Municipal microservices each need database credentials, and instances must stay interchangeable as Auto Scaling replaces them. How should secrets be supplied?
Select an answer to reveal the explanation.
Short Explanation
Secrets Manager is the city key cabinet—new microservice desks check out the current key when they start, so you can swap desks freely. Baking passwords into AMIs or images, or emailing them, glues secrets to machines you wanted to throw away.
Full Explanation
Retrieving secrets at runtime from AWS Secrets Manager (or a similar managed secret store) keeps credentials out of AMIs and images and lets Auto Scaling replace instances without redistribution workflows. Baking secrets into images or sharing them out-of-band undermines rotation and interchangeable service design.