> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tensor9.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Systems Manager (SSM)

> AWS Systems Manager (SSM). Manages fleets of instances: inventory, patch baselines, remote shell sessions, Run Command documents, and Parameter Store for configuration values.

**On this page**

* [Coverage by target cloud](#coverage-by-target-cloud)
* [How the targets compare](#how-the-targets-compare)
  * [Max adaptation](#max-adaptation)
* [On Google Cloud](#on-google-cloud)
  * [Via Google Parameter Manager](#via-google-parameter-manager)
  * [Via Secret Manager](#via-secret-manager)
* [On Azure](#on-azure)
* [On OCI](#on-oci)
* [On Private Kubernetes](#on-private-kubernetes)

## Coverage by target cloud

| Target             | Available |
| ------------------ | --------- |
| Google Cloud       | ✓         |
| Azure              | ✓         |
| OCI                | ✓         |
| Private Kubernetes | ✓         |

## How the targets compare

Each row compares a capability of Systems Manager (SSM) with its adaptation on each target.
A dash means this row is not stated for that target.

### Max adaptation

| Capability                                 | Systems Manager (SSM)        | Google Cloud · Google Parameter Manager                                                                                                        | Google Cloud · Secret Manager                                                                                                         | Azure                                                                                                                                                   | OCI                                                                                                                               | Private Kubernetes                                                                                                                                       |
| ------------------------------------------ | ---------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------- |
| API served · what your app calls           | Parameter Store API          | the same API, served from durable adapter state                                                                                                | the same API, served from durable adapter state                                                                                       | the same API, served from durable adapter state                                                                                                         | the same API, served from durable adapter state                                                                                   | the same API, served from durable adapter state                                                                                                          |
| Where parameters live · the backing store  | AWS-managed storage          | durable parameter records + Google Parameter Manager target copy                                                                               | durable parameter records + Google Secret Manager target copy                                                                         | durable parameter records + Azure App Configuration target copy                                                                                         | durable parameter records + OCI Vault target copy                                                                                 | durable parameter records + Kubernetes Secrets target copy                                                                                               |
| Encryption at rest · SecureString handling | KMS-encrypted SecureString   | all three type markers are retained in durable state; Parameter Manager encrypts its provider copy at rest; sensitivity follows actual values  | all three type markers are retained in durable state; Secret Manager encrypts its provider copy at rest                               | String and StringList are supported; SecureString remains outside the App Configuration mapping. Direct Key Vault access is a separate application path | all three type markers are retained in durable state; the configured OCI vault key encrypts the provider copy                     | all three type markers are retained; protect durable state and configure Kubernetes storage encryption. Base64 encoding does not encrypt the target copy |
| Path hierarchies · by-path reads           | native                       | caller-scoped record queries; no per-value provider reads                                                                                      | caller-scoped record queries; no per-value provider reads                                                                             | caller-scoped record queries; no per-value provider reads                                                                                               | caller-scoped record queries; no per-value provider reads                                                                         | caller-scoped record queries; no per-value provider reads                                                                                                |
| Versions & labels · history                | 100-version history + labels | retained values and adapter-owned label references provide parameter history and named labels; Parameter Manager has no native version aliases | retained values and adapter-owned label references provide parameter history and named labels; native aliases do not decide AWS reads | numeric history is retained; the adapter owns AWS version selection. Named SSM labels remain outside this mapping                                       | -                                                                                                                                 | only the latest value and increasing AWS version counter are retained; previous values and named labels are unsupported                                  |
| API coverage                               | full                         | partial                                                                                                                                        | partial                                                                                                                               | partial                                                                                                                                                 | partial                                                                                                                           | partial                                                                                                                                                  |
| Versions · history                         | 100-version history + labels | -                                                                                                                                              | -                                                                                                                                     | -                                                                                                                                                       | numeric history is retained; the adapter owns AWS version identity and selection independently of native OCI versionNumber values | -                                                                                                                                                        |
| Delete semantics · DeleteParameter         | immediate delete             | -                                                                                                                                              | -                                                                                                                                     | -                                                                                                                                                       | leaves AWS reads immediately; native secret cleanup is scheduled separately                                                       | -                                                                                                                                                        |

## On Google Cloud

### Via Google Parameter Manager

| Operation                                                   | Area           | Support      | Depth        | Notes                                                                                                                                                        |
| ----------------------------------------------------------- | -------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Consumed parameters (read-only references)                  | Build & deploy | Supported    | Common       | a parameter the stack reads but does not own is supplied by the customer during installation; that supply path is distinct from runtime parameter management |
| Filters & discovery (DescribeParameters / ParameterFilters) | Discovery      | Partial      | Full surface | DescribeParameters serves paginated metadata without values; complete ParameterFilters behavior is outside the documented contract                           |
| Change notifications                                        | Events         | Out of scope | Full surface | parameter-change events are outside this mapping                                                                                                             |
| Batch reads (GetParameters)                                 | Parameters     | Supported    | Common       | reads caller-scoped parameter records and partitions found and missing names                                                                                 |
| Hierarchies & by-path reads (GetParametersByPath)           | Parameters     | Supported    | Common       | queries live adapter records by path, applies recursion rules, and returns paginated results; no provider value fetch per returned parameter                 |
| Parameter reads (GetParameter)                              | Parameters     | Supported    | Common       | reads the current value, type, and AWS version from the caller-scoped durable parameter record; the target copy is reconciled separately                     |
| Parameter writes & deletes                                  | Parameters     | Supported    | Common       | PutParameter creates or updates durable parameter state and reconciles the target; DeleteParameter withdraws reads while target cleanup proceeds separately  |
| Parameter policies & Advanced tier                          | Policies       | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                 |
| Public & shared parameters                                  | Scope          | Out of scope | Full surface | AWS-published public parameters and cross-account shared parameters are outside this mapping                                                                 |
| The wider Systems Manager suite                             | Scope          | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management, and documents remain out of scope                                               |
| Custom encryption keys (KeyId)                              | Types          | Out of scope | Most usage   | custom per-parameter AWS KMS keys are unsupported; protect durable adapter state and configure the target copy independently                                 |
| Parameter types (String / StringList / SecureString)        | Types          | Supported    | Common       | all three type markers are retained in durable state; Parameter Manager encrypts its provider copy at rest; sensitivity follows actual values                |
| Reading ciphertext (WithDecryption=false)                   | Types          | Out of scope | Most usage   | SecureString reads require WithDecryption=true; the adapter does not return AWS KMS ciphertext                                                               |
| Versions & labels                                           | Versions       | Supported    | Most usage   | retained values and adapter-owned label references provide parameter history and named labels; Parameter Manager has no native version aliases               |

#### Requests and durable parameter state

With Max adaptation, your application sends Parameter Store requests in its AWS SDK to the Tensor9 adapter. The adapter keeps a durable parameter record containing the name, type, current value, version counter, description, and tags. Reads use that record. A background worker reconciles its current value to Google Parameter Manager.

`PutParameter` creates a parameter or updates it when `Overwrite=true`. An existing name with `Overwrite=false` returns `ParameterAlreadyExists`. Writes advance the AWS version counter and wait for target reconciliation within a bounded interval; a terminal target rejection is reported. `DeleteParameter` removes the parameter from reads while target cleanup proceeds separately.

Protect and back up the adapter's state as well as the target store. Direct provider edits do not update the AWS parameter record and can be overwritten during reconciliation. Existing AWS values and provider history are not automatically imported.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjNjQ3NDhiIj5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhOyBmb250LXNpemU6MTFweCI+R29vZ2xlIFBhcmFtZXRlciBNYW5hZ2VyPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjYzljZmQ4Ij5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4OyBmb250LXNpemU6MTFweCI+R29vZ2xlIFBhcmFtZXRlciBNYW5hZ2VyPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />
</div>

<p className="t9-caption">AWS parameter reads use durable adapter state. Target reconciliation and cleanup run separately.</p>

#### Batch reads, paths, and metadata

GetParameter and GetParameters read caller-scoped parameter records. Batch reads partition found and missing names. GetParametersByPath selects live records by path, applies recursion rules, and returns paginated results in name order. It does not fetch every matching value from the provider store, so the earlier direct-proxy per-parameter access cost is not the Max read path.

DescribeParameters returns paginated metadata, including names, types, versions, and descriptions, without parameter values. Complete ParameterFilters behavior is outside the documented contract. Tag operations update the parameter's metadata. These operations cover Parameter Store; Run Command, Session Manager, patching, state management, and documents remain outside the mapping.

#### Versions and labels

This mapping retains parameter history and named SSM labels. The adapter maintains retained values and label-to-version references for GetParameterHistory, LabelParameterVersion, and version-qualified reads. Parameter Manager has no native version aliases; selecting its highest native version is not the Max request path.

#### Target storage and encryption

Google Parameter Manager holds the reconciled parameter value in the customer's project. The deployment uses Google workload identity. Parameter resources and their native versions are the target representation; the adapter owns the AWS parameter name, current version, and read behavior.

All three parameter types are supported. Parameter Manager encrypts its copy at rest. Protect durable adapter state and backups too. Parameter resources can contain sensitive values; choose access controls from their contents, not the service's name.

#### Limits and deployment

Custom per-parameter KMS keys, AWS ciphertext reads with WithDecryption=false, parameter policies, and the Advanced tier are unsupported. SecureString reads on a supporting mapping require WithDecryption=true. AWS-published public parameters, cross-account shared parameters, and parameter-change events are outside this mapping.

Load values through the Parameter Store API and verify reads, overwrite behavior, and deletion before switching the application. Deployment can also initialize stack-owned literal values from the release. The customer supplies parameters the stack only reads during installation; that secret-supply path is distinct from runtime parameter management.

Provider storage, access permissions, reconciliation, and durable-state availability affect operation. Historical direct-proxy measurements describe their recorded request path; they do not establish Max latency, throughput, or per-read provider charges.

### Via Secret Manager

| Operation                                                   | Area           | Support      | Depth        | Notes                                                                                                                                                        |
| ----------------------------------------------------------- | -------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Consumed parameters (read-only references)                  | Build & deploy | Supported    | Common       | a parameter the stack reads but does not own is supplied by the customer during installation; that supply path is distinct from runtime parameter management |
| Filters & discovery (DescribeParameters / ParameterFilters) | Discovery      | Partial      | Full surface | DescribeParameters serves paginated metadata without values; complete ParameterFilters behavior is outside the documented contract                           |
| Change notifications                                        | Events         | Out of scope | Full surface | parameter-change events are outside this mapping                                                                                                             |
| Batch reads (GetParameters)                                 | Parameters     | Supported    | Common       | reads caller-scoped parameter records and partitions found and missing names                                                                                 |
| Hierarchies & by-path reads (GetParametersByPath)           | Parameters     | Supported    | Common       | queries live adapter records by path, applies recursion rules, and returns paginated results; no provider value fetch per returned parameter                 |
| Parameter reads (GetParameter)                              | Parameters     | Supported    | Common       | reads the current value, type, and AWS version from the caller-scoped durable parameter record; the target copy is reconciled separately                     |
| Parameter writes & deletes                                  | Parameters     | Supported    | Common       | PutParameter creates or updates durable parameter state and reconciles the target; DeleteParameter withdraws reads while target cleanup proceeds separately  |
| Parameter policies & Advanced tier                          | Policies       | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                 |
| Public & shared parameters                                  | Scope          | Out of scope | Full surface | AWS-published public parameters and cross-account shared parameters are outside this mapping                                                                 |
| The wider Systems Manager suite                             | Scope          | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management, and documents remain out of scope                                               |
| Custom encryption keys (KeyId)                              | Types          | Out of scope | Most usage   | custom per-parameter AWS KMS keys are unsupported; protect durable adapter state and configure the target copy independently                                 |
| Parameter types (String / StringList / SecureString)        | Types          | Supported    | Common       | all three type markers are retained in durable state; Secret Manager encrypts its provider copy at rest                                                      |
| Reading ciphertext (WithDecryption=false)                   | Types          | Out of scope | Most usage   | SecureString reads require WithDecryption=true; the adapter does not return AWS KMS ciphertext                                                               |
| Versions & labels                                           | Versions       | Supported    | Most usage   | retained values and adapter-owned label references provide parameter history and named labels; native aliases do not decide AWS reads                        |

#### Requests and durable parameter state

With Max adaptation, your application sends Parameter Store requests in its AWS SDK to the Tensor9 adapter. The adapter keeps a durable parameter record containing the name, type, current value, version counter, description, and tags. Reads use that record. A background worker reconciles its current value to Google Secret Manager.

`PutParameter` creates a parameter or updates it when `Overwrite=true`. An existing name with `Overwrite=false` returns `ParameterAlreadyExists`. Writes advance the AWS version counter and wait for target reconciliation within a bounded interval; a terminal target rejection is reported. `DeleteParameter` removes the parameter from reads while target cleanup proceeds separately.

Protect and back up the adapter's state as well as the target store. Direct provider edits do not update the AWS parameter record and can be overwritten during reconciliation. Existing AWS values and provider history are not automatically imported.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjNjQ3NDhiIj5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhOyBmb250LXNpemU6MTFweCI+R29vZ2xlIFNlY3JldCBNYW5hZ2VyPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjYzljZmQ4Ij5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4OyBmb250LXNpemU6MTFweCI+R29vZ2xlIFNlY3JldCBNYW5hZ2VyPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />
</div>

<p className="t9-caption">AWS parameter reads use durable adapter state. Target reconciliation and cleanup run separately.</p>

#### Batch reads, paths, and metadata

GetParameter and GetParameters read caller-scoped parameter records. Batch reads partition found and missing names. GetParametersByPath selects live records by path, applies recursion rules, and returns paginated results in name order. It does not fetch every matching value from the provider store, so the earlier direct-proxy per-parameter access cost is not the Max read path.

DescribeParameters returns paginated metadata, including names, types, versions, and descriptions, without parameter values. Complete ParameterFilters behavior is outside the documented contract. Tag operations update the parameter's metadata. These operations cover Parameter Store; Run Command, Session Manager, patching, state management, and documents remain outside the mapping.

#### Versions and labels

This mapping retains parameter history and named SSM labels. The adapter maintains the retained values and label-to-version references needed by GetParameterHistory, LabelParameterVersion, and version-qualified reads. Moving a provider alias directly does not move an SSM label.

#### Target storage and encryption

Google Secret Manager holds the reconciled current value in the customer's project. The deployment uses Google workload identity. Its native versions and aliases describe the provider copy; AWS reads and version selection belong to the adapter.

All three parameter types are supported. Secret Manager encrypts its copy at rest. Protect the adapter's durable parameter state and backups as well as the provider copy; storing an ordinary String as a secret does not change the sensitivity of its contents.

#### Limits and deployment

Custom per-parameter KMS keys, AWS ciphertext reads with WithDecryption=false, parameter policies, and the Advanced tier are unsupported. SecureString reads on a supporting mapping require WithDecryption=true. AWS-published public parameters, cross-account shared parameters, and parameter-change events are outside this mapping.

Load values through the Parameter Store API and verify reads, overwrite behavior, and deletion before switching the application. Deployment can also initialize stack-owned literal values from the release. The customer supplies parameters the stack only reads during installation; that secret-supply path is distinct from runtime parameter management.

Provider storage, access permissions, reconciliation, and durable-state availability affect operation. Historical direct-proxy measurements describe their recorded request path; they do not establish Max latency, throughput, or per-read provider charges.

## On Azure

| Operation                                                   | Area           | Support      | Depth        | Notes                                                                                                                                                        |
| ----------------------------------------------------------- | -------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Consumed parameters (read-only references)                  | Build & deploy | Supported    | Common       | a parameter the stack reads but does not own is supplied by the customer during installation; that supply path is distinct from runtime parameter management |
| Filters & discovery (DescribeParameters / ParameterFilters) | Discovery      | Partial      | Full surface | DescribeParameters serves paginated metadata without values; complete ParameterFilters behavior is outside the documented contract                           |
| Change notifications                                        | Events         | Out of scope | Full surface | parameter-change events are outside this mapping                                                                                                             |
| Batch reads (GetParameters)                                 | Parameters     | Supported    | Common       | reads caller-scoped parameter records and partitions found and missing names                                                                                 |
| Hierarchies & by-path reads (GetParametersByPath)           | Parameters     | Supported    | Common       | queries live adapter records by path, applies recursion rules, and returns paginated results; no provider value fetch per returned parameter                 |
| Parameter reads (GetParameter)                              | Parameters     | Supported    | Common       | reads the current value, type, and AWS version from the caller-scoped durable parameter record; the target copy is reconciled separately                     |
| Parameter writes & deletes                                  | Parameters     | Supported    | Common       | PutParameter creates or updates durable parameter state and reconciles the target; DeleteParameter withdraws reads while target cleanup proceeds separately  |
| Parameter policies & Advanced tier                          | Policies       | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                 |
| Public & shared parameters                                  | Scope          | Out of scope | Full surface | AWS-published public parameters and cross-account shared parameters are outside this mapping                                                                 |
| The wider Systems Manager suite                             | Scope          | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management, and documents remain out of scope                                               |
| Custom encryption keys (KeyId)                              | Types          | Out of scope | Most usage   | custom per-parameter AWS KMS keys are unsupported; protect durable adapter state and configure the target copy independently                                 |
| Parameter types (String / StringList / SecureString)        | Types          | Partial      | Common       | String and StringList are supported; SecureString remains outside the App Configuration mapping. Direct Key Vault access is a separate application path      |
| Reading ciphertext (WithDecryption=false)                   | Types          | Out of scope | Most usage   | SecureString reads require WithDecryption=true; the adapter does not return AWS KMS ciphertext                                                               |
| Versions & labels                                           | Versions       | Partial      | Most usage   | numeric history is retained; the adapter owns AWS version selection. Named SSM labels remain outside this mapping                                            |

#### Requests and durable parameter state

With Max adaptation, your application sends Parameter Store requests in its AWS SDK to the Tensor9 adapter. The adapter keeps a durable parameter record containing the name, type, current value, version counter, description, and tags. Reads use that record. A background worker reconciles its current value to Azure App Configuration.

`PutParameter` creates a parameter or updates it when `Overwrite=true`. An existing name with `Overwrite=false` returns `ParameterAlreadyExists`. Writes advance the AWS version counter and wait for target reconciliation within a bounded interval; a terminal target rejection is reported. `DeleteParameter` removes the parameter from reads while target cleanup proceeds separately.

Protect and back up the adapter's state as well as the target store. Direct provider edits do not update the AWS parameter record and can be overwritten during reconciliation. Existing AWS values and provider history are not automatically imported.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjNjQ3NDhiIj5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhOyBmb250LXNpemU6MTFweCI+QXp1cmUgQXBwIENvbmZpZ3VyYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+Y29uZmlndXJlZCB0YXJnZXQgY29weTwvdGV4dD4KPC9zdmc+" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjYzljZmQ4Ij5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4OyBmb250LXNpemU6MTFweCI+QXp1cmUgQXBwIENvbmZpZ3VyYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+Y29uZmlndXJlZCB0YXJnZXQgY29weTwvdGV4dD4KPC9zdmc+" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />
</div>

<p className="t9-caption">AWS parameter reads use durable adapter state. Target reconciliation and cleanup run separately.</p>

#### Batch reads, paths, and metadata

GetParameter and GetParameters read caller-scoped parameter records. Batch reads partition found and missing names. GetParametersByPath selects live records by path, applies recursion rules, and returns paginated results in name order. It does not fetch every matching value from the provider store, so the earlier direct-proxy per-parameter access cost is not the Max read path.

DescribeParameters returns paginated metadata, including names, types, versions, and descriptions, without parameter values. Complete ParameterFilters behavior is outside the documented contract. Tag operations update the parameter's metadata. These operations cover Parameter Store; Run Command, Session Manager, patching, state management, and documents remain outside the mapping.

#### Versions and labels

This mapping retains numeric parameter versions; named SSM version labels are unsupported. App Configuration labels can represent retained target versions, but they are different from SSM labels. The adapter owns the AWS version counter and selection; the highest provider label does not decide a Max read.

#### Target storage and encryption

Azure App Configuration holds the reconciled configuration value in the customer's store, accessed with the deployment's managed identity. Its key prefixes and label dimension organize the provider copy. GetParametersByPath queries adapter records rather than using a provider prefix query as the application read path.

String and StringList are supported. SecureString is unsupported for this App Configuration mapping. Accessing Azure Key Vault directly requires application changes and is a separate option. Protect adapter state and the encrypted provider store; storage encryption alone does not add SecureString support.

#### Limits and deployment

Custom per-parameter KMS keys, AWS ciphertext reads with WithDecryption=false, parameter policies, and the Advanced tier are unsupported. SecureString reads on a supporting mapping require WithDecryption=true. AWS-published public parameters, cross-account shared parameters, and parameter-change events are outside this mapping.

Load values through the Parameter Store API and verify reads, overwrite behavior, and deletion before switching the application. Deployment can also initialize stack-owned literal values from the release. The customer supplies parameters the stack only reads during installation; that secret-supply path is distinct from runtime parameter management.

Provider storage, access permissions, reconciliation, and durable-state availability affect operation. Historical direct-proxy measurements describe their recorded request path; they do not establish Max latency, throughput, or per-read provider charges.

## On OCI

| Operation                                                   | Area           | Support      | Depth        | Notes                                                                                                                                                        |
| ----------------------------------------------------------- | -------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Consumed parameters (read-only references)                  | Build & deploy | Supported    | Common       | a parameter the stack reads but does not own is supplied by the customer during installation; that supply path is distinct from runtime parameter management |
| Filters & discovery (DescribeParameters / ParameterFilters) | Discovery      | Partial      | Full surface | DescribeParameters serves paginated metadata without values; complete ParameterFilters behavior is outside the documented contract                           |
| Change notifications                                        | Events         | Out of scope | Full surface | parameter-change events are outside this mapping                                                                                                             |
| Batch reads (GetParameters)                                 | Parameters     | Supported    | Common       | reads caller-scoped parameter records and partitions found and missing names                                                                                 |
| Hierarchies & by-path reads (GetParametersByPath)           | Parameters     | Supported    | Common       | queries live adapter records by path, applies recursion rules, and returns paginated results; no provider value fetch per returned parameter                 |
| Parameter reads (GetParameter)                              | Parameters     | Supported    | Common       | reads the current value, type, and AWS version from the caller-scoped durable parameter record; the target copy is reconciled separately                     |
| Parameter writes & deletes                                  | Parameters     | Supported    | Common       | PutParameter creates or updates durable parameter state and reconciles the target; DeleteParameter withdraws reads while target cleanup proceeds separately  |
| Parameter policies & Advanced tier                          | Policies       | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                 |
| Public & shared parameters                                  | Scope          | Out of scope | Full surface | AWS-published public parameters and cross-account shared parameters are outside this mapping                                                                 |
| The wider Systems Manager suite                             | Scope          | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management, and documents remain out of scope                                               |
| Custom encryption keys (KeyId)                              | Types          | Out of scope | Most usage   | custom per-parameter AWS KMS keys are unsupported; protect durable adapter state and configure the target copy independently                                 |
| Parameter types (String / StringList / SecureString)        | Types          | Supported    | Common       | all three type markers are retained in durable state; the configured OCI vault key encrypts the provider copy                                                |
| Reading ciphertext (WithDecryption=false)                   | Types          | Out of scope | Most usage   | SecureString reads require WithDecryption=true; the adapter does not return AWS KMS ciphertext                                                               |
| Move-only version labels                                    | Versions       | Out of scope | Most usage   | named SSM labels are outside this mapping; native OCI stages do not define the AWS contract                                                                  |
| Versions                                                    | Versions       | Supported    | Most usage   | numeric history is retained; the adapter owns AWS version identity and selection independently of native OCI versionNumber values                            |

#### Requests and durable parameter state

With Max adaptation, your application sends Parameter Store requests in its AWS SDK to the Tensor9 adapter. The adapter keeps a durable parameter record containing the name, type, current value, version counter, description, and tags. Reads use that record. A background worker reconciles its current value to OCI Vault.

`PutParameter` creates a parameter or updates it when `Overwrite=true`. An existing name with `Overwrite=false` returns `ParameterAlreadyExists`. Writes advance the AWS version counter and wait for target reconciliation within a bounded interval; a terminal target rejection is reported. `DeleteParameter` removes the parameter from reads while target cleanup proceeds separately.

Protect and back up the adapter's state as well as the target store. Direct provider edits do not update the AWS parameter record and can be overwritten during reconciliation. Existing AWS values and provider history are not automatically imported.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjNjQ3NDhiIj5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhOyBmb250LXNpemU6MTFweCI+T0NJIFZhdWx0PC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjYzljZmQ4Ij5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4OyBmb250LXNpemU6MTFweCI+T0NJIFZhdWx0PC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />
</div>

<p className="t9-caption">AWS parameter reads use durable adapter state. Target reconciliation and cleanup run separately.</p>

#### Batch reads, paths, and metadata

GetParameter and GetParameters read caller-scoped parameter records. Batch reads partition found and missing names. GetParametersByPath selects live records by path, applies recursion rules, and returns paginated results in name order. It does not fetch every matching value from the provider store, so the earlier direct-proxy per-parameter access cost is not the Max read path.

DescribeParameters returns paginated metadata, including names, types, versions, and descriptions, without parameter values. Complete ParameterFilters behavior is outside the documented contract. Tag operations update the parameter's metadata. These operations cover Parameter Store; Run Command, Session Manager, patching, state management, and documents remain outside the mapping.

#### Versions and labels

This mapping retains numeric parameter versions; named SSM labels are unsupported. OCI supplies versioned target storage, while the adapter maintains AWS version identity and selection. A native versionNumber is not an instruction to read around the parameter record.

#### Target storage and encryption

OCI Vault holds the reconciled value as a secret, including ordinary String configuration. Configure the vault, compartment, encryption key, and resource-principal access for secret management and retrieval. Native secret versions describe the provider copy; the adapter owns the AWS parameter record and read path.

All three parameter types use the configured vault key for the provider copy. OCI schedules physical secret deletion; that cleanup can finish after the parameter leaves the AWS-readable set. Reusing a name must be reconciled with any retained native secret, without confusing its version sequence with the new AWS parameter identity. Protect durable adapter state and backups as well as the vault.

#### Limits and deployment

Custom per-parameter KMS keys, AWS ciphertext reads with WithDecryption=false, parameter policies, and the Advanced tier are unsupported. SecureString reads on a supporting mapping require WithDecryption=true. AWS-published public parameters, cross-account shared parameters, and parameter-change events are outside this mapping.

Load values through the Parameter Store API and verify reads, overwrite behavior, and deletion before switching the application. Deployment can also initialize stack-owned literal values from the release. The customer supplies parameters the stack only reads during installation; that secret-supply path is distinct from runtime parameter management.

Provider storage, access permissions, reconciliation, and durable-state availability affect operation. Historical direct-proxy measurements describe their recorded request path; they do not establish Max latency, throughput, or per-read provider charges.

## On Private Kubernetes

| Operation                                                   | Area           | Support      | Depth        | Notes                                                                                                                                                        |
| ----------------------------------------------------------- | -------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Consumed parameters (read-only references)                  | Build & deploy | Supported    | Common       | a parameter the stack reads but does not own is supplied by the customer during installation; that supply path is distinct from runtime parameter management |
| Filters & discovery (DescribeParameters / ParameterFilters) | Discovery      | Partial      | Full surface | DescribeParameters serves paginated metadata without values; complete ParameterFilters behavior is outside the documented contract                           |
| Change notifications                                        | Events         | Out of scope | Full surface | parameter-change events are outside this mapping                                                                                                             |
| Batch reads (GetParameters)                                 | Parameters     | Supported    | Common       | reads caller-scoped parameter records and partitions found and missing names                                                                                 |
| Hierarchies & by-path reads (GetParametersByPath)           | Parameters     | Supported    | Common       | queries live adapter records by path, applies recursion rules, and returns paginated results; no provider value fetch per returned parameter                 |
| Parameter reads (GetParameter)                              | Parameters     | Supported    | Common       | reads the current value, type, and AWS version from the caller-scoped durable parameter record; the target copy is reconciled separately                     |
| Parameter writes & deletes                                  | Parameters     | Supported    | Common       | PutParameter creates or updates durable parameter state and reconciles the target; DeleteParameter withdraws reads while target cleanup proceeds separately  |
| Parameter policies & Advanced tier                          | Policies       | Out of scope | Most usage   | parameter policies and the Advanced tier are outside the documented contract                                                                                 |
| Public & shared parameters                                  | Scope          | Out of scope | Full surface | AWS-published public parameters and cross-account shared parameters are outside this mapping                                                                 |
| The wider Systems Manager suite                             | Scope          | Out of scope | Full surface | Parameter Store only: remote commands, sessions, patching, state management, and documents remain out of scope                                               |
| Custom encryption keys (KeyId)                              | Types          | Out of scope | Most usage   | custom per-parameter AWS KMS keys are unsupported; protect durable adapter state and configure the target copy independently                                 |
| Parameter types (String / StringList / SecureString)        | Types          | Supported    | Common       | all three type markers are retained; protect durable state and configure Kubernetes storage encryption. Base64 encoding does not encrypt the target copy     |
| Reading ciphertext (WithDecryption=false)                   | Types          | Out of scope | Most usage   | SecureString reads require WithDecryption=true; the adapter does not return AWS KMS ciphertext                                                               |
| Versions & labels                                           | Versions       | Out of scope | Most usage   | only the latest value and increasing AWS version counter are retained; previous values and named labels are unsupported                                      |

#### Requests and durable parameter state

With Max adaptation, your application sends Parameter Store requests in its AWS SDK to the Tensor9 adapter. The adapter keeps a durable parameter record containing the name, type, current value, version counter, description, and tags. Reads use that record. A background worker reconciles its current value to Kubernetes Secrets.

`PutParameter` creates a parameter or updates it when `Overwrite=true`. An existing name with `Overwrite=false` returns `ParameterAlreadyExists`. Writes advance the AWS version counter and wait for target reconciliation within a bounded interval; a terminal target rejection is reported. `DeleteParameter` removes the parameter from reads while target cleanup proceeds separately.

Protect and back up the adapter's state as well as the target store. Direct provider edits do not update the AWS parameter record and can be overwritten during reconciliation. Existing AWS values and provider history are not automatically imported.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmEiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjZWNmZGY1IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzA0Nzg1NyI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjNjQ3NDhiIj5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhOyBmb250LXNpemU6MTFweCI+S3ViZXJuZXRlcyBTZWNyZXRzPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJQYXJhbWV0ZXIgU3RvcmUgcmVxdWVzdHMgcmVhZCBkdXJhYmxlIGFkYXB0ZXIgcmVjb3JkczsgcmVjb25jaWxpYXRpb24gbWFpbnRhaW5zIHRoZSBjb25maWd1cmVkIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIxNCIgeT0iNjUiIHdpZHRoPSIxNTUiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjkxIiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDgiPllvdXIgYXBwbGljYXRpb248L3RleHQ+Cjx0ZXh0IHg9IjkxIiB5PSIxMTYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij5QYXJhbWV0ZXIgU3RvcmUgU0RLPC90ZXh0Pgo8cGF0aCBkPSJNMTY5LDEwNCBIMjQ0IGwtOSwtNSBtOSw1IGwtOSw1IiBmaWxsPSJub25lIiBzdHJva2U9IiM2NDc0OGIiIHN0cm9rZS13aWR0aD0iMiIvPgo8cmVjdCB4PSIyNTAiIHk9IjM4IiB3aWR0aD0iMjgyIiBoZWlnaHQ9IjEzMCIgcng9IjEyIiBmaWxsPSIjMWEzMTI2IiBzdHJva2U9IiMwNTk2NjkiLz4KPHRleHQgeD0iMzkxIiB5PSI2OSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDcwMCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPkR1cmFibGUgcGFyYW1ldGVyIHJlY29yZDwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSI5NCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPm5hbWUgwrcgdHlwZSDCtyB2YWx1ZSDCtyB2ZXJzaW9uPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlc2NyaXB0aW9uIMK3IHRhZ3MgwrcgbGlmZWN5Y2xlPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjE0MSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwLjVweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzkwZGVjOCI+QVdTIHJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxwYXRoIGQ9Ik01MzIsMTA0IEg2MDMgbC05LC01IG05LDUgbC05LDUiIGZpbGw9Im5vbmUiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIi8+Cjx0ZXh0IHg9IjU2NyIgeT0iODYiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMHB4ICdTRiBNb25vJywgdWktbW9ub3NwYWNlLCAnSmV0QnJhaW5zIE1vbm8nLCBNZW5sbywgbW9ub3NwYWNlOyBmaWxsOiAjYzljZmQ4Ij5yZWNvbmNpbGU8L3RleHQ+CjxyZWN0IHg9IjYwOSIgeT0iNjUiIHdpZHRoPSIyMTMiIGhlaWdodD0iNzgiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjcxNSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4OyBmb250LXNpemU6MTFweCI+S3ViZXJuZXRlcyBTZWNyZXRzPC90ZXh0Pgo8dGV4dCB4PSI3MTUiIHk9IjExNiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmNvbmZpZ3VyZWQgdGFyZ2V0IGNvcHk8L3RleHQ+Cjwvc3ZnPg==" alt="Parameter Store requests read durable adapter records; reconciliation maintains the configured target copy." />
</div>

<p className="t9-caption">AWS parameter reads use durable adapter state. Target reconciliation and cleanup run separately.</p>

#### Batch reads, paths, and metadata

GetParameter and GetParameters read caller-scoped parameter records. Batch reads partition found and missing names. GetParametersByPath selects live records by path, applies recursion rules, and returns paginated results in name order. It does not fetch every matching value from the provider store, so the earlier direct-proxy per-parameter access cost is not the Max read path.

DescribeParameters returns paginated metadata, including names, types, versions, and descriptions, without parameter values. Complete ParameterFilters behavior is outside the documented contract. Tag operations update the parameter's metadata. These operations cover Parameter Store; Run Command, Session Manager, patching, state management, and documents remain outside the mapping.

#### Versions and labels

This mapping retains the latest value and its increasing version counter. Previous values and named SSM labels are unsupported. A counter records writes; it does not make old values readable. Choose a mapping with retained history when the application needs it.

#### Target storage and encryption

A Kubernetes Secret holds the reconciled current value in the customer cluster. The deployment's service account accesses the backing objects. AWS reads use durable parameter records, not a Kubernetes Secret lookup for each request; the parameter counter belongs to that record.

All three parameter type markers are preserved. Kubernetes Secret values are base64-encoded; base64 is not encryption. Configure Kubernetes access control and storage encryption, and protect the adapter's durable state and backups. This storage option stays inside the customer cluster, including disconnected deployments.

#### Limits and deployment

Custom per-parameter KMS keys, AWS ciphertext reads with WithDecryption=false, parameter policies, and the Advanced tier are unsupported. SecureString reads on a supporting mapping require WithDecryption=true. AWS-published public parameters, cross-account shared parameters, and parameter-change events are outside this mapping.

Load values through the Parameter Store API and verify reads, overwrite behavior, and deletion before switching the application. Deployment can also initialize stack-owned literal values from the release. The customer supplies parameters the stack only reads during installation; that secret-supply path is distinct from runtime parameter management.

Provider storage, access permissions, reconciliation, and durable-state availability affect operation. Historical direct-proxy measurements describe their recorded request path; they do not establish Max latency, throughput, or per-read provider charges.

[Service Catalog](/service-adapters/catalog).
