generated: '2026-06-20' method: derived source: openapi/amazon-secrets-manager-openapi.yml description: >- Entity-relationship graph derived from the OpenAPI component schemas and their $ref links and id-reference fields. Amazon Secrets Manager is organized around a Secret aggregate that owns versioned secret values, rotation rules, and tags. identifiers: ARN: description: >- Every secret is globally identified by an Amazon Resource Name, e.g. arn:aws:secretsmanager:{region}:{account}:secret:{name}-{6-char-suffix}. example: arn:aws:secretsmanager:us-east-1:123456789012:secret:MySecret-a1b2c3 SecretId: description: Most operations accept either the ARN or the friendly Name as SecretId. VersionId: description: A UUID identifying one version of a secret's value. entities: - name: Secret schema: openapi/amazon-secrets-manager-openapi.yml#/components/schemas/Secret key: ARN description: The managed secret aggregate — metadata, rotation config, and tags. - name: SecretValue schema: openapi/amazon-secrets-manager-openapi.yml#/components/schemas/SecretValue key: VersionId description: A single encrypted version of a secret's SecretString or SecretBinary. - name: RotationRules schema: openapi/amazon-secrets-manager-openapi.yml#/components/schemas/RotationRules description: The rotation schedule configuration embedded in a Secret. - name: Tag schema: openapi/amazon-secrets-manager-openapi.yml#/components/schemas/Tag description: A Key/Value label attached to a Secret. relationships: - from: Secret to: SecretValue type: has_many via: VersionId / SecretVersionsToStages detail: A secret holds multiple versions keyed by VersionId with staging labels. - from: Secret to: RotationRules type: has_one via: RotationRules detail: Rotation schedule embedded via the RotationRules $ref. - from: Secret to: Tag type: has_many via: Tags detail: A secret carries an array of Tag objects. - from: SecretValue to: Secret type: belongs_to via: ARN detail: A secret value version references its parent secret's ARN and Name. external_references: - target: AWS KMS key via: KmsKeyId detail: Secret.KmsKeyId references the KMS key (ARN/alias) used for encryption at rest. - target: AWS Lambda function via: RotationLambdaARN detail: Secret.RotationLambdaARN references the Lambda that performs rotation.