Maintained with ☕️ by
IcePanel logo

AWS DataSync now supports AWS Secrets Manager for all location types

Share

Services

AWS DataSync now supports AWS Secrets Manager for credential management across all location types, including Hadoop Distributed File System (HDFS), Amazon FSx for Windows File Server, and Amazon FSx for NetApp ONTAP. Previously, Secrets Manager integration was limited to a subset of location types, requiring you to provide credentials directly through the DataSync API or console. You can centralize credential management for all DataSync locations in Secrets Manager, providing a single, consistent approach across all your data transfers. You can also encrypt credentials with your own AWS KMS key instead of the default AWS-owned key, helping you meet your organization's security requirements and governance policies. All secrets are stored in your account, allowing you to update credentials as needed, independent of the DataSync service. DataSync supports two approaches for credential management. You can provide a secret ARN referencing credentials you manage in Secrets Manager for full control over rotation, auditing, and access policies. Alternatively, DataSync can automatically create and manage secrets on your behalf. This capability is available is available in the majority of AWS regions where AWS DataSync is offered. For the full list of supported regions, visit the [AWS Capabilities tool](https://builder.aws.com/build/capabilities) in Builder Center. To get started, visit the [AWS DataSync console](https://console.aws.amazon.com/datasync/). For more information, see [Managing credentials with AWS Secrets Manager](https://docs.aws.amazon.com/datasync/latest/userguide/location-credentials.html) in the AWS DataSync documentation.