> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tensor9.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Secrets Manager

> AWS Secrets Manager. Keeps credentials and API keys encrypted under KMS, serves them over an API, and rotates them on a schedule with Lambda.

**On this page**

* [Coverage by target cloud](#coverage-by-target-cloud)
* [How the targets compare](#how-the-targets-compare)
  * [Max adaptation](#max-adaptation)
* [On Google Cloud](#on-google-cloud)
* [On Azure](#on-azure)
* [On OCI](#on-oci)
* [On Private Kubernetes](#on-private-kubernetes)

## Coverage by target cloud

| Target             | Available |
| ------------------ | --------- |
| Google Cloud       | ✓         |
| Azure              | ✓         |
| OCI                | ✓         |
| Private Kubernetes | ✓         |

## How the targets compare

Each row compares a capability of Secrets Manager with its adaptation on each target.
A dash means this row is not stated for that target.

### Max adaptation

| Capability                                                     | Secrets Manager | Google Cloud                                                                                                                             | Azure                                                                                                                                    | OCI                                                                                                                                      | Private Kubernetes                                                                                                                       |
| -------------------------------------------------------------- | --------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| Version stages · current / pending / previous                  | Yes             | Yes - stage labels and immutable versions are maintained in adapter state                                                                | Yes - stage labels and immutable versions are maintained in adapter state                                                                | Yes - stage labels and immutable versions are maintained in adapter state                                                                | Yes - stage labels and immutable versions are maintained in adapter state                                                                |
| Secret rotation · function-driven rotation                     | Yes             | Yes - four-step rotation through a connected Lambda adapter and supplied function                                                        | Yes - four-step rotation through a connected Lambda adapter and supplied function                                                        | Yes - four-step rotation through a connected Lambda adapter and supplied function                                                        | Yes - four-step rotation through a connected Lambda adapter and supplied function                                                        |
| Recovery window · scheduled deletion                           | Yes             | Yes - 7-30 days in adapter state; target cleanup is separate                                                                             | Yes - 7-30 days in adapter state; target cleanup is separate                                                                             | Yes - 7-30 days in adapter state; target cleanup is separate                                                                             | Yes - 7-30 days in adapter state; target cleanup is separate                                                                             |
| Per-secret encryption key · customer-managed key configuration | Yes             | Partial - depends on protection of adapter state and target key configuration; KmsKeyId metadata alone does not select an encryption key | Partial - depends on protection of adapter state and target key configuration; KmsKeyId metadata alone does not select an encryption key | Partial - depends on protection of adapter state and target key configuration; KmsKeyId metadata alone does not select an encryption key | Partial - depends on protection of adapter state and target key configuration; KmsKeyId metadata alone does not select an encryption key |
| Cross-region replication · physical copies                     | Yes             | Partial - region settings are retained; configure and verify physical target replication separately                                      | Partial - region settings are retained; configure and verify physical target replication separately                                      | Partial - region settings are retained; configure and verify physical target replication separately                                      | Partial - region settings are retained; configure and verify physical target replication separately                                      |
| Binary + string values · value payload                         | Yes             | Yes - string and binary values retained in the secret record                                                                             | Partial - target-encoded value must fit Key Vault's 25 KiB limit                                                                         | Yes - string and binary values retained in the secret record                                                                             | Yes - string and binary values retained in the secret record                                                                             |
| Tags · key/value metadata                                      | Yes             | Yes - source tags retained in adapter state without provider label normalization                                                         | Yes - source tags retained in adapter state without provider label normalization                                                         | Yes - source tags retained in adapter state without provider label normalization                                                         | Yes - source tags retained in adapter state without provider label normalization                                                         |
| API coverage                                                   | full            | high                                                                                                                                     | high                                                                                                                                     | high                                                                                                                                     | high                                                                                                                                     |

## On Google Cloud

| Operation                    | Area            | Support      | Depth        | Notes                                                                                                              |
| ---------------------------- | --------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------ |
| BatchGetSecretValue          | Bulk & generate | Supported    | Most usage   | reads requested secrets from their records with list/filter selection                                              |
| GetRandomPassword            | Bulk & generate | Supported    | Most usage   | generates a password using the operating system's secure random source and requested character rules               |
| ListSecrets                  | Listing & tags  | Supported    | Common       | lists and filters caller-scoped records, excluding deleted secrets                                                 |
| TagResource                  | Listing & tags  | Supported    | Full surface | retains source tags verbatim; deployment directive tags cannot be mutated                                          |
| UntagResource                | Listing & tags  | Supported    | Full surface | removes source tags; deployment directive tags are protected                                                       |
| RemoveRegionsFromReplication | Replication     | Partial      | Full surface | removes region entries from the secret record; physical target replicas are managed separately                     |
| ReplicateSecretToRegions     | Replication     | Partial      | Most usage   | retains requested region configuration; physical copies require separately configured target replication           |
| StopReplicationToReplica     | Replication     | Out of scope | Full surface | this adapter serves primary records and does not promote an independent regional replica                           |
| DeleteResourcePolicy         | Resource policy | Supported    | Full surface | removes the policy document from the secret record                                                                 |
| GetResourcePolicy            | Resource policy | Supported    | Full surface | returns the stored source policy document                                                                          |
| PutResourcePolicy            | Resource policy | Partial      | Full surface | stores and validates the policy; full resource-policy enforcement is separate from policy management               |
| ValidateResourcePolicy       | Resource policy | Partial      | Full surface | checks syntax, public access, and administrative lockout; does not promise AWS's complete policy analysis          |
| CancelRotateSecret           | Rotation        | Supported    | Full surface | disables rotation and withdraws its run; pending labels remain for the caller to resolve                           |
| RotateSecret                 | Rotation        | Supported    | Most usage   | runs the four-step protocol; the connected Lambda adapter must be able to invoke the supplied function             |
| CreateSecret                 | Secret CRUD     | Supported    | Common       | creates durable secret state and the initial version; target-specific value and key constraints still apply        |
| DeleteSecret                 | Secret CRUD     | Supported    | Common       | records a 7-30 day recovery window, default 30; force deletion withdraws the record while target cleanup follows   |
| DescribeSecret               | Secret CRUD     | Supported    | Common       | reports the secret record, including version stages, deletion, rotation, and replica configuration                 |
| GetSecretValue               | Secret CRUD     | Supported    | Common       | reads the requested version or stage from durable state; scheduled deletion blocks reads                           |
| PutSecretValue               | Secret CRUD     | Supported    | Common       | adds an immutable version with idempotency-token checks and updates stages                                         |
| RestoreSecret                | Secret CRUD     | Supported    | Most usage   | cancels scheduled deletion before the recovery window expires                                                      |
| UpdateSecret                 | Secret CRUD     | Supported    | Most usage   | updates metadata or adds a value version; an encryption-key ID must be distinguished from target key configuration |
| ListSecretVersionIds         | Versioning      | Supported    | Most usage   | lists immutable versions and their stage labels from the record                                                    |
| UpdateSecretVersionStage     | Versioning      | Supported    | Most usage   | moves source stage labels independently of provider-native aliases                                                 |

#### Requests, versions, and deletion

Your application sends AWS Secrets Manager requests to the Tensor9 adapter in the customer environment. The adapter keeps a durable record containing the secret's values, version IDs, stage labels, tags, and lifecycle settings. Reads use that record; they do not select whichever version happens to be latest in the target store.

`PutSecretValue` creates an immutable version. `AWSCURRENT`, `AWSPENDING`, `AWSPREVIOUS`, and custom labels select versions in the record. Moving a label changes which value a read returns. A repeated request token with the same value returns the earlier result; reusing the token with a different value is rejected.

Scheduled deletion blocks reads for a recoverable period of 7-30 days, with 30 days as the default. `RestoreSecret` cancels that deletion before the window expires. Force deletion removes the secret from the API immediately; removal of any target copy is completed separately.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICM2NDc0OGIiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjZmZmIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmE7IGZvbnQtc2l6ZToxMXB4Ij5Hb29nbGUgU2VjcmV0IE1hbmFnZXI8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICNjOWNmZDgiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjMjYyNjI2IiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDg7IGZvbnQtc2l6ZToxMXB4Ij5Hb29nbGUgU2VjcmV0IE1hbmFnZXI8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />
</div>

<p className="t9-caption">AWS version history stays in the record; the target copy follows its current value.</p>

#### Rotation and access policies

The adapter runs the four rotation steps: create a candidate, update the credential at its source, test it, and make it current. Your rotation function performs the credential-specific work. The deployment must connect that function through the Lambda adapter; a rotation request is rejected when the configured function cannot be reached. Cancelling rotation stops the run but leaves the pending label for the caller to resolve.

Resource-policy operations store, return, delete, and validate the AWS policy document. Validation checks syntax, public access, and policies that would lock every caller out of policy administration. Those operations are distinct from complete resource-policy enforcement: the endpoint authorizes the authenticated principal, and target-store access uses the deployment's cloud identity. Review effective permissions when resource policies grant cross-account access or impose restrictions beyond the principal's permissions.

#### Target storage, encryption, and replication

Google Secret Manager stores the current value under the deployment's Google identity. Its numbered versions are target revisions, not the source of AWS stage selection. Google replication and encryption settings govern that provider copy.

The adapter's durable record retains all versions and labels. Reconciliation writes the current value and its revision to Google Secret Manager. Direct edits to that copy do not update AWS version history and can be overwritten. Protect and back up adapter state as well as the target store.

Encryption follows the deployment's storage and key configuration. The adapter retains `KmsKeyId` as metadata. Protect the durable state and configure any target copy to meet the workload's encryption-key requirements.

Replication requests maintain region configuration in the secret record. They do not by themselves establish a second physical copy or disaster recovery in another region. Configure and verify geographic replication of the underlying storage separately. This adapter serves primary secret records; `StopReplicationToReplica` does not promote an independent regional replica.

Google's native replication policy is chosen when its secret is created. AWS stage moves and delayed deletion are handled in the adapter's record, so they do not require corresponding Google aliases or a native secret recovery window.

#### Cutover and ongoing operation

Create the target deployment, load the required values through the Secrets Manager API, and verify current, previous, and explicitly versioned reads before switching the application. Existing provider values and their history are not automatically imported into the adapter's record.

Test credential rotation with the real database or API it updates, including a failed test step and a retried callback. Verify deletion and restore behavior before relying on the recovery window. The customer controls access to secret state, rotation-function permissions, backup retention, and monitoring.

## On Azure

| Operation                    | Area            | Support      | Depth        | Notes                                                                                                              |
| ---------------------------- | --------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------ |
| BatchGetSecretValue          | Bulk & generate | Supported    | Most usage   | reads requested secrets from their records with list/filter selection                                              |
| GetRandomPassword            | Bulk & generate | Supported    | Most usage   | generates a password using the operating system's secure random source and requested character rules               |
| ListSecrets                  | Listing & tags  | Supported    | Common       | lists and filters caller-scoped records, excluding deleted secrets                                                 |
| TagResource                  | Listing & tags  | Supported    | Full surface | retains source tags verbatim; deployment directive tags cannot be mutated                                          |
| UntagResource                | Listing & tags  | Supported    | Full surface | removes source tags; deployment directive tags are protected                                                       |
| RemoveRegionsFromReplication | Replication     | Partial      | Full surface | removes region entries from the secret record; physical target replicas are managed separately                     |
| ReplicateSecretToRegions     | Replication     | Partial      | Most usage   | retains requested region configuration; physical copies require separately configured target replication           |
| StopReplicationToReplica     | Replication     | Out of scope | Full surface | this adapter serves primary records and does not promote an independent regional replica                           |
| DeleteResourcePolicy         | Resource policy | Supported    | Full surface | removes the policy document from the secret record                                                                 |
| GetResourcePolicy            | Resource policy | Supported    | Full surface | returns the stored source policy document                                                                          |
| PutResourcePolicy            | Resource policy | Partial      | Full surface | stores and validates the policy; full resource-policy enforcement is separate from policy management               |
| ValidateResourcePolicy       | Resource policy | Partial      | Full surface | checks syntax, public access, and administrative lockout; does not promise AWS's complete policy analysis          |
| CancelRotateSecret           | Rotation        | Supported    | Full surface | disables rotation and withdraws its run; pending labels remain for the caller to resolve                           |
| RotateSecret                 | Rotation        | Supported    | Most usage   | runs the four-step protocol; the connected Lambda adapter must be able to invoke the supplied function             |
| CreateSecret                 | Secret CRUD     | Supported    | Common       | creates durable secret state and the initial version; target-specific value and key constraints still apply        |
| DeleteSecret                 | Secret CRUD     | Supported    | Common       | records a 7-30 day recovery window, default 30; force deletion withdraws the record while target cleanup follows   |
| DescribeSecret               | Secret CRUD     | Supported    | Common       | reports the secret record, including version stages, deletion, rotation, and replica configuration                 |
| GetSecretValue               | Secret CRUD     | Supported    | Common       | reads the requested version or stage from durable state; scheduled deletion blocks reads                           |
| PutSecretValue               | Secret CRUD     | Supported    | Common       | adds an immutable version with idempotency-token checks and updates stages                                         |
| RestoreSecret                | Secret CRUD     | Supported    | Most usage   | cancels scheduled deletion before the recovery window expires                                                      |
| UpdateSecret                 | Secret CRUD     | Supported    | Most usage   | updates metadata or adds a value version; an encryption-key ID must be distinguished from target key configuration |
| ListSecretVersionIds         | Versioning      | Supported    | Most usage   | lists immutable versions and their stage labels from the record                                                    |
| UpdateSecretVersionStage     | Versioning      | Supported    | Most usage   | moves source stage labels independently of provider-native aliases                                                 |

#### Requests, versions, and deletion

Your application sends AWS Secrets Manager requests to the Tensor9 adapter in the customer environment. The adapter keeps a durable record containing the secret's values, version IDs, stage labels, tags, and lifecycle settings. Reads use that record; they do not select whichever version happens to be latest in the target store.

`PutSecretValue` creates an immutable version. `AWSCURRENT`, `AWSPENDING`, `AWSPREVIOUS`, and custom labels select versions in the record. Moving a label changes which value a read returns. A repeated request token with the same value returns the earlier result; reusing the token with a different value is rejected.

Scheduled deletion blocks reads for a recoverable period of 7-30 days, with 30 days as the default. `RestoreSecret` cancels that deletion before the window expires. Force deletion removes the secret from the API immediately; removal of any target copy is completed separately.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICM2NDc0OGIiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjZmZmIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmE7IGZvbnQtc2l6ZToxMXB4Ij5BenVyZSBLZXkgVmF1bHQ8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICNjOWNmZDgiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjMjYyNjI2IiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDg7IGZvbnQtc2l6ZToxMXB4Ij5BenVyZSBLZXkgVmF1bHQ8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />
</div>

<p className="t9-caption">AWS version history stays in the record; the target copy follows its current value.</p>

#### Rotation and access policies

The adapter runs the four rotation steps: create a candidate, update the credential at its source, test it, and make it current. Your rotation function performs the credential-specific work. The deployment must connect that function through the Lambda adapter; a rotation request is rejected when the configured function cannot be reached. Cancelling rotation stops the run but leaves the pending label for the caller to resolve.

Resource-policy operations store, return, delete, and validate the AWS policy document. Validation checks syntax, public access, and policies that would lock every caller out of policy administration. Those operations are distinct from complete resource-policy enforcement: the endpoint authorizes the authenticated principal, and target-store access uses the deployment's cloud identity. Review effective permissions when resource policies grant cross-account access or impose restrictions beyond the principal's permissions.

#### Target storage, encryption, and replication

Azure Key Vault stores the current value under the deployment's Azure identity. A version tag tracks the adapter revision because Key Vault's native version IDs are opaque. The adapter retains AWS version history and stage labels independently.

The adapter's durable record retains all versions and labels. Reconciliation writes the current value and its revision to Azure Key Vault. Direct edits to that copy do not update AWS version history and can be overwritten. Protect and back up adapter state as well as the target store.

Encryption follows the deployment's storage and key configuration. The adapter retains `KmsKeyId` as metadata. Protect the durable state and configure any target copy to meet the workload's encryption-key requirements.

Replication requests maintain region configuration in the secret record. They do not by themselves establish a second physical copy or disaster recovery in another region. Configure and verify geographic replication of the underlying storage separately. This adapter serves primary secret records; `StopReplicationToReplica` does not promote an independent regional replica.

Key Vault limits a stored value to 25 KiB; encoded binary content must fit that limit. This target's deletion and name-reuse workflow requires purge permission. A purge-protected vault can block final removal or reuse of a deleted name. AWS scheduled deletion is handled by the adapter before this target cleanup begins.

#### Cutover and ongoing operation

Create the target deployment, load the required values through the Secrets Manager API, and verify current, previous, and explicitly versioned reads before switching the application. Existing provider values and their history are not automatically imported into the adapter's record.

Test credential rotation with the real database or API it updates, including a failed test step and a retried callback. Verify deletion and restore behavior before relying on the recovery window. The customer controls access to secret state, rotation-function permissions, backup retention, and monitoring.

## On OCI

| Operation                    | Area            | Support      | Depth        | Notes                                                                                                              |
| ---------------------------- | --------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------ |
| BatchGetSecretValue          | Bulk & generate | Supported    | Most usage   | reads requested secrets from their records with list/filter selection                                              |
| GetRandomPassword            | Bulk & generate | Supported    | Most usage   | generates a password using the operating system's secure random source and requested character rules               |
| ListSecrets                  | Listing & tags  | Supported    | Common       | lists and filters caller-scoped records, excluding deleted secrets                                                 |
| TagResource                  | Listing & tags  | Supported    | Full surface | retains source tags verbatim; deployment directive tags cannot be mutated                                          |
| UntagResource                | Listing & tags  | Supported    | Full surface | removes source tags; deployment directive tags are protected                                                       |
| RemoveRegionsFromReplication | Replication     | Partial      | Full surface | removes region entries from the secret record; physical target replicas are managed separately                     |
| ReplicateSecretToRegions     | Replication     | Partial      | Most usage   | retains requested region configuration; physical copies require separately configured target replication           |
| StopReplicationToReplica     | Replication     | Out of scope | Full surface | this adapter serves primary records and does not promote an independent regional replica                           |
| DeleteResourcePolicy         | Resource policy | Supported    | Full surface | removes the policy document from the secret record                                                                 |
| GetResourcePolicy            | Resource policy | Supported    | Full surface | returns the stored source policy document                                                                          |
| PutResourcePolicy            | Resource policy | Partial      | Full surface | stores and validates the policy; full resource-policy enforcement is separate from policy management               |
| ValidateResourcePolicy       | Resource policy | Partial      | Full surface | checks syntax, public access, and administrative lockout; does not promise AWS's complete policy analysis          |
| CancelRotateSecret           | Rotation        | Supported    | Full surface | disables rotation and withdraws its run; pending labels remain for the caller to resolve                           |
| RotateSecret                 | Rotation        | Supported    | Most usage   | runs the four-step protocol; the connected Lambda adapter must be able to invoke the supplied function             |
| CreateSecret                 | Secret CRUD     | Supported    | Common       | creates durable secret state and the initial version; target-specific value and key constraints still apply        |
| DeleteSecret                 | Secret CRUD     | Supported    | Common       | records a 7-30 day recovery window, default 30; force deletion withdraws the record while target cleanup follows   |
| DescribeSecret               | Secret CRUD     | Supported    | Common       | reports the secret record, including version stages, deletion, rotation, and replica configuration                 |
| GetSecretValue               | Secret CRUD     | Supported    | Common       | reads the requested version or stage from durable state; scheduled deletion blocks reads                           |
| PutSecretValue               | Secret CRUD     | Supported    | Common       | adds an immutable version with idempotency-token checks and updates stages                                         |
| RestoreSecret                | Secret CRUD     | Supported    | Most usage   | cancels scheduled deletion before the recovery window expires                                                      |
| UpdateSecret                 | Secret CRUD     | Supported    | Most usage   | updates metadata or adds a value version; an encryption-key ID must be distinguished from target key configuration |
| ListSecretVersionIds         | Versioning      | Supported    | Most usage   | lists immutable versions and their stage labels from the record                                                    |
| UpdateSecretVersionStage     | Versioning      | Supported    | Most usage   | moves source stage labels independently of provider-native aliases                                                 |

#### Requests, versions, and deletion

Your application sends AWS Secrets Manager requests to the Tensor9 adapter in the customer environment. The adapter keeps a durable record containing the secret's values, version IDs, stage labels, tags, and lifecycle settings. Reads use that record; they do not select whichever version happens to be latest in the target store.

`PutSecretValue` creates an immutable version. `AWSCURRENT`, `AWSPENDING`, `AWSPREVIOUS`, and custom labels select versions in the record. Moving a label changes which value a read returns. A repeated request token with the same value returns the earlier result; reusing the token with a different value is rejected.

Scheduled deletion blocks reads for a recoverable period of 7-30 days, with 30 days as the default. `RestoreSecret` cancels that deletion before the window expires. Force deletion removes the secret from the API immediately; removal of any target copy is completed separately.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2NiZDVlMSIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICM2NDc0OGIiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjZmZmIiBzdHJva2U9IiNjYmQ1ZTEiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwZjE3MmE7IGZvbnQtc2l6ZToxMXB4Ij5PQ0kgVmF1bHQ8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogIzY0NzQ4YiI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI4MzYiIGhlaWdodD0iMjEwIiB2aWV3Qm94PSIwIDAgODM2IDIxMCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHJlYWQgYW5kIHVwZGF0ZSB0aGUgYWRhcHRlcidzIGR1cmFibGUgc2VjcmV0IHJlY29yZC4gUmVjb25jaWxpYXRpb24gd3JpdGVzIHRoZSBjdXJyZW50IHZhbHVlIHRvIHRoZSBjb25maWd1cmVkIHN0b3JlLiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8ZGVmcz48bWFya2VyIGlkPSJzbS1yZWNvcmQtYXJyb3ciIHZpZXdCb3g9IjAgMCAxMCAxMCIgcmVmWD0iOCIgcmVmWT0iNSIgbWFya2VyV2lkdGg9IjYiIG1hcmtlckhlaWdodD0iNiIgb3JpZW50PSJhdXRvLXN0YXJ0LXJldmVyc2UiPjxwYXRoIGQ9Ik0wLDAgTDEwLDUgTDAsMTAgeiIgZmlsbD0iIzY0NzQ4YiIvPjwvbWFya2VyPjwvZGVmcz4KPHJlY3QgeD0iMTQiIHk9IjY1IiB3aWR0aD0iMTU1IiBoZWlnaHQ9Ijc4IiByeD0iMTIiIGZpbGw9IiMyNjI2MjYiIHN0cm9rZT0iIzNkNGY2NiIvPgo8dGV4dCB4PSI5MSIgeT0iOTUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSI5MSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+QVdTIFNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxsaW5lIHgxPSIxNjkiIHkxPSIxMDQiIHgyPSIyNDQiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHJlY3QgeD0iMjUwIiB5PSIzOCIgd2lkdGg9IjI4MiIgaGVpZ2h0PSIxMzAiIHJ4PSIxMiIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjM5MSIgeT0iNjkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5UZW5zb3I5IHNlY3JldCByZWNvcmQ8L3RleHQ+Cjx0ZXh0IHg9IjM5MSIgeT0iOTQiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSIzOTEiIHk9IjExNSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iMzkxIiB5PSIxNDEiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPnJlYWRzIGFuZCB3cml0ZXMgdXNlIHRoaXMgc3RhdGU8L3RleHQ+CjxsaW5lIHgxPSI1MzIiIHkxPSIxMDQiIHgyPSI2MDMiIHkyPSIxMDQiIHN0cm9rZT0iIzY0NzQ4YiIgc3Ryb2tlLXdpZHRoPSIyIiBtYXJrZXItZW5kPSJ1cmwoI3NtLXJlY29yZC1hcnJvdykiLz4KPHRleHQgeD0iNTY3IiB5PSI4NiIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDEwcHggJ1NGIE1vbm8nLCB1aS1tb25vc3BhY2UsICdKZXRCcmFpbnMgTW9ubycsIE1lbmxvLCBtb25vc3BhY2U7IGZpbGw6ICNjOWNmZDgiPnJlY29uY2lsZTwvdGV4dD4KPHJlY3QgeD0iNjA5IiB5PSI2NSIgd2lkdGg9IjIxMyIgaGVpZ2h0PSI3OCIgcng9IjEyIiBmaWxsPSIjMjYyNjI2IiBzdHJva2U9IiMzZDRmNjYiLz4KPHRleHQgeD0iNzE1IiB5PSI5NSIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDY1MCAxMy41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNlZDg7IGZvbnQtc2l6ZToxMXB4Ij5PQ0kgVmF1bHQ8L3RleHQ+Cjx0ZXh0IHg9IjcxNSIgeT0iMTE2IiB0ZXh0LWFuY2hvcj0ibWlkZGxlIiBzdHlsZT0iZm9udDogMTFweCBJbnRlciwgc2Fucy1zZXJpZjsgZmlsbDogI2M5Y2ZkOCI+Y3VycmVudCB2YWx1ZSwgd2hlcmUgY29uZmlndXJlZDwvdGV4dD4KPC9zdmc+" alt="AWS Secrets Manager requests read and update the adapter's durable secret record. Reconciliation writes the current value to the configured store." />
</div>

<p className="t9-caption">AWS version history stays in the record; the target copy follows its current value.</p>

#### Rotation and access policies

The adapter runs the four rotation steps: create a candidate, update the credential at its source, test it, and make it current. Your rotation function performs the credential-specific work. The deployment must connect that function through the Lambda adapter; a rotation request is rejected when the configured function cannot be reached. Cancelling rotation stops the run but leaves the pending label for the caller to resolve.

Resource-policy operations store, return, delete, and validate the AWS policy document. Validation checks syntax, public access, and policies that would lock every caller out of policy administration. Those operations are distinct from complete resource-policy enforcement: the endpoint authorizes the authenticated principal, and target-store access uses the deployment's cloud identity. Review effective permissions when resource policies grant cross-account access or impose restrictions beyond the principal's permissions.

#### Target storage, encryption, and replication

OCI Vault is the target store for the current secret value in this mapping. OCI requires an encryption key for the vault secret and provides its own version stages and replication settings. The adapter owns AWS history and stage selection, independently of those native features.

The adapter's durable record retains all versions and labels. Reconciliation writes the current value and its revision to OCI Vault. Direct edits to that copy do not update AWS version history and can be overwritten. Protect and back up adapter state as well as the target store.

Encryption follows the deployment's storage and key configuration. The adapter retains `KmsKeyId` as metadata. Protect the durable state and configure any target copy to meet the workload's encryption-key requirements.

Replication requests maintain region configuration in the secret record. They do not by themselves establish a second physical copy or disaster recovery in another region. Configure and verify geographic replication of the underlying storage separately. This adapter serves primary secret records; `StopReplicationToReplica` does not promote an independent regional replica.

Configure the OCI key and any geographic replication for the provider copy. OCI's native scheduled-deletion rules can delay physical removal after the AWS API has withdrawn a secret. These target rules do not replace the adapter's deletion window or create an independent AWS regional replica.

#### Cutover and ongoing operation

Create the target deployment, load the required values through the Secrets Manager API, and verify current, previous, and explicitly versioned reads before switching the application. Existing provider values and their history are not automatically imported into the adapter's record.

Test credential rotation with the real database or API it updates, including a failed test step and a retried callback. Verify deletion and restore behavior before relying on the recovery window. The customer controls access to secret state, rotation-function permissions, backup retention, and monitoring.

## On Private Kubernetes

| Operation                    | Area            | Support      | Depth        | Notes                                                                                                              |
| ---------------------------- | --------------- | ------------ | ------------ | ------------------------------------------------------------------------------------------------------------------ |
| BatchGetSecretValue          | Bulk & generate | Supported    | Most usage   | reads requested secrets from their records with list/filter selection                                              |
| GetRandomPassword            | Bulk & generate | Supported    | Most usage   | generates a password using the operating system's secure random source and requested character rules               |
| ListSecrets                  | Listing & tags  | Supported    | Common       | lists and filters caller-scoped records, excluding deleted secrets                                                 |
| TagResource                  | Listing & tags  | Supported    | Full surface | retains source tags verbatim; deployment directive tags cannot be mutated                                          |
| UntagResource                | Listing & tags  | Supported    | Full surface | removes source tags; deployment directive tags are protected                                                       |
| RemoveRegionsFromReplication | Replication     | Partial      | Full surface | removes region entries from the secret record; physical target replicas are managed separately                     |
| ReplicateSecretToRegions     | Replication     | Partial      | Most usage   | retains requested region configuration; physical copies require separately configured target replication           |
| StopReplicationToReplica     | Replication     | Out of scope | Full surface | this adapter serves primary records and does not promote an independent regional replica                           |
| DeleteResourcePolicy         | Resource policy | Supported    | Full surface | removes the policy document from the secret record                                                                 |
| GetResourcePolicy            | Resource policy | Supported    | Full surface | returns the stored source policy document                                                                          |
| PutResourcePolicy            | Resource policy | Partial      | Full surface | stores and validates the policy; full resource-policy enforcement is separate from policy management               |
| ValidateResourcePolicy       | Resource policy | Partial      | Full surface | checks syntax, public access, and administrative lockout; does not promise AWS's complete policy analysis          |
| CancelRotateSecret           | Rotation        | Supported    | Full surface | disables rotation and withdraws its run; pending labels remain for the caller to resolve                           |
| RotateSecret                 | Rotation        | Supported    | Most usage   | runs the four-step protocol; the connected Lambda adapter must be able to invoke the supplied function             |
| CreateSecret                 | Secret CRUD     | Supported    | Common       | creates durable secret state and the initial version; target-specific value and key constraints still apply        |
| DeleteSecret                 | Secret CRUD     | Supported    | Common       | records a 7-30 day recovery window, default 30; force deletion withdraws the record while target cleanup follows   |
| DescribeSecret               | Secret CRUD     | Supported    | Common       | reports the secret record, including version stages, deletion, rotation, and replica configuration                 |
| GetSecretValue               | Secret CRUD     | Supported    | Common       | reads the requested version or stage from durable state; scheduled deletion blocks reads                           |
| PutSecretValue               | Secret CRUD     | Supported    | Common       | adds an immutable version with idempotency-token checks and updates stages                                         |
| RestoreSecret                | Secret CRUD     | Supported    | Most usage   | cancels scheduled deletion before the recovery window expires                                                      |
| UpdateSecret                 | Secret CRUD     | Supported    | Most usage   | updates metadata or adds a value version; an encryption-key ID must be distinguished from target key configuration |
| ListSecretVersionIds         | Versioning      | Supported    | Most usage   | lists immutable versions and their stage labels from the record                                                    |
| UpdateSecretVersionStage     | Versioning      | Supported    | Most usage   | moves source stage labels independently of provider-native aliases                                                 |

#### Requests, versions, and deletion

Your application sends AWS Secrets Manager requests to the Tensor9 adapter in the customer environment. The adapter keeps a durable record containing the secret's values, version IDs, stage labels, tags, and lifecycle settings. Reads use that record; they do not select whichever version happens to be latest in the target store.

`PutSecretValue` creates an immutable version. `AWSCURRENT`, `AWSPENDING`, `AWSPREVIOUS`, and custom labels select versions in the record. Moving a label changes which value a read returns. A repeated request token with the same value returns the earlier result; reusing the token with a different value is rejected.

Scheduled deletion blocks reads for a recoverable period of 7-30 days, with 30 days as the default. `RestoreSecret` cancels that deletion before the window expires. Force deletion removes the secret from the API immediately; removal of any target copy is completed separately.

<div className="t9-diagram-scroll" role="region" aria-label="Scrollable diagram" tabIndex={0}>
  <img className="t9-diagram-light" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NTAiIGhlaWdodD0iMTkwIiB2aWV3Qm94PSIwIDAgNjUwIDE5MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHVzZSBkdXJhYmxlIGFkYXB0ZXIgc3RhdGUgd2l0aG91dCBhIHNlcGFyYXRlIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6IzMzNDE1NX08L3N0eWxlPgo8cmVjdCB4PSIyMCIgeT0iNTUiIHdpZHRoPSIxODUiIGhlaWdodD0iODAiIHJ4PSIxMiIgZmlsbD0iI2ZmZiIgc3Ryb2tlPSIjY2JkNWUxIi8+Cjx0ZXh0IHg9IjExMiIgeT0iODgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMGYxNzJhIj5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSIxMTIiIHk9IjExMyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPlNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxwYXRoIGQ9Ik0yMDUsOTUgSDMwMCBsLTksLTUgbTksNSBsLTksNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz4KPHJlY3QgeD0iMzA1IiB5PSIyNSIgd2lkdGg9IjMyNSIgaGVpZ2h0PSIxNDAiIHJ4PSIxMiIgZmlsbD0iI2VjZmRmNSIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjQ2NyIgeT0iNTkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjMDQ3ODU3Ij5EdXJhYmxlIGFkYXB0ZXIgc3RhdGU8L3RleHQ+Cjx0ZXh0IHg9IjQ2NyIgeT0iODUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjNjQ3NDhiIj52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSI0NjciIHk9IjEwOCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM2NDc0OGIiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iNDY3IiB5PSIxMzciIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICMwNDc4NTciPm5vIGFkZGl0aW9uYWwgS3ViZXJuZXRlcyBTZWNyZXQ8L3RleHQ+Cjwvc3ZnPg==" alt="AWS Secrets Manager requests use durable adapter state without a separate target copy." />

  <img className="t9-diagram-dark" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NTAiIGhlaWdodD0iMTkwIiB2aWV3Qm94PSIwIDAgNjUwIDE5MCIgcm9sZT0iaW1nIiBhcmlhLWxhYmVsPSJBV1MgU2VjcmV0cyBNYW5hZ2VyIHJlcXVlc3RzIHVzZSBkdXJhYmxlIGFkYXB0ZXIgc3RhdGUgd2l0aG91dCBhIHNlcGFyYXRlIHRhcmdldCBjb3B5LiI+PHN0eWxlPnRleHR7Zm9udC1mYW1pbHk6SW50ZXIsLWFwcGxlLXN5c3RlbSxCbGlua01hY1N5c3RlbUZvbnQsJ1NlZ29lIFVJJyxSb2JvdG8sJ0hlbHZldGljYSBOZXVlJyxBcmlhbCxzYW5zLXNlcmlmO2ZpbGw6I2NiZDVlMX08L3N0eWxlPgo8cmVjdCB4PSIyMCIgeT0iNTUiIHdpZHRoPSIxODUiIGhlaWdodD0iODAiIHJ4PSIxMiIgZmlsbD0iIzI2MjYyNiIgc3Ryb2tlPSIjM2Q0ZjY2Ii8+Cjx0ZXh0IHg9IjExMiIgeT0iODgiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA2NTAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZWQ4Ij5Zb3VyIGFwcGxpY2F0aW9uPC90ZXh0Pgo8dGV4dCB4PSIxMTIiIHk9IjExMyIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPlNlY3JldHMgTWFuYWdlciBTREs8L3RleHQ+CjxwYXRoIGQ9Ik0yMDUsOTUgSDMwMCBsLTksLTUgbTksNSBsLTksNSIgZmlsbD0ibm9uZSIgc3Ryb2tlPSIjNjQ3NDhiIiBzdHJva2Utd2lkdGg9IjIiLz4KPHJlY3QgeD0iMzA1IiB5PSIyNSIgd2lkdGg9IjMyNSIgaGVpZ2h0PSIxNDAiIHJ4PSIxMiIgZmlsbD0iIzFhMzEyNiIgc3Ryb2tlPSIjMDU5NjY5Ii8+Cjx0ZXh0IHg9IjQ2NyIgeT0iNTkiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiA3MDAgMTMuNXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjOTBkZWM4Ij5EdXJhYmxlIGFkYXB0ZXIgc3RhdGU8L3RleHQ+Cjx0ZXh0IHg9IjQ2NyIgeT0iODUiIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMXB4IEludGVyLCBzYW5zLXNlcmlmOyBmaWxsOiAjYzljZmQ4Ij52YWx1ZXMgwrcgdmVyc2lvbnMgwrcgc3RhZ2UgbGFiZWxzPC90ZXh0Pgo8dGV4dCB4PSI0NjciIHk9IjEwOCIgdGV4dC1hbmNob3I9Im1pZGRsZSIgc3R5bGU9ImZvbnQ6IDExcHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICNjOWNmZDgiPmRlbGV0aW9uIHdpbmRvdyDCtyByb3RhdGlvbiDCtyBwb2xpY2llczwvdGV4dD4KPHRleHQgeD0iNDY3IiB5PSIxMzciIHRleHQtYW5jaG9yPSJtaWRkbGUiIHN0eWxlPSJmb250OiAxMC41cHggSW50ZXIsIHNhbnMtc2VyaWY7IGZpbGw6ICM5MGRlYzgiPm5vIGFkZGl0aW9uYWwgS3ViZXJuZXRlcyBTZWNyZXQ8L3RleHQ+Cjwvc3ZnPg==" alt="AWS Secrets Manager requests use durable adapter state without a separate target copy." />
</div>

<p className="t9-caption">The adapter stores values and version history in its durable state.</p>

#### Rotation and access policies

The adapter runs the four rotation steps: create a candidate, update the credential at its source, test it, and make it current. Your rotation function performs the credential-specific work. The deployment must connect that function through the Lambda adapter; a rotation request is rejected when the configured function cannot be reached. Cancelling rotation stops the run but leaves the pending label for the caller to resolve.

Resource-policy operations store, return, delete, and validate the AWS policy document. Validation checks syntax, public access, and policies that would lock every caller out of policy administration. Those operations are distinct from complete resource-policy enforcement: the endpoint authorizes the authenticated principal, and target-store access uses the deployment's cloud identity. Review effective permissions when resource policies grant cross-account access or impose restrictions beyond the principal's permissions.

#### Target storage, encryption, and replication

The customer deployment stores the secret entirely in the adapter's durable state. This configuration creates no additional Kubernetes Secret. Version history and reads use the same secret record as cloud-backed deployments.

All versions and labels remain in the adapter's durable state. Protect that state store and its backups; no separate cloud secret copy is configured.

Encryption follows the deployment's storage and key configuration. The adapter retains `KmsKeyId` as metadata. Protect the durable state and configure any target copy to meet the workload's encryption-key requirements.

Replication requests maintain region configuration in the secret record. They do not by themselves establish a second physical copy or disaster recovery in another region. Configure and verify geographic replication of the underlying storage separately. This adapter serves primary secret records; `StopReplicationToReplica` does not promote an independent regional replica.

Storage durability, encryption, backups, and recovery depend on the appliance's state store. A Kubernetes namespace or an external synchronization controller does not provide that history.

#### Cutover and ongoing operation

Create the target deployment, load the required values through the Secrets Manager API, and verify current, previous, and explicitly versioned reads before switching the application. Existing provider values and their history are not automatically imported into the adapter's record.

Test credential rotation with the real database or API it updates, including a failed test step and a retried callback. Verify deletion and restore behavior before relying on the recovery window. The customer controls access to secret state, rotation-function permissions, backup retention, and monitoring.

[Service Catalog](/service-adapters/catalog).
