store; Run Command, Session Manager, patching, state management, and documents remain outside the mapping.

#### Versions and labels

This mapping retains numeric parameter versions; named SSM version labels are unsupported. App Configuration labels can represent retained target versions, but they are different from SSM labels. The adapter owns the AWS version counter and selection; the highest provider label does not decide a Max read.

#### Target storage and encryption

Azure App Configuration holds the reconciled configuration value in the customer's store, accessed with the deployment's managed identity. Its key prefixes and label dimension organize the provider copy. GetParametersByPath queries adapter records rather than using a provider prefix query as the application read path.

String and StringList are supported. SecureString is unsupported for this App Configuration mapping. Accessing Azure Key Vault directly requires application changes and is a separate option. Protect adapter state and the encrypted provider store; storage encryption alone does not add SecureString support.

#### Limits and deployment

Custom per-parameter KMS keys, AWS ciphertext reads with WithDecryption=false, parameter policies, and the Advanced tier are unsupported. SecureString reads on a supporting mapping require WithDecryption=true. AWS-published public parameters, cross-account shared parameters, and parameter-change events are outside this mapping.

Load values through the Parameter Store API and verify reads, overwrite behavior, and deletion before switching the application. Deployment can also initialize stack-owned literal values from the release. The customer supplies parameters the stack only reads during installation; that secret-supply path is distinct from runtime parameter management.

Provider storage, access permissions, reconciliation, and durable-state availability affect operation. Historical direct-proxy measurements describe their recorded request path; they do not establish Max latency, throughput, or per-read provider charges.

## On Google Cloud

### Google Parameter Manager

| Operation                                                   | Area           | Support      | Depth        | Notes                                                                                                                                                        |
| ----------------------------------------------------------- | -------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Consumed parameters (read-only references)                  | Build & deploy | Supported    | Common       | a parameter the stack reads but does not own is supplied by the customer during installation; that supply path is distinct from runtime parameter management |
| Filters & discovery (DescribeParameters / ParameterFilters) | Discovery      | Partial      | Full surface | DescribeParameters serves paginated metadata without values; complete ParameterFilters behavior is outside the documented contract                           |
| Change notifications                                        | Events         | Out of scope | Full surface | parameter-change events are outside this mapping                                                                                                             |
| Batch reads (GetParameters)                                 | Parameters     | Supported    | Common       | reads caller-scoped parameter records and partitions found and missing names                                                                                 |
| Hierarchies & by-path reads (GetParametersByPath)           | Parameters     | Supported    | Common       | queries live adapter records by path, applies recursion rules, and returns paginated results; no provider value fetch per returned parameter                 |
| Parameter reads (GetParameter)                              | Parameters     | Supported    | Common       | reads the current value, type, and AWS version from the caller-scoped durable parameter record; the target copy is reconciled separately                     |
| Parameter writes & deletes                                  | Parameters     | Supported    | Common       | PutParameter creates or updates durable parameter state and reconciles the target; DeleteParameter withdraws reads while target cleanup proceeds separately  |
| Parameter policies & Advanced tier                          | Policies       | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                 |
| Public & shared parameters                                  | Scope          | Out of scope | Full surface | AWS-published public parameters and cross-account shared parameters are outside this mapping                                                                 |
| The wider Systems Manager suite                             | Scope          | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management, and documents remain out of scope                                               |
| Custom encryption keys (KeyId)                              | Types          | Out of scope | Most usage   | custom per-parameter AWS KMS keys are unsupported; protect durable adapter state and configure the target copy independently                                 |
| Parameter types (String / StringList / SecureString)        | Types          | Supported    | Common       | all three type markers are retained in durable state; Parameter Manager encrypts its provider copy at rest; sensitivity follows actual values                |
| Reading ciphertext (WithDecryption=false)                   | Types          | Out of scope | Most usage   | SecureString reads require WithDecryption=true; the adapter does not return AWS KMS ciphertext                                                               |
| Versions & labels                                           | Versions       | Supported    | Most usage   | retained values and adapter-owned label references provide parameter history and named labels; Parameter Manager has no native version aliases               |

#### Requests and durable parameter state

With Cloud Adapter, your application sends Parameter Store requests in its AWS SDK to the Tensor9 adapter. The adapter keeps a durable parameter record containing the name, type, current value, version counter, description, and tags. Reads use that record. A background worker reconciles its current value to Google Parameter Manager.

`PutParameter` creates a parameter or updates it when `Overwrite=true`. An existing name with `Overwrite=false` returns `ParameterAlreadyExists`. Writes advance the AWS version counter and wait for target reconciliation within a bounded interval; a terminal target rejection is reported. `DeleteParameter` removes the parameter from reads while target cleanup proceeds separately.

Protect and back up the adapter's state as well as the target store. Direct provider edits do not update the AWS parameter record and can be overwritten during reconciliation. Existing AWS values and provider history are not automatically imported.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjNjQ3NDhiIj5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhOyBmb250LXNpemU6MTFweCI+R29vZ2xlIFBhcmFtZXRlciBNYW5hZ2VyPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjYzljZmQ4Ij5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4OyBmb250LXNpemU6MTFweCI+R29vZ2xlIFBhcmFtZXRlciBNYW5hZ2VyPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />
</div>

<p className="t9-caption">AWS parameter reads use durable adapter state. Target reconciliation and cleanup run separately.</p>

#### Batch reads, paths, and metadata

GetParameter and GetParameters read caller-scoped parameter records. Batch reads partition found and missing names. GetParametersByPath selects live records by path, applies recursion rules, and returns paginated results in name order. It does not fetch every matching value from the provider store, so the earlier direct-proxy per-parameter access cost is not the Max read path.

DescribeParameters returns paginated metadata, including names, types, versions, and descriptions, without parameter values. Complete ParameterFilters behavior is outside the documented contract. Tag operations update the parameter's metadata. These operations cover Parameter Store; Run Command, Session Manager, patching, state management, and documents remain outside the mapping.

#### Versions and labels

This mapping retains parameter history and named SSM labels. The adapter maintains retained values and label-to-version references for GetParameterHistory, LabelParameterVersion, and version-qualified reads. Parameter Manager has no native version aliases; selecting its highest native version is not the Max request path.

#### Target storage and encryption

Google Parameter Manager holds the reconciled parameter value in the customer's project. The deployment uses Google workload identity. Parameter resources and their native versions are the target representation; the adapter owns the AWS parameter name, current version, and read behavior.

All three parameter types are supported. Parameter Manager encrypts its copy at rest. Protect durable adapter state and backups too. Parameter resources can contain sensitive values; choose access controls from their contents, not the service's name.

#### Limits and deployment

Custom per-parameter KMS keys, AWS ciphertext reads with WithDecryption=false, parameter policies, and the Advanced tier are unsupported. SecureString reads on a supporting mapping require WithDecryption=true. AWS-published public parameters, cross-account shared parameters, and parameter-change events are outside this mapping.

Load values through the Parameter Store API and verify reads, overwrite behavior, and deletion before switching the application. Deployment can also initialize stack-owned literal values from the release. The customer supplies parameters the stack only reads during installation; that secret-supply path is distinct from runtime parameter management.

Provider storage, access permissions, reconciliation, and durable-state availability affect operation. Historical direct-proxy measurements describe their recorded request path; they do not establish Max latency, throughput, or per-read provider charges.

### Secret Manager

| Operation                                                   | Area           | Support      | Depth        | Notes                                                                                                                                                        |
| ----------------------------------------------------------- | -------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Consumed parameters (read-only references)                  | Build & deploy | Supported    | Common       | a parameter the stack reads but does not own is supplied by the customer during installation; that supply path is distinct from runtime parameter management |
| Filters & discovery (DescribeParameters / ParameterFilters) | Discovery      | Partial      | Full surface | DescribeParameters serves paginated metadata without values; complete ParameterFilters behavior is outside the documented contract                           |
| Change notifications                                        | Events         | Out of scope | Full surface | parameter-change events are outside this mapping                                                                                                             |
| Batch reads (GetParameters)                                 | Parameters     | Supported    | Common       | reads caller-scoped parameter records and partitions found and missing names                                                                                 |
| Hierarchies & by-path reads (GetParametersByPath)           | Parameters     | Supported    | Common       | queries live adapter records by path, applies recursion rules, and returns paginated results; no provider value fetch per returned parameter                 |
| Parameter reads (GetParameter)                              | Parameters     | Supported    | Common       | reads the current value, type, and AWS version from the caller-scoped durable parameter record; the target copy is reconciled separately                     |
| Parameter writes & deletes                                  | Parameters     | Supported    | Common       | PutParameter creates or updates durable parameter state and reconciles the target; DeleteParameter withdraws reads while target cleanup proceeds separately  |
| Parameter policies & Advanced tier                          | Policies       | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                 |
| Public & shared parameters                                  | Scope          | Out of scope | Full surface | AWS-published public parameters and cross-account shared parameters are outside this mapping                                                                 |
| The wider Systems Manager suite                             | Scope          | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management, and documents remain out of scope                                               |
| Custom encryption keys (KeyId)                              | Types          | Out of scope | Most usage   | custom per-parameter AWS KMS keys are unsupported; protect durable adapter state and configure the target copy independently                                 |
| Parameter types (String / StringList / SecureString)        | Types          | Supported    | Common       | all three type markers are retained in durable state; Secret Manager encrypts its provider copy at rest                                                      |
| Reading ciphertext (WithDecryption=false)                   | Types          | Out of scope | Most usage   | SecureString reads require WithDecryption=true; the adapter does not return AWS KMS ciphertext                                                               |
| Versions & labels                                           | Versions       | Supported    | Most usage   | retained values and adapter-owned label references provide parameter history and named labels; native aliases do not decide AWS reads                        |

#### Requests and durable parameter state

With Cloud Adapter, your application sends Parameter Store requests in its AWS SDK to the Tensor9 adapter. The adapter keeps a durable parameter record containing the name, type, current value, version counter, description, and tags. Reads use that record. A background worker reconciles its current value to Google Secret Manager.

`PutParameter` creates a parameter or updates it when `Overwrite=true`. An existing name with `Overwrite=false` returns `ParameterAlreadyExists`. Writes advance the AWS version counter and wait for target reconciliation within a bounded interval; a terminal target rejection is reported. `DeleteParameter` removes the parameter from reads while target cleanup proceeds separately.

Protect and back up the adapter's state as well as the target store. Direct provider edits do not update the AWS parameter record and can be overwritten during reconciliation. Existing AWS values and provider history are not automatically imported.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjNjQ3NDhiIj5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhOyBmb250LXNpemU6MTFweCI+R29vZ2xlIFNlY3JldCBNYW5hZ2VyPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjYzljZmQ4Ij5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4OyBmb250LXNpemU6MTFweCI+R29vZ2xlIFNlY3JldCBNYW5hZ2VyPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />
</div>

<p className="t9-caption">AWS parameter reads use durable adapter state. Target reconciliation and cleanup run separately.</p>

#### Batch reads, paths, and metadata

GetParameter and GetParameters read caller-scoped parameter records. Batch reads partition found and missing names. GetParametersByPath selects live records by path, applies recursion rules, and returns paginated results in name order. It does not fetch every matching value from the provider store, so the earlier direct-proxy per-parameter access cost is not the Max read path.

DescribeParameters returns paginated metadata, including names, types, versions, and descriptions, without parameter values. Complete ParameterFilters behavior is outside the documented contract. Tag operations update the parameter's metadata. These operations cover Parameter Store; Run Command, Session Manager, patching, state management, and documents remain outside the mapping.

#### Versions and labels

This mapping retains parameter history and named SSM labels. The adapter maintains the retained values and label-to-version references needed by GetParameterHistory, LabelParameterVersion, and version-qualified reads. Moving a provider alias directly does not move an SSM label.

#### Target storage and encryption

Google Secret Manager holds the reconciled current value in the customer's project. The deployment uses Google workload identity. Its native versions and aliases describe the provider copy; AWS reads and version selection belong to the adapter.

All three parameter types are supported. Secret Manager encrypts its copy at rest. Protect the adapter's durable parameter state and backups as well as the provider copy; storing an ordinary String as a secret does not change the sensitivity of its contents.

#### Limits and deployment

Custom per-parameter KMS keys, AWS ciphertext reads with WithDecryption=false, parameter policies, and the Advanced tier are unsupported. SecureString reads on a supporting mapping require WithDecryption=true. AWS-published public parameters, cross-account shared parameters, and parameter-change events are outside this mapping.

Load values through the Parameter Store API and verify reads, overwrite behavior, and deletion before switching the application. Deployment can also initialize stack-owned literal values from the release. The customer supplies parameters the stack only reads during installation; that secret-supply path is distinct from runtime parameter management.

Provider storage, access permissions, reconciliation, and durable-state availability affect operation. Historical direct-proxy measurements describe their recorded request path; they do not establish Max latency, throughput, or per-read provider charges.

## On OCI

### OCI Vault

| Operation                                                   | Area           | Support      | Depth        | Notes                                                                                                                                                        |
| ----------------------------------------------------------- | -------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Consumed parameters (read-only references)                  | Build & deploy | Supported    | Common       | a parameter the stack reads but does not own is supplied by the customer during installation; that supply path is distinct from runtime parameter management |
| Filters & discovery (DescribeParameters / ParameterFilters) | Discovery      | Partial      | Full surface | DescribeParameters serves paginated metadata without values; complete ParameterFilters behavior is outside the documented contract                           |
| Change notifications                                        | Events         | Out of scope | Full surface | parameter-change events are outside this mapping                                                                                                             |
| Batch reads (GetParameters)                                 | Parameters     | Supported    | Common       | reads caller-scoped parameter records and partitions found and missing names                                                                                 |
| Hierarchies & by-path reads (GetParametersByPath)           | Parameters     | Supported    | Common       | queries live adapter records by path, applies recursion rules, and returns paginated results; no provider value fetch per returned parameter                 |
| Parameter reads (GetParameter)                              | Parameters     | Supported    | Common       | reads the current value, type, and AWS version from the caller-scoped durable parameter record; the target copy is reconciled separately                     |
| Parameter writes & deletes                                  | Parameters     | Supported    | Common       | PutParameter creates or updates durable parameter state and reconciles the target; DeleteParameter withdraws reads while target cleanup proceeds separately  |
| Parameter policies & Advanced tier                          | Policies       | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                 |
| Public & shared parameters                                  | Scope          | Out of scope | Full surface | AWS-published public parameters and cross-account shared parameters are outside this mapping                                                                 |
| The wider Systems Manager suite                             | Scope          | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management, and documents remain out of scope                                               |
| Custom encryption keys (KeyId)                              | Types          | Out of scope | Most usage   | custom per-parameter AWS KMS keys are unsupported; protect durable adapter state and configure the target copy independently                                 |
| Parameter types (String / StringList / SecureString)        | Types          | Supported    | Common       | all three type markers are retained in durable state; the configured OCI vault key encrypts the provider copy                                                |
| Reading ciphertext (WithDecryption=false)                   | Types          | Out of scope | Most usage   | SecureString reads require WithDecryption=true; the adapter does not return AWS KMS ciphertext                                                               |
| Move-only version labels                                    | Versions       | Out of scope | Most usage   | named SSM labels are outside this mapping; native OCI stages do not define the AWS contract                                                                  |
| Versions                                                    | Versions       | Supported    | Most usage   | numeric history is retained; the adapter owns AWS version identity and selection independently of native OCI versionNumber values                            |

#### Requests and durable parameter state

With Cloud Adapter, your application sends Parameter Store requests in its AWS SDK to the Tensor9 adapter. The adapter keeps a durable parameter record containing the name, type, current value, version counter, description, and tags. Reads use that record. A background worker reconciles its current value to OCI Vault.

`PutParameter` creates a parameter or updates it when `Overwrite=true`. An existing name with `Overwrite=false` returns `ParameterAlreadyExists`. Writes advance the AWS version counter and wait for target reconciliation within a bounded interval; a terminal target rejection is reported. `DeleteParameter` removes the parameter from reads while target cleanup proceeds separately.

Protect and back up the adapter's state as well as the target store. Direct provider edits do not update the AWS parameter record and can be overwritten during reconciliation. Existing AWS values and provider history are not automatically imported.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjNjQ3NDhiIj5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhOyBmb250LXNpemU6MTFweCI+T0NJIFZhdWx0PC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjYzljZmQ4Ij5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4OyBmb250LXNpemU6MTFweCI+T0NJIFZhdWx0PC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />
</div>

<p className="t9-caption">AWS parameter reads use durable adapter state. Target reconciliation and cleanup run separately.</p>

#### Batch reads, paths, and metadata

GetParameter and GetParameters read caller-scoped parameter records. Batch reads partition found and missing names. GetParametersByPath selects live records by path, applies recursion rules, and returns paginated results in name order. It does not fetch every matching value from the provider store, so the earlier direct-proxy per-parameter access cost is not the Max read path.

DescribeParameters returns paginated metadata, including names, types, versions, and descriptions, without parameter values. Complete ParameterFilters behavior is outside the documented contract. Tag operations update the parameter's metadata. These operations cover Parameter Store; Run Command, Session Manager, patching, state management, and documents remain outside the mapping.

#### Versions and labels

This mapping retains numeric parameter versions; named SSM labels are unsupported. OCI supplies versioned target storage, while the adapter maintains AWS version identity and selection. A native versionNumber is not an instruction to read around the parameter record.

#### Target storage and encryption

OCI Vault holds the reconciled value as a secret, including ordinary String configuration. Configure the vault, compartment, encryption key, and resource-principal access for secret management and retrieval. Native secret versions describe the provider copy; the adapter owns the AWS parameter record and read path.

All three parameter types use the configured vault key for the provider copy. OCI schedules physical secret deletion; that cleanup can finish after the parameter leaves the AWS-readable set. Reusing a name must be reconciled with any retained native secret, without confusing its version sequence with the new AWS parameter identity. Protect durable adapter state and backups as well as the vault.

#### Limits and deployment

Custom per-parameter KMS keys, AWS ciphertext reads with WithDecryption=false, parameter policies, and the Advanced tier are unsupported. SecureString reads on a supporting mapping require WithDecryption=true. AWS-published public parameters, cross-account shared parameters, and parameter-change events are outside this mapping.

Load values through the Parameter Store API and verify reads, overwrite behavior, and deletion before switching the application. Deployment can also initialize stack-owned literal values from the release. The customer supplies parameters the stack only reads during installation; that secret-supply path is distinct from runtime parameter management.

Provider storage, access permissions, reconciliation, and durable-state availability affect operation. Historical direct-proxy measurements describe their recorded request path; they do not establish Max latency, throughput, or per-read provider charges.

## On Scaleway

### Scaleway Secret Manager

| Operation                                            | Area       | Support      | Depth        | Notes                                                                                                                                                                                                                                                      |
| ---------------------------------------------------- | ---------- | ------------ | ------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Parameter names longer than the encoding allows      | Names      | Out of scope | Most usage   | Scaleway secret names are at most 255 characters and the hierarchy encoding expands each path character threefold, so a path-heavy name over roughly 85 characters is REFUSED - at compile time by the build, at run time by the adapter - never truncated |
| Hierarchies & by-path reads (GetParametersByPath)    | Parameters | Partial      | Common       | supported, but served by listing secrets 100 at a time and filtering in the adapter rather than by the provider - see the path note below for why the native path field is deliberately not used                                                           |
| Parameter reads (GetParameter)                       | Parameters | Supported    | Common       | each parameter is one Scaleway secret; the value and its type ride the payload, so a read returns the value and the original String / StringList / SecureString marker                                                                                     |
| Parameter writes & deletes                           | Parameters | Supported    | Common       | a write adds a new Scaleway secret revision; the SSM version number IS that revision, so versions advance monotonically as AWS callers expect                                                                                                              |
| Parameter policies & Advanced tier                   | Policies   | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                                                                                                               |
| The wider Systems Manager suite                      | Scope      | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management and documents remain out of scope                                                                                                                                              |
| Custom encryption keys (KeyId)                       | Types      | Out of scope | Most usage   | a per-parameter customer KMS key is not served on this path; Secret Manager applies its own encryption at rest                                                                                                                                             |
| Parameter types (String / StringList / SecureString) | Types      | Partial      | Common       | all three markers survive a round trip through the adapter, but the STORE no longer distinguishes them: every parameter is a Secret Manager secret, encrypted at rest whichever tier it came from                                                          |

## Existing data and credentials

Selecting a backend does not copy existing data, credentials or access policies. Plan and verify migration separately before changing an application's endpoint. Do not assume an identifier, credential or encrypted value from the origin service works unchanged on the target.

## Configure, tune and debug

Start with [setup](/cloud-adapter/getting-started/overview) and [configuration](/cloud-adapter/configuration/overview). Use [tuning](/cloud-adapter/tuning/overview) to understand supported request tags, [debugging](/cloud-adapter/debugging/overview) to investigate a request, and [High Fidelity Cloud Emulators](/cloud-adapter/local-testing/overview) to validate a bounded reproduction.
