aws-cdk.aws-secretsmanager
The CDK Construct Library for AWS::SecretsManager
Decision gist · record as of 2026-08-14
No—do not install. This package is end-of-support as of 2023-06-01 and explicitly deprecated in favor of AWS CDK v2. While it has low install friction and no known vulnerabilities, using an unsupported major version of AWS CDK introduces technical debt and blocks access to bug fixes and security updates. Migrate to aws-cdk-lib.aws_secretsmanager (CDK v2) instead.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires AWS CDK v1 environment; v1 is end-of-support as of 2023-06-01 and users should migrate to AWS CDK v2 instead.
- Low install friction with 11 runtime dependencies, all AWS CDK modules and supporting libraries.
- However, the package is explicitly end-of-support as of 2023-06-01; the description banner states AWS CDK v1 has reached End-of-Support and users should migrate to AWS CDK v2.
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing commercial use, modification, and distribution with minimal restrictions—standard for AWS CDK libraries.
last release 2023-06-19 (1152 days) · last repo commit 2026-08-14 · 12,868 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 151,492 downloads/mo, #10,930 on PyPI
Alternatives
Verify before relying
pip install aws-cdk.aws-secretsmanager
import aws_cdk.aws_secretsmanager as secretsmanager
secret = secretsmanager.Secret(self, "Secret")
secret.grant_read(role)- Whether AWS CDK v2 equivalent (aws-cdk-lib.aws_secretsmanager) is recommended as a drop-in replacement or requires code changes.
- Current security patch status and timeline for v1 end-of-life support.
What it is and what it does
This is the AWS CDK v1 construct library for AWS Secrets Manager, a service for storing and rotating database credentials, API keys, and other secrets in AWS. It provides Python classes to define secrets as infrastructure-as-code, configure automatic rotation via Lambda functions or hosted rotation for databases like MySQL and PostgreSQL, and grant read/write permissions to IAM roles and principals.
The library integrates with AWS KMS for encryption, supports importing existing secrets by ARN or name, and handles cross-account access through resource and KMS key policies. However, AWS CDK v1 reached end-of-support on 2023-06-01, and the package is no longer being updated; users are directed to migrate to AWS CDK v2.
Use it for
- Define and provision database credentials as CDK constructs, with automatic secret generation and KMS encryption.
- Set up automated secret rotation schedules using custom Lambda functions or AWS-hosted rotation for MySQL, PostgreSQL, Oracle, and other databases.
- Grant IAM roles and cross-account principals read and write permissions to secrets with automatic KMS key policy updates.
- Import existing secrets from AWS Secrets Manager by ARN or name into a CDK stack for reference in other constructs.
- Manage database credential rotation in VPC-deployed environments using hosted rotation with network connectivity rules.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No—do not install.
This package is end-of-support as of 2023-06-01 and explicitly deprecated in favor of AWS CDK v2. While it has low install friction and no known vulnerabilities, using an unsupported major version of AWS CDK introduces technical debt and blocks access to bug fixes and security updates. Migrate to aws-cdk-lib.aws_secretsmanager (CDK v2) instead.
Install
aws-cdk-aws-secretsmanager on PyPI
Before you install
Low install friction with 11 runtime dependencies, all AWS CDK modules and supporting libraries. However, the package is explicitly end-of-support as of 2023-06-01; the description banner states AWS CDK v1 has reached End-of-Support and users should migrate to AWS CDK v2. Active repository maintenance does not offset the deprecated status.
Requires AWS CDK v1 environment; v1 is end-of-support as of 2023-06-01 and users should migrate to AWS CDK v2 instead.
License in practice
Licensed under Apache-2.0 (permissive), allowing commercial use, modification, and distribution with minimal restrictions—standard for AWS CDK libraries.
Quickstart
pip install aws-cdk.aws-secretsmanager
import aws_cdk.aws_secretsmanager as secretsmanager
secret = secretsmanager.Secret(self, "Secret")
secret.grant_read(role)
Verify before relying
- Whether AWS CDK v2 equivalent (aws-cdk-lib.aws_secretsmanager) is recommended as a drop-in replacement or requires code changes.
- Current security patch status and timeline for v1 end-of-life support.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release ~=3.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 11 packagesaws-cdk.aws-ec2aws-cdk.aws-iamaws-cdk.aws-kmsaws-cdk.aws-lambdaaws-cdk.aws-samaws-cdk.coreaws-cdk.cx-apiconstructsjsiipublicationtypeguard |
| Maintenance | Actively maintained 1,152 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 151,492 / month, #10,930 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 7 - InactiveFramework :: AWS CDKFramework :: AWS CDK :: 1Intended Audience :: DevelopersLicense :: OSI ApprovedOperating System :: OS IndependentProgramming Language :: JavaScriptProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Typing :: Typed |
Evidence: aws_cdk.aws_secretsmanager-1.204.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “aws secrets manager cdk”
- aws-cdk.aws-secretsmanagerAWS CDK construct library for provisioning and managing AWS Secrets…
- datadog-cdk-constructs-v2Provides AWS CDK constructs to automatically instrument Lambda…
- aws-cdk.aws-glue-alphaProvides AWS CDK L2 constructs for defining AWS Glue jobs (Spark ETL,…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also aws-cdk.aws-kms · aws-secretsmanager-caching · credstash · aws-cdk.aws-ssm · aws-cdk.aws-iam · cerberus-python-client · aws-cdk.aws-ecr · aws-cdk.aws-dynamodb · aws-cdk.aws-s3 · aws-cdk.region-info