| I’ve refactored the feature definition to be more structured, and I’ve provided a few constraints to focus the ticket. Identifying how to proceed on this is a bit confusing, in part because AWS themselves seem to be confused. They have effectively built 2 services (SM and PS) which, for the task of managing secrets, seem to do the same thing (with 1 or 2 feature variations). In 2018 it got more confusing when they allowed PS to act as a passthrough, so it can retrieve secrets from SM (presumably with the implied extra API call and associated cost). |