
Stop Overpaying for Secrets You Never Rotate: Migrate to SSM Parameter Store with Terraform 🔐
AWS Secrets Manager charges $0.40/secret/month plus API call fees. SSM Parameter Store SecureString is free for most use cases. Here's how to migrate safely with Terraform. Quick math: How many secrets do you have in AWS Secrets Manager? 20 secrets → $8/month → $96/year 50 secrets → $20/month → $240/year 100 secrets → $40/month → $480/year 200 secrets → $80/month → $960/year Plus $0.05 per 10,000 API calls on top. Now here's the kicker: SSM Parameter Store SecureString does the same thing for $0.00. 💰 Same KMS encryption. Same IAM access control. Same SDK integration. Zero cost (standard tier). Let's migrate. 🤔 When to Stay vs When to Switch Not every secret should move. Here's the honest breakdown: Stay with Secrets Manager when: ✋ ❌ You use automatic rotation (RDS, Redshift, DocumentDB credentials) ❌ You need cross-account sharing via resource policies ❌ You use replica secrets across regions ❌ You store secrets > 8KB (Secrets Manager supports 64KB) Switch to SSM Parameter Store when
Continue reading on Dev.to DevOps
Opens in a new tab



