Show HN: Credstash – A tiny python utility for managing secrets in EC2
github.com
github.com
The utility does depend on three external services: DynamoDB, KMS, and IAM (for permissioning). This might sound like a lot, but the target usecase for something like this is a fleet running in the cloud. If you're already running in EC2, then using IAM roles to distribute AWS creds is a no-brainer and very simple. KMS and DDB are also not arduous things to depend on if you're already in the cloud.
For credstash, you need to set up your KMS key (and set whatever policies around it make sense for you). Once you do that, there's nothing to manage. Sure, you depend on DDB, but credstash creates the table for you, and unless you need to dial up more throughput (which is a mouse-click operation), you never have to touch it.
It actually doesn't appear to be officially deprecated at all, although perhaps it is considered feature complete:
http://aws.amazon.com/simpledb/
However, Amazon seems to ignore questions as to its status which tends to make me wary as well.
It may not be officially deprecated, but a service tat hasn't been touched in three years, which AWS will only tell you about if asked very specifically, makes me not want to use it as a foundation for any new services.
According to the release notes: http://aws.amazon.com/releasenotes/Amazon-SimpleDB the last update to the service was 2011
DynamoDB's free tier doesn't expire after 12 months. (Source: http://aws.amazon.com/free/)
For example, even the official Kinesis Client Library will store its state in a DynamoDB table. (link: http://docs.aws.amazon.com/kinesis/latest/dev/kinesis-record...)