Does this look appealing?
Does this look appealing?
The benefit of AWS Secrets Manager has been that it integrates directly with other services. In ECS/Fargate, you can create a task definition and list secrets to be injected at run time. It also has features like secret rotation so you don't have to roll your own (well, you kinda do w/Lambda, but they have samples), and you can use things like IAM to lock down access per-secret or per-IAM-ARN-hierarchy.
Like everything in AWS, it'll cost you more, but it'll also eliminate a lot of engineering time. If you're trying to pinch pennies, use Vault or something hokey like pulling a token from AWS SSM PS or S3 and rely on IAM roles/profiles/etc for access control.
[0] https://docs.aws.amazon.com/systems-manager/latest/userguide...
"The primary orchestrator going forward is Kubernetes. Mirantis is committed to providing an excellent experience to all Docker Enterprise platform customers and currently expects to support Swarm for at least two years, depending on customer input into the roadmap. Mirantis is also evaluating options for making the transition to Kubernetes easier for Swarm users."
https://www.mirantis.com/blog/mirantis-acquires-docker-enter...
Also, I haven’t needed to integrate something like Vault because the Swarm secrets feature covers my use case perfectly.
I currently have my secrets stored in an encrypted text file in case I need to bring them back up.
There is nothing stopping you from forking the project and adding all the enterprise functionality you want.