> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tensor9.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Secrets Manager

> Secrets Manager APIs with Cloud Adapter.

This page describes how Secrets Manager maps to services in the environment where the application runs. Some profiles adapt origin API calls; others translate infrastructure or document target-native behavior.

## Supported environments

| Environment        | Mapping |
| ------------------ | ------- |
| Akamai             | API     |
| Azure              | API     |
| Google Cloud       | API     |
| OCI                | API     |
| Private Kubernetes | API     |
| Scaleway           | API     |

API means the profile adapts origin API behavior. Infrastructure means the profile changes provisioned resources or documents a target-native alternative without promising an origin API endpoint. Check the operation and capability tables for the behavior your application depends on.

## How the targets compare

Each row compares a capability of Secrets Manager with its adaptation on each target.
A dash means this profile does not state the capability for that target.

### Cloud Adapter

| Capability                                                     | Secrets Manager | Akamai, Private Kubernetes, and Scaleway · Kubernetes Secret                                                                             | Azure                                                                                                                                    | Google Cloud                                                                                                                             | OCI                                                                                                                                      | Scaleway · Scaleway Secret Manager                                                                                                       |
| -------------------------------------------------------------- | --------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| Version stages · current / pending / previous                  | Yes             | Yes - stage labels and immutable versions are maintained in adapter state                                                                | Yes - stage labels and immutable versions are maintained in adapter state                                                                | Yes - stage labels and immutable versions are maintained in adapter state                                                                | Yes - stage labels and immutable versions are maintained in adapter state                                                                | Yes - stage labels and immutable versions are maintained in adapter state                                                                |
| Secret rotation · function-driven rotation                     | Yes             | Yes - four-step rotation through a connected Lambda adapter and supplied function                                                        | Yes - four-step rotation through a connected Lambda adapter and supplied function                                                        | Yes - four-step rotation through a connected Lambda adapter and supplied function                                                        | Yes - four-step rotation through a connected Lambda adapter and supplied function                                                        | Yes - four-step rotation through a connected Lambda adapter and supplied function                                                        |
| Recovery window · scheduled deletion                           | Yes             | Yes - 7-30 days in adapter state; target cleanup is separate                                                                             | Yes - 7-30 days in adapter state; target cleanup is separate                                                                             | Yes - 7-30 days in adapter state; target cleanup is separate                                                                             | Yes - 7-30 days in adapter state; target cleanup is separate                                                                             | Yes - 7-30 days in adapter state; target cleanup is separate                                                                             |
| Per-secret encryption key · customer-managed key configuration | Yes             | Partial - depends on protection of adapter state and target key configuration; KmsKeyId metadata alone does not select an encryption key | Partial - depends on protection of adapter state and target key configuration; KmsKeyId metadata alone does not select an encryption key | Partial - depends on protection of adapter state and target key configuration; KmsKeyId metadata alone does not select an encryption key | Partial - depends on protection of adapter state and target key configuration; KmsKeyId metadata alone does not select an encryption key | Partial - depends on protection of adapter state and target key configuration; KmsKeyId metadata alone does not select an encryption key |
| Cross-region replication · physical copies                     | Yes             | Partial - region settings are retained; configure and verify physical target replication separately                                      | Partial - region settings are retained; configure and verify physical target replication separately                                      | Partial - region settings are retained; configure and verify physical target replication separately                                      | Partial - region settings are retained; configure and verify physical target replication separately                                      | Partial - region settings are retained; configure and verify physical target replication separately                                      |
| Binary + string values · value payload                         | Yes             | Yes - string and binary values retained in the secret record                                                                             | Partial - target-encoded value must fit Key Vault's 25 KiB limit                                                                         | Yes - string and binary values retained in the secret record                                                                             | Yes - string and binary values retained in the secret record                                                                             | Yes - string and binary values retained in the secret record                                                                             |
| Tags · key/value metadata                                      | Yes             | Yes - source tags retained in adapter state without provider label normalization                                                         | Yes - source tags retained in adapter state without provider label normalization                                                         | Yes - source tags retained in adapter state without provider label normalization                                                         | Yes - source tags retained in adapter state without provider label normalization                                                         | Yes - source tags retained in adapter state without provider label normalization                                                         |
| API coverage                                                   | full            | high                                                                                                                                     | high                                                                                                                                     | high                                                                                                                                     | high                                                                                                                                     | high                                                                                                                                     |

## On Akamai, Private Kubernetes, and Scaleway

### Kubernetes Secret

| Operation                    | Area            | Support      | Depth        | Notes                                                                                                              |
| ---------------------------- | --------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------ |
| BatchGetSecretValue          | Bulk & generate | Supported    | Most usage   | reads requested secrets from their records with list/filter selection                                              |
| GetRandomPassword            | Bulk & generate | Supported    | Most usage   | generates a password using the operating system's secure random source and requested character rules               |
| ListSecrets                  | Listing & tags  | Supported    | Common       | lists and filters caller-scoped records, excluding deleted secrets                                                 |
| TagResource                  | Listing & tags  | Supported    | Full surface | retains source tags verbatim; deployment directive tags cannot be mutated                                          |
| UntagResource                | Listing & tags  | Supported    | Full surface | removes source tags; deployment directive tags are protected                                                       |
| RemoveRegionsFromReplication | Replication     | Partial      | Full surface | removes region entries from the secret record; physical target replicas are managed separately                     |
| ReplicateSecretToRegions     | Replication     | Partial      | Most usage   | retains requested region configuration; physical copies require separately configured target replication           |
| StopReplicationToReplica     | Replication     | Out of scope | Full surface | this adapter serves primary records and does not promote an independent regional replica                           |
| DeleteResourcePolicy         | Resource policy | Supported    | Full surface | removes the policy document from the secret record                                                                 |
| GetResourcePolicy            | Resource policy | Supported    | Full surface | returns the stored source policy document                                                                          |
| PutResourcePolicy            | Resource policy | Partial      | Full surface | stores and validates the policy; full resource-policy enforcement is separate from policy management               |
| ValidateResourcePolicy       | Resource policy | Partial      | Full surface | checks syntax, public access, and administrative lockout; does not promise AWS's complete policy analysis          |
| CancelRotateSecret           | Rotation        | Supported    | Full surface | disables rotation and withdraws its run; pending labels remain for the caller to resolve                           |
| RotateSecret                 | Rotation        | Supported    | Most usage   | runs the four-step protocol; the connected Lambda adapter must be able to invoke the supplied function             |
| CreateSecret                 | Secret CRUD     | Supported    | Common       | creates durable secret state and the initial version; target-specific value and key constraints still apply        |
| DeleteSecret                 | Secret CRUD     | Supported    | Common       | records a 7-30 day recovery window, default 30; force deletion withdraws the record while target cleanup follows   |
| DescribeSecret               | Secret CRUD     | Supported    | Common       | reports the secret record, including version stages, deletion, rotation, and replica configuration                 |
| GetSecretValue               | Secret CRUD     | Supported    | Common       | reads the requested version or stage from durable state; scheduled deletion blocks reads                           |
| PutSecretValue               | Secret CRUD     | Supported    | Common       | adds an immutable version with idempotency-token checks and updates stages                                         |
| RestoreSecret                | Secret CRUD     | Supported    | Most usage   | cancels scheduled deletion before the recovery window expires                                                      |
| UpdateSecret                 | Secret CRUD     | Supported    | Most usage   | updates metadata or adds a value version; an encryption-key ID must be distinguished from target key configuration |
| ListSecretVersionIds         | Versioning      | Supported    | Most usage   | lists immutable versions and their stage labels from the record                                                    |
| UpdateSecretVersionStage     | Versioning      | Supported    | Most usage   | moves source stage labels independently of provider-native aliases                                                 |

#### Requests, versions, and deletion

Your application sends AWS Secrets Manager requests to the Tensor9 adapter in the target environment. The adapter keeps a durable record containing the secret's values, version IDs, stage labels, tags, and lifecycle settings. Reads use that record; they do not select whichever version happens to be latest in the target store.

`PutSecretValue` creates an immutable version. `AWSCURRENT`, `AWSPENDING`, `AWSPREVIOUS`, and custom labels select versions in the record. Moving a label changes which value a read returns. A repeated request token with the same value returns the earlier result; reusing the token with a different value is rejected.

Scheduled deletion blocks reads for a recoverable period of 7-30 days, with 30 days as the default. `RestoreSecret` cancels that deletion before the window expires. Force deletion removes the secret from the API immediately; removal of any target copy is completed separately.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NTAiIGhlaWdodD0iMTkwIiB2aWV3Qm94PSIwIDAgNjUwIDE5MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHVzZSBkdXJhYmxlIGFkYXB0ZXIgc3RhdGUgd2l0aG91dCBhIHNlcGFyYXRlIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIyMCIgeT0iNTUiIHdpZHRoPSIxODUiIGhlaWdodD0iODAiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjExMiIgeT0iODgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSIxMTIiIHk9IjExMyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPlNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxwYXRoIGQ9Ik0yMDUsOTUgSDMwMCBsLTksLTUgbTksNSBsLTksNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz4KPHJlY3QgeD0iMzA1IiB5PSIyNSIgd2lkdGg9IjMyNSIgaGVpZ2h0PSIxNDAiIHJ4PSIxMiIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjQ2NyIgeT0iNTkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5EdXJhYmxlIGFkYXB0ZXIgc3RhdGU8L3RleHQ+Cjx0ZXh0IHg9IjQ2NyIgeT0iODUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSI0NjciIHk9IjEwOCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iNDY3IiB5PSIxMzciIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPm5vIGFkZGl0aW9uYWwgS3ViZXJuZXRlcyBTZWNyZXQ8L3RleHQ+Cjwvc3ZnPg==" alt="AWS Secrets Manager requests use durable adapter state without a separate target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NTAiIGhlaWdodD0iMTkwIiB2aWV3Qm94PSIwIDAgNjUwIDE5MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHVzZSBkdXJhYmxlIGFkYXB0ZXIgc3RhdGUgd2l0aG91dCBhIHNlcGFyYXRlIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIyMCIgeT0iNTUiIHdpZHRoPSIxODUiIGhlaWdodD0iODAiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjExMiIgeT0iODgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSIxMTIiIHk9IjExMyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPlNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxwYXRoIGQ9Ik0yMDUsOTUgSDMwMCBsLTksLTUgbTksNSBsLTksNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz4KPHJlY3QgeD0iMzA1IiB5PSIyNSIgd2lkdGg9IjMyNSIgaGVpZ2h0PSIxNDAiIHJ4PSIxMiIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjQ2NyIgeT0iNTkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5EdXJhYmxlIGFkYXB0ZXIgc3RhdGU8L3RleHQ+Cjx0ZXh0IHg9IjQ2NyIgeT0iODUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSI0NjciIHk9IjEwOCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iNDY3IiB5PSIxMzciIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPm5vIGFkZGl0aW9uYWwgS3ViZXJuZXRlcyBTZWNyZXQ8L3RleHQ+Cjwvc3ZnPg==" alt="AWS Secrets Manager requests use durable adapter state without a separate target copy." />
</div>

<p className="t9-caption">The adapter stores values and version history in its durable state.</p>

#### Rotation and access policies

The adapter runs the four rotation steps: create a candidate, update the credential at its source, test it, and make it current. Your rotation function performs the credential-specific work. The deployment must connect that function through the Lambda adapter; a rotation request is rejected when the configured function cannot be reached. Cancelling rotation stops the run but leaves the pending label for the caller to resolve.

Resource-policy operations store, return, delete, and validate the AWS policy document. Validation checks syntax, public access, and policies that would lock every caller out of policy administration. Those operations are distinct from complete resource-policy enforcement: the endpoint authorizes the authenticated principal, and target-store access uses the deployment's cloud identity. Review effective permissions when resource policies grant cross-account access or impose restrictions beyond the principal's permissions.

#### Target storage, encryption, and replication

The customer deployment stores the secret entirely in the adapter's durable state. This configuration creates no additional Kubernetes Secret. Version history and reads use the same secret record as cloud-backed deployments.

All versions and labels remain in the adapter's durable state. Protect that state store and its backups; no separate cloud secret copy is configured.

Encryption follows the deployment's storage and key configuration. The adapter retains `KmsKeyId` as metadata. Protect the durable state and configure any target copy to meet the workload's encryption-key requirements.

Replication requests maintain region configuration in the secret record. They do not by themselves establish a second physical copy or disaster recovery in another region. Configure and verify geographic replication of the underlying storage separately. This adapter serves primary secret records; `StopReplicationToReplica` does not promote an independent regional replica.

Storage durability, encryption, backups, and recovery depend on the Cloud Adapter deployment's state store. A Kubernetes namespace or an external synchronization controller does not provide that history.

#### Cutover and ongoing operation

Create the target deployment, load the required values through the Secrets Manager API, and verify current, previous, and explicitly versioned reads before switching the application. Existing provider values and their history are not automatically imported into the adapter's record.

Test credential rotation with the real database or API it updates, including a failed test step and a retried callback. Verify deletion and restore behavior before relying on the recovery window. The customer controls access to secret state, rotation-function permissions, backup retention, and monitoring.

## On Azure

### Key Vault

| Operation                    | Area            | Support      | Depth        | Notes                                                                                                              |
| ---------------------------- | --------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------ |
| BatchGetSecretValue          | Bulk & generate | Supported    | Most usage   | reads requested secrets from their records with list/filter selection                                              |
| GetRandomPassword            | Bulk & generate | Supported    | Most usage   | generates a password using the operating system's secure random source and requested character rules               |
| ListSecrets                  | Listing & tags  | Supported    | Common       | lists and filters caller-scoped records, excluding deleted secrets                                                 |
| TagResource                  | Listing & tags  | Supported    | Full surface | retains source tags verbatim; deployment directive tags cannot be mutated                                          |
| UntagResource                | Listing & tags  | Supported    | Full surface | removes source tags; deployment directive tags are protected                                                       |
| RemoveRegionsFromReplication | Replication     | Partial      | Full surface | removes region entries from the secret record; physical target replicas are managed separately                     |
| ReplicateSecretToRegions     | Replication     | Partial      | Most usage   | retains requested region configuration; physical copies require separately configured target replication           |
| StopReplicationToReplica     | Replication     | Out of scope | Full surface | this adapter serves primary records and does not promote an independent regional replica                           |
| DeleteResourcePolicy         | Resource policy | Supported    | Full surface | removes the policy document from the secret record                                                                 |
| GetResourcePolicy            | Resource policy | Supported    | Full surface | returns the stored source policy document                                                                          |
| PutResourcePolicy            | Resource policy | Partial      | Full surface | stores and validates the policy; full resource-policy enforcement is separate from policy management               |
| ValidateResourcePolicy       | Resource policy | Partial      | Full surface | checks syntax, public access, and administrative lockout; does not promise AWS's complete policy analysis          |
| CancelRotateSecret           | Rotation        | Supported    | Full surface | disables rotation and withdraws its run; pending labels remain for the caller to resolve                           |
| RotateSecret                 | Rotation        | Supported    | Most usage   | runs the four-step protocol; the connected Lambda adapter must be able to invoke the supplied function             |
| CreateSecret                 | Secret CRUD     | Supported    | Common       | creates durable secret state and the initial version; target-specific value and key constraints still apply        |
| DeleteSecret                 | Secret CRUD     | Supported    | Common       | records a 7-30 day recovery window, default 30; force deletion withdraws the record while target cleanup follows   |
| DescribeSecret               | Secret CRUD     | Supported    | Common       | reports the secret record, including version stages, deletion, rotation, and replica configuration                 |
| GetSecretValue               | Secret CRUD     | Supported    | Common       | reads the requested version or stage from durable state; scheduled deletion blocks reads                           |
| PutSecretValue               | Secret CRUD     | Supported    | Common       | adds an immutable version with idempotency-token checks and updates stages                                         |
| RestoreSecret                | Secret CRUD     | Supported    | Most usage   | cancels scheduled deletion before the recovery window expires                                                      |
| UpdateSecret                 | Secret CRUD     | Supported    | Most usage   | updates metadata or adds a value version; an encryption-key ID must be distinguished from target key configuration |
| ListSecretVersionIds         | Versioning      | Supported    | Most usage   | lists immutable versions and their stage labels from the record                                                    |
| UpdateSecretVersionStage     | Versioning      | Supported    | Most usage   | moves source stage labels independently of provider-native aliases                                                 |

#### Requests, versions, and deletion

Your application sends AWS Secrets Manager requests to the Tensor9 adapter in the target environment. The adapter keeps a durable record containing the secret's values, version IDs, stage labels, tags, and lifecycle settings. Reads use that record; they do not select whichever version happens to be latest in the target store.

`PutSecretValue` creates an immutable version. `AWSCURRENT`, `AWSPENDING`, `AWSPREVIOUS`, and custom labels select versions in the record. Moving a label changes which value a read returns. A repeated request token with the same value returns the earlier result; reusing the token with a different value is rejected.

Scheduled deletion blocks reads for a recoverable period of 7-30 days, with 30 days as the default. `RestoreSecret` cancels that deletion before the window expires. Force deletion removes the secret from the API immediately; removal of any target copy is completed separately.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICM2NDc0OGIiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjZmZmIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmE7IGZvbnQtc2l6ZToxMXB4Ij5BenVyZSBLZXkgVmF1bHQ8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICNjOWNmZDgiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjMjYyNjI2IiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDg7IGZvbnQtc2l6ZToxMXB4Ij5BenVyZSBLZXkgVmF1bHQ8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />
</div>

<p className="t9-caption">AWS version history stays in the record; the target copy follows its current value.</p>

#### Rotation and access policies

The adapter runs the four rotation steps: create a candidate, update the credential at its source, test it, and make it current. Your rotation function performs the credential-specific work. The deployment must connect that function through the Lambda adapter; a rotation request is rejected when the configured function cannot be reached. Cancelling rotation stops the run but leaves the pending label for the caller to resolve.

Resource-policy operations store, return, delete, and validate the AWS policy document. Validation checks syntax, public access, and policies that would lock every caller out of policy administration. Those operations are distinct from complete resource-policy enforcement: the endpoint authorizes the authenticated principal, and target-store access uses the deployment's cloud identity. Review effective permissions when resource policies grant cross-account access or impose restrictions beyond the principal's permissions.

#### Target storage, encryption, and replication

Azure Key Vault stores the current value under the deployment's Azure identity. A version tag tracks the adapter revision because Key Vault's native version IDs are opaque. The adapter retains AWS version history and stage labels independently.

The adapter's durable record retains all versions and labels. Reconciliation writes the current value and its revision to Azure Key Vault. Direct edits to that copy do not update AWS version history and can be overwritten. Protect and back up adapter state as well as the target store.

Encryption follows the deployment's storage and key configuration. The adapter retains `KmsKeyId` as metadata. Protect the durable state and configure any target copy to meet the workload's encryption-key requirements.

Replication requests maintain region configuration in the secret record. They do not by themselves establish a second physical copy or disaster recovery in another region. Configure and verify geographic replication of the underlying storage separately. This adapter serves primary secret records; `StopReplicationToReplica` does not promote an independent regional replica.

Key Vault limits a stored value to 25 KiB; encoded binary content must fit that limit. This target's deletion and name-reuse workflow requires purge permission. A purge-protected vault can block final removal or reuse of a deleted name. AWS scheduled deletion is handled by the adapter before this target cleanup begins.

#### Cutover and ongoing operation

Create the target deployment, load the required values through the Secrets Manager API, and verify current, previous, and explicitly versioned reads before switching the application. Existing provider values and their history are not automatically imported into the adapter's record.

Test credential rotation with the real database or API it updates, including a failed test step and a retried callback. Verify deletion and restore behavior before relying on the recovery window. The customer controls access to secret state, rotation-function permissions, backup retention, and monitoring.

## On Google Cloud

### Google Secret Manager

| Operation                    | Area            | Support      | Depth        | Notes                                                                                                              |
| ---------------------------- | --------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------ |
| BatchGetSecretValue          | Bulk & generate | Supported    | Most usage   | reads requested secrets from their records with list/filter selection                                              |
| GetRandomPassword            | Bulk & generate | Supported    | Most usage   | generates a password using the operating system's secure random source and requested character rules               |
| ListSecrets                  | Listing & tags  | Supported    | Common       | lists and filters caller-scoped records, excluding deleted secrets                                                 |
| TagResource                  | Listing & tags  | Supported    | Full surface | retains source tags verbatim; deployment directive tags cannot be mutated                                          |
| UntagResource                | Listing & tags  | Supported    | Full surface | removes source tags; deployment directive tags are protected                                                       |
| RemoveRegionsFromReplication | Replication     | Partial      | Full surface | removes region entries from the secret record; physical target replicas are managed separately                     |
| ReplicateSecretToRegions     | Replication     | Partial      | Most usage   | retains requested region configuration; physical copies require separately configured target replication           |
| StopReplicationToReplica     | Replication     | Out of scope | Full surface | this adapter serves primary records and does not promote an independent regional replica                           |
| DeleteResourcePolicy         | Resource policy | Supported    | Full surface | removes the policy document from the secret record                                                                 |
| GetResourcePolicy            | Resource policy | Supported    | Full surface | returns the stored source policy document                                                                          |
| PutResourcePolicy            | Resource policy | Partial      | Full surface | stores and validates the policy; full resource-policy enforcement is separate from policy management               |
| ValidateResourcePolicy       | Resource policy | Partial      | Full surface | checks syntax, public access, and administrative lockout; does not promise AWS's complete policy analysis          |
| CancelRotateSecret           | Rotation        | Supported    | Full surface | disables rotation and withdraws its run; pending labels remain for the caller to resolve                           |
| RotateSecret                 | Rotation        | Supported    | Most usage   | runs the four-step protocol; the connected Lambda adapter must be able to invoke the supplied function             |
| CreateSecret                 | Secret CRUD     | Supported    | Common       | creates durable secret state and the initial version; target-specific value and key constraints still apply        |
| DeleteSecret                 | Secret CRUD     | Supported    | Common       | records a 7-30 day recovery window, default 30; force deletion withdraws the record while target cleanup follows   |
| DescribeSecret               | Secret CRUD     | Supported    | Common       | reports the secret record, including version stages, deletion, rotation, and replica configuration                 |
| GetSecretValue               | Secret CRUD     | Supported    | Common       | reads the requested version or stage from durable state; scheduled deletion blocks reads                           |
| PutSecretValue               | Secret CRUD     | Supported    | Common       | adds an immutable version with idempotency-token checks and updates stages                                         |
| RestoreSecret                | Secret CRUD     | Supported    | Most usage   | cancels scheduled deletion before the recovery window expires                                                      |
| UpdateSecret                 | Secret CRUD     | Supported    | Most usage   | updates metadata or adds a value version; an encryption-key ID must be distinguished from target key configuration |
| ListSecretVersionIds         | Versioning      | Supported    | Most usage   | lists immutable versions and their stage labels from the record                                                    |
| UpdateSecretVersionStage     | Versioning      | Supported    | Most usage   | moves source stage labels independently of provider-native aliases                                                 |

#### Requests, versions, and deletion

Your application sends AWS Secrets Manager requests to the Tensor9 adapter in the target environment. The adapter keeps a durable record containing the secret's values, version IDs, stage labels, tags, and lifecycle settings. Reads use that record; they do not select whichever version happens to be latest in the target store.

`PutSecretValue` creates an immutable version. `AWSCURRENT`, `AWSPENDING`, `AWSPREVIOUS`, and custom labels select versions in the record. Moving a label changes which value a read returns. A repeated request token with the same value returns the earlier result; reusing the token with a different value is rejected.

Scheduled deletion blocks reads for a recoverable period of 7-30 days, with 30 days as the default. `RestoreSecret` cancels that deletion before the window expires. Force deletion removes the secret from the API immediately; removal of any target copy is completed separately.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICM2NDc0OGIiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjZmZmIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmE7IGZvbnQtc2l6ZToxMXB4Ij5Hb29nbGUgU2VjcmV0IE1hbmFnZXI8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICNjOWNmZDgiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjMjYyNjI2IiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDg7IGZvbnQtc2l6ZToxMXB4Ij5Hb29nbGUgU2VjcmV0IE1hbmFnZXI8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />
</div>

<p className="t9-caption">AWS version history stays in the record; the target copy follows its current value.</p>

#### Rotation and access policies

The adapter runs the four rotation steps: create a candidate, update the credential at its source, test it, and make it current. Your rotation function performs the credential-specific work. The deployment must connect that function through the Lambda adapter; a rotation request is rejected when the configured function cannot be reached. Cancelling rotation stops the run but leaves the pending label for the caller to resolve.

Resource-policy operations store, return, delete, and validate the AWS policy document. Validation checks syntax, public access, and policies that would lock every caller out of policy administration. Those operations are distinct from complete resource-policy enforcement: the endpoint authorizes the authenticated principal, and target-store access uses the deployment's cloud identity. Review effective permissions when resource policies grant cross-account access or impose restrictions beyond the principal's permissions.

#### Target storage, encryption, and replication

Google Secret Manager stores the current value under the deployment's Google identity. Its numbered versions are target revisions, not the source of AWS stage selection. Google replication and encryption settings govern that provider copy.

The adapter's durable record retains all versions and labels. Reconciliation writes the current value and its revision to Google Secret Manager. Direct edits to that copy do not update AWS version history and can be overwritten. Protect and back up adapter state as well as the target store.

Encryption follows the deployment's storage and key configuration. The adapter retains `KmsKeyId` as metadata. Protect the durable state and configure any target copy to meet the workload's encryption-key requirements.

Replication requests maintain region configuration in the secret record. They do not by themselves establish a second physical copy or disaster recovery in another region. Configure and verify geographic replication of the underlying storage separately. This adapter serves primary secret records; `StopReplicationToReplica` does not promote an independent regional replica.

Google's native replication policy is chosen when its secret is created. AWS stage moves and delayed deletion are handled in the adapter's record, so they do not require corresponding Google aliases or a native secret recovery window.

#### Cutover and ongoing operation

Create the target deployment, load the required values through the Secrets Manager API, and verify current, previous, and explicitly versioned reads before switching the application. Existing provider values and their history are not automatically imported into the adapter's record.

Test credential rotation with the real database or API it updates, including a failed test step and a retried callback. Verify deletion and restore behavior before relying on the recovery window. The customer controls access to secret state, rotation-function permissions, backup retention, and monitoring.

## On OCI

### OCI Vault

| Operation                    | Area            | Support      | Depth        | Notes                                                                                                              |
| ---------------------------- | --------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------ |
| BatchGetSecretValue          | Bulk & generate | Supported    | Most usage   | reads requested secrets from their records with list/filter selection                                              |
| GetRandomPassword            | Bulk & generate | Supported    | Most usage   | generates a password using the operating system's secure random source and requested character rules               |
| ListSecrets                  | Listing & tags  | Supported    | Common       | lists and filters caller-scoped records, excluding deleted secrets                                                 |
| TagResource                  | Listing & tags  | Supported    | Full surface | retains source tags verbatim; deployment directive tags cannot be mutated                                          |
| UntagResource                | Listing & tags  | Supported    | Full surface | removes source tags; deployment directive tags are protected                                                       |
| RemoveRegionsFromReplication | Replication     | Partial      | Full surface | removes region entries from the secret record; physical target replicas are managed separately                     |
| ReplicateSecretToRegions     | Replication     | Partial      | Most usage   | retains requested region configuration; physical copies require separately configured target replication           |
| StopReplicationToReplica     | Replication     | Out of scope | Full surface | this adapter serves primary records and does not promote an independent regional replica                           |
| DeleteResourcePolicy         | Resource policy | Supported    | Full surface | removes the policy document from the secret record                                                                 |
| GetResourcePolicy            | Resource policy | Supported    | Full surface | returns the stored source policy document                                                                          |
| PutResourcePolicy            | Resource policy | Partial      | Full surface | stores and validates the policy; full resource-policy enforcement is separate from policy management               |
| ValidateResourcePolicy       | Resource policy | Partial      | Full surface | checks syntax, public access, and administrative lockout; does not promise AWS's complete policy analysis          |
| CancelRotateSecret           | Rotation        | Supported    | Full surface | disables rotation and withdraws its run; pending labels remain for the caller to resolve                           |
| RotateSecret                 | Rotation        | Supported    | Most usage   | runs the four-step protocol; the connected Lambda adapter must be able to invoke the supplied function             |
| CreateSecret                 | Secret CRUD     | Supported    | Common       | creates durable secret state and the initial version; target-specific value and key constraints still apply        |
| DeleteSecret                 | Secret CRUD     | Supported    | Common       | records a 7-30 day recovery window, default 30; force deletion withdraws the record while target cleanup follows   |
| DescribeSecret               | Secret CRUD     | Supported    | Common       | reports the secret record, including version stages, deletion, rotation, and replica configuration                 |
| GetSecretValue               | Secret CRUD     | Supported    | Common       | reads the requested version or stage from durable state; scheduled deletion blocks reads                           |
| PutSecretValue               | Secret CRUD     | Supported    | Common       | adds an immutable version with idempotency-token checks and updates stages                                         |
| RestoreSecret                | Secret CRUD     | Supported    | Most usage   | cancels scheduled deletion before the recovery window expires                                                      |
| UpdateSecret                 | Secret CRUD     | Supported    | Most usage   | updates metadata or adds a value version; an encryption-key ID must be distinguished from target key configuration |
| ListSecretVersionIds         | Versioning      | Supported    | Most usage   | lists immutable versions and their stage labels from the record                                                    |
| UpdateSecretVersionStage     | Versioning      | Supported    | Most usage   | moves source stage labels independently of provider-native aliases                                                 |

#### Requests, versions, and deletion

Your application sends AWS Secrets Manager requests to the Tensor9 adapter in the target environment. The adapter keeps a durable record containing the secret's values, version IDs, stage labels, tags, and lifecycle settings. Reads use that record; they do not select whichever version happens to be latest in the target store.

`PutSecretValue` creates an immutable version. `AWSCURRENT`, `AWSPENDING`, `AWSPREVIOUS`, and custom labels select versions in the record. Moving a label changes which value a read returns. A repeated request token with the same value returns the earlier result; reusing the token with a different value is rejected.

Scheduled deletion blocks reads for a recoverable period of 7-30 days, with 30 days as the default. `RestoreSecret` cancels that deletion before the window expires. Force deletion removes the secret from the API immediately; removal of any target copy is completed separately.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICM2NDc0OGIiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjZmZmIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmE7IGZvbnQtc2l6ZToxMXB4Ij5PQ0kgVmF1bHQ8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICNjOWNmZDgiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjMjYyNjI2IiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDg7IGZvbnQtc2l6ZToxMXB4Ij5PQ0kgVmF1bHQ8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />
</div>

<p className="t9-caption">AWS version history stays in the record; the target copy follows its current value.</p>

#### Rotation and access policies

The adapter runs the four rotation steps: create a candidate, update the credential at its source, test it, and make it current. Your rotation function performs the credential-specific work. The deployment must connect that function through the Lambda adapter; a rotation request is rejected when the configured function cannot be reached. Cancelling rotation stops the run but leaves the pending label for the caller to resolve.

Resource-policy operations store, return, delete, and validate the AWS policy document. Validation checks syntax, public access, and policies that would lock every caller out of policy administration. Those operations are distinct from complete resource-policy enforcement: the endpoint authorizes the authenticated principal, and target-store access uses the deployment's cloud identity. Review effective permissions when resource policies grant cross-account access or impose restrictions beyond the principal's permissions.

#### Target storage, encryption, and replication

OCI Vault is the target store for the current secret value in this mapping. OCI requires an encryption key for the vault secret and provides its own version stages and replication settings. The adapter owns AWS history and stage selection, independently of those native features.

The adapter's durable record retains all versions and labels. Reconciliation writes the current value and its revision to OCI Vault. Direct edits to that copy do not update AWS version history and can be overwritten. Protect and back up adapter state as well as the target store.

Encryption follows the deployment's storage and key configuration. The adapter retains `KmsKeyId` as metadata. Protect the durable state and configure any target copy to meet the workload's encryption-key requirements.

Replication requests maintain region configuration in the secret record. They do not by themselves establish a second physical copy or disaster recovery in another region. Configure and verify geographic replication of the underlying storage separately. This adapter serves primary secret records; `StopReplicationToReplica` does not promote an independent regional replica.

Configure the OCI key and any geographic replication for the provider copy. OCI's native scheduled-deletion rules can delay physical removal after the AWS API has withdrawn a secret. These target rules do not replace the adapter's deletion window or create an independent AWS regional replica.

#### Cutover and ongoing operation

Create the target deployment, load the required values through the Secrets Manager API, and verify current, previous, and explicitly versioned reads before switching the application. Existing provider values and their history are not automatically imported into the adapter's record.

Test credential rotation with the real database or API it updates, including a failed test step and a retried callback. Verify deletion and restore behavior before relying on the recovery window. The customer controls access to secret state, rotation-function permissions, backup retention, and monitoring.

## On Scaleway

### Scaleway Secret Manager

| Operation                    | Area            | Support      | Depth        | Notes                                                                                                              |
| ---------------------------- | --------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------ |
| BatchGetSecretValue          | Bulk & generate | Supported    | Most usage   | reads requested secrets from their records with list/filter selection                                              |
| GetRandomPassword            | Bulk & generate | Supported    | Most usage   | generates a password using the operating system's secure random source and requested character rules               |
| ListSecrets                  | Listing & tags  | Supported    | Common       | lists and filters caller-scoped records, excluding deleted secrets                                                 |
| TagResource                  | Listing & tags  | Supported    | Full surface | retains source tags verbatim; deployment directive tags cannot be mutated                                          |
| UntagResource                | Listing & tags  | Supported    | Full surface | removes source tags; deployment directive tags are protected                                                       |
| RemoveRegionsFromReplication | Replication     | Partial      | Full surface | removes region entries from the secret record; physical target replicas are managed separately                     |
| ReplicateSecretToRegions     | Replication     | Partial      | Most usage   | retains requested region configuration; physical copies require separately configured target replication           |
| StopReplicationToReplica     | Replication     | Out of scope | Full surface | this adapter serves primary records and does not promote an independent regional replica                           |
| DeleteResourcePolicy         | Resource policy | Supported    | Full surface | removes the policy document from the secret record                                                                 |
| GetResourcePolicy            | Resource policy | Supported    | Full surface | returns the stored source policy document                                                                          |
| PutResourcePolicy            | Resource policy | Partial      | Full surface | stores and validates the policy; full resource-policy enforcement is separate from policy management               |
| ValidateResourcePolicy       | Resource policy | Partial      | Full surface | checks syntax, public access, and administrative lockout; does not promise AWS's complete policy analysis          |
| CancelRotateSecret           | Rotation        | Supported    | Full surface | disables rotation and withdraws its run; pending labels remain for the caller to resolve                           |
| RotateSecret                 | Rotation        | Supported    | Most usage   | runs the four-step protocol; the connected Lambda adapter must be able to invoke the supplied function             |
| CreateSecret                 | Secret CRUD     | Supported    | Common       | creates durable secret state and the initial version; target-specific value and key constraints still apply        |
| DeleteSecret                 | Secret CRUD     | Supported    | Common       | records a 7-30 day recovery window, default 30; force deletion withdraws the record while target cleanup follows   |
| DescribeSecret               | Secret CRUD     | Supported    | Common       | reports the secret record, including version stages, deletion, rotation, and replica configuration                 |
| GetSecretValue               | Secret CRUD     | Supported    | Common       | reads the requested version or stage from durable state; scheduled deletion blocks reads                           |
| PutSecretValue               | Secret CRUD     | Supported    | Common       | adds an immutable version with idempotency-token checks and updates stages                                         |
| RestoreSecret                | Secret CRUD     | Supported    | Most usage   | cancels scheduled deletion before the recovery window expires                                                      |
| UpdateSecret                 | Secret CRUD     | Supported    | Most usage   | updates metadata or adds a value version; an encryption-key ID must be distinguished from target key configuration |
| ListSecretVersionIds         | Versioning      | Supported    | Most usage   | lists immutable versions and their stage labels from the record                                                    |
| UpdateSecretVersionStage     | Versioning      | Supported    | Most usage   | moves source stage labels independently of provider-native aliases                                                 |

#### Requests, versions, and deletion

Your application sends AWS Secrets Manager requests to the Tensor9 adapter in the target environment. The adapter keeps a durable record containing the secret's values, version IDs, stage labels, tags, and lifecycle settings. Reads use that record; they do not select whichever version happens to be latest in the target store.

`PutSecretValue` creates an immutable version. `AWSCURRENT`, `AWSPENDING`, `AWSPREVIOUS`, and custom labels select versions in the record. Moving a label changes which value a read returns. A repeated request token with the same value returns the earlier result; reusing the token with a different value is rejected.

Scheduled deletion blocks reads for a recoverable period of 7-30 days, with 30 days as the default. `RestoreSecret` cancels that deletion before the window expires. Force deletion removes the secret from the API immediately; removal of any target copy is completed separately.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICM2NDc0OGIiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjZmZmIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmE7IGZvbnQtc2l6ZToxMXB4Ij5TY2FsZXdheSBTZWNyZXQgTWFuYWdlcjwvdGV4dD4KPHRleHQgeD0iNzE1IiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5jdXJyZW50IHZhbHVlLCB3aGVyZSBjb25maWd1cmVkPC90ZXh0Pgo8L3N2Zz4=" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICNjOWNmZDgiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjMjYyNjI2IiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDg7IGZvbnQtc2l6ZToxMXB4Ij5TY2FsZXdheSBTZWNyZXQgTWFuYWdlcjwvdGV4dD4KPHRleHQgeD0iNzE1IiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5jdXJyZW50IHZhbHVlLCB3aGVyZSBjb25maWd1cmVkPC90ZXh0Pgo8L3N2Zz4=" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />
</div>

<p className="t9-caption">AWS version history stays in the record; the target copy follows its current value.</p>

#### Rotation and access policies

The adapter runs the four rotation steps: create a candidate, update the credential at its source, test it, and make it current. Your rotation function performs the credential-specific work. The deployment must connect that function through the Lambda adapter; a rotation request is rejected when the configured function cannot be reached. Cancelling rotation stops the run but leaves the pending label for the caller to resolve.

Resource-policy operations store, return, delete, and validate the AWS policy document. Validation checks syntax, public access, and policies that would lock every caller out of policy administration. Those operations are distinct from complete resource-policy enforcement: the endpoint authorizes the authenticated principal, and target-store access uses the deployment's cloud identity. Review effective permissions when resource policies grant cross-account access or impose restrictions beyond the principal's permissions.

#### Target storage, encryption, and replication

Scaleway Secret Manager is the target store for the current secret value in this mapping: one Scaleway secret per logical secret, and the adapter's declared version is carried as that secret's REVISION. A read resolves the newest ENABLED revision; a write appends one enabled revision when the target is behind. The adapter owns AWS history and stage selection independently of Scaleway's own revision numbering, and never reads a stored payload back out of Scaleway -- values are served from the adapter's own record.

The adapter's durable record retains all versions and labels. Reconciliation writes the current value and its revision to Scaleway Secret Manager. Direct edits to that copy do not update AWS version history and can be overwritten. Protect and back up adapter state as well as the target store.

Encryption follows the deployment's storage and key configuration. The adapter retains `KmsKeyId` as metadata. Protect the durable state and configure any target copy to meet the workload's encryption-key requirements.

Replication requests maintain region configuration in the secret record. They do not by themselves establish a second physical copy or disaster recovery in another region. Configure and verify geographic replication of the underlying storage separately. This adapter serves primary secret records; `StopReplicationToReplica` does not promote an independent regional replica.

YOUR SECRET NAMES ARE TRANSFORMED, and this is the one thing to know before you go looking in the Scaleway console. Scaleway's name grammar admits only letters, digits, dot, dash and underscore, so the commonest AWS shape -- `prod/db/password` -- is rejected outright at create. The adapter therefore encodes each name: lower-case letters and digits are kept and every other byte becomes `_` plus two hex digits, so `a/b` and `a_b` stay distinct, and an encoding over 255 characters folds to a 200-character prefix plus a short hash. The secret you named `prod/db/password` exists, holds the right value, and is listed under its encoded name. Two smaller differences: Scaleway tags are a flat list of strings rather than key/value pairs, so AWS tag pairs are encoded into that shape; and a secret whose every revision is disabled resolves to nothing, which the adapter reads as absent and repairs by appending a fresh enabled revision rather than by reusing a disabled one.

#### Cutover and ongoing operation

Create the target deployment, load the required values through the Secrets Manager API, and verify current, previous, and explicitly versioned reads before switching the application. Existing provider values and their history are not automatically imported into the adapter's record.

Test credential rotation with the real database or API it updates, including a failed test step and a retried callback. Verify deletion and restore behavior before relying on the recovery window. The customer controls access to secret state, rotation-function permissions, backup retention, and monitoring.

## Existing data and credentials

Selecting a backend does not copy existing data, credentials or access policies. Plan and verify migration separately before changing an application's endpoint. Do not assume an identifier, credential or encrypted value from the origin service works unchanged on the target.

## Configure, tune and debug

Start with [setup](/cloud-adapter/getting-started/overview) and [configuration](/cloud-adapter/configuration/overview). Use [tuning](/cloud-adapter/tuning/overview) to understand supported request tags, [debugging](/cloud-adapter/debugging/overview) to investigate a request, and [High Fidelity Cloud Emulators](/cloud-adapter/local-testing/overview) to validate a bounded reproduction.
