OrchestrAI Live

AWS · Cloud service

AWS Secrets Manager with OrchestrAI

Catalog exported 2026-09-02

Handle AWS Secrets Manager from chat: create secrets, store values, rotate, and set resource policies.

OrchestrAI exposes 10 Secrets Manager operations: 3 are low-risk (read-only or low-impact), and 7 create or modify resources and run only after you confirm the plan. 6 of them also carry a step-level approval gate.

10operations
3low risk
7create or modify
0destructive
6step-level approval

What teams use it for

Teams use OrchestrAI to create a secret for a new database credential, store a new version of a value, retrieve a value during an incident, configure automatic rotation through a Lambda function, trigger a rotation immediately, and attach a resource policy for cross-account access. Retrieving a value is medium risk, while creating, updating, rotating, and setting policies are high risk with confirmation. Listing secrets, describing them, and deleting them are not available, so an inventory of what exists comes from the console.

Every Secrets Manager operation, with its risk level

AWS Secrets Manager operations available through OrchestrAI
Operation What it does Risk Step-level approval
Create Secret (Terraform-style) Create a Secrets Manager secret Low risk No
Set Secret Resource Policy Set a resource-based policy on a Secrets Manager secret Low risk No
Set Secrets Resource Policy Set a resource-based policy on a secret Low risk No
Configure Secret Rotation Configure automatic rotation for a secret using a Lambda function Creates resources Yes
Get Secret Value Retrieve a secret value from Secrets Manager Creates resources No
Update Secret Value Update the value of a Secrets Manager secret Creates resources Yes
Create Secret Create a new secret in Secrets Manager Modifies existing Yes
Put Secret Resource Policy Attach a resource-based policy to a secret for cross-account access Modifies existing Yes
Put Secret Value Store or update the value of a secret in Secrets Manager Modifies existing Yes
Rotate Secret Rotate a secret in Secrets Manager Modifies existing Yes

Risk tiers come from the catalog: low is read-only or low-impact, medium creates resources and is reversible, high modifies existing resources, destructive may lose data. Every plan that creates or changes resources is shown with its cost estimate and waits for your confirmation. Operations marked with a step-level approval pause again on their own step. Destructive operations require a typed risk phrase.

Prompts that work

  • Create a secret named prod/orders-db with the username and password I paste next
  • Rotate the prod/payments-api-key secret now
  • Configure rotation on prod/orders-db every 30 days using the rotate-rds-secret Lambda

Before anything runs

Every mutation shows its plan, cost estimate, and blast radius, then waits for your confirmation. Destructive operations require a typed risk phrase. Credentials are minted per run through OIDC federation and discarded afterward; nothing you create here is invisible later, because every resource lands in the desired-state ledger where drift is detected and can be converged. Details on the security page.

Frequently asked questions

Can OrchestrAI list the secrets in my Secrets Manager account?
No, there is no list or describe operation, so you need the secret name to work with it.
How is retrieving a secret value handled in OrchestrAI?
It is a medium-risk operation and the value is used within the run. Creating or updating a secret value is high risk and waits for your confirmation.
Which Secrets Manager operations need an extra approval step?
6 operations carry a step-level approval gate on top of plan confirmation: Create Secret, Rotate Secret, Update Secret Value, Put Secret Resource Policy, Configure Secret Rotation, Put Secret Value. None of them is classed destructive.

Other AWS services

Related integrations

Try it on your own account

Connect your cloud read-only and see your resources, drift, and costs before anything runs. $5 minimum to start. Unused credits refunded in your first 14 days.

Start for $5

Unused credits refunded in your first 14 days.