CloudBurn Logo
CloudBurnHome
  • Cost estimation

    • AWS Simple Pricing CalculatorEstimate your AWS stack
    • IaC Cost EstimatorReview costs before merge

    Cost Optimization

    • Unused resourcesFind resources to remove
    • Resource efficiencyImprove what you keep
    • Commitment savingsReview plans and reservations
    • Cost GovernanceBudgets, alerts, and tags

    Product

    • RoadmapWhat's coming next
    • ChangelogProduct updates
    • DocsGuides and reference
    • AboutWhy CloudBurn exists
  • Pricing
  • Blog
  • Tools
Join the CloudBurn Discord community
Notify me at launch
Join the CloudBurn Discord community1.8k
Navigation
    • Overview
    • Understanding Rules
      • CloudFront
      • CloudTrail
      • CloudWatch
      • AWS Config
      • Cost Explorer
      • Cost Guardrails
      • Cost Optimization Hub
      • DynamoDB
      • EBS
      • EC2
      • ECR
      • ECS
      • EKS
      • ElastiCache
      • ELB
      • EMR
      • KMS
      • Lambda
      • RDS
      • Redshift
      • Route 53
      • S3
      • SageMaker
      • Secrets Manager
      • Tagging
    • Overview
    • Understanding Rules
      • CloudFront
      • CloudTrail
      • CloudWatch
      • AWS Config
      • Cost Explorer
      • Cost Guardrails
      • Cost Optimization Hub
      • DynamoDB
      • EBS
      • EC2
      • ECR
      • ECS
      • EKS
      • ElastiCache
      • ELB
      • EMR
      • KMS
      • Lambda
      • RDS
      • Redshift
      • Route 53
      • S3
      • SageMaker
      • Secrets Manager
      • Tagging
Loading documentation page
CloudBurn Logo
CloudBurn

Open-source AWS cost checks and an upcoming platform for cost estimation, optimization, and governance.

1.8k

Product

  • Pricing
  • Roadmap
  • Changelog
  • About
  • Blog
  • Newsletter
  • Docs
  • Contact

Free Tools

  • Lambda Cost Calculator
  • EC2 Pricing Calculator
  • S3 Pricing Calculator
  • EBS Pricing Calculator
  • Fargate Pricing Calculator
  • RDS Pricing Calculator
  • Aurora Cost Calculator
  • All AWS pricing calculators →

Newsletter

Subscribe for CloudBurn product updates, changelogs, and actionable AWS cost optimization tips delivered to your inbox.

Newsletter signup form loading.
Enter your email…
Subscribe
---- subscribers
OR SIGN UP WITH
GGH

By signing up you agree to our privacy policy.

CloudBurn © 2026 | Terms & Privacy

Built with ❤️ by Towards the Cloud

CloudBurn Rules

Secrets Manager Rules

CloudBurn cost optimization rules for AWS Secrets Manager.

These rules flag forgotten secrets sitting in Secrets Manager that no application has accessed in months.

Rule IDScan TypeSeverityName
CLDBRN-AWS-SECRETSMANAGER-1DiscoveryLowSecrets Manager Secret Unused

CLDBRN-AWS-SECRETSMANAGER-1

Secrets Manager Secret Unused

Scan type: Discovery

Severity: Low

What it checks

Flags Secrets Manager secrets that have not been accessed for more than 90 days, or that have never been accessed at all. Unused secrets indicate credentials or configuration values that no running application retrieves.

Why it matters

Secrets Manager charges $0.40 per secret per month. A handful of forgotten secrets may seem trivial, but teams that provision secrets for every environment and experiment often accumulate dozens over time. Beyond cost, unused secrets are a security liability: stale credentials that nobody monitors are prime targets for credential compromise.

What triggers a finding

Either of these conditions:

  • The secret has no lastAccessedDate (it was created but never retrieved)
  • The lastAccessedDate is more than 90 days in the past

How to remediate

  1. Verify the secret is truly unused by checking CloudTrail for GetSecretValue events
  2. If the secret backs a decommissioned application, delete it:
# Schedule deletion with 7-day recovery window
aws secretsmanager delete-secret \
  --secret-id my-old-secret \
  --recovery-window-in-days 7
  1. If the secret is still needed but accessed infrequently, consider whether SSM Parameter Store (SecureString) would be a cheaper alternative at $0.05 per 10,000 API calls with no per-parameter charge

See Also

  • CLI discover command - scan live Secrets Manager resources
  • SDK Reference - run discovery programmatically
← PreviousSageMakerNext →Tagging