github.com/aquasecurity/trivy-iac@v0.8.1-0.20240127024015-3d8e412cf0ab/avd_docs/aws/ecs/AVD-AWS-0036/docs.md (about) 1 2 You should not make secrets available to a user in plaintext in any scenario. Secrets can instead be pulled from a secure secret storage system by the service requiring them. 3 4 ### Impact 5 Sensitive data could be exposed in the AWS Management Console 6 7 <!-- DO NOT CHANGE --> 8 {{ remediationActions }} 9 10 ### Links 11 - https://docs.aws.amazon.com/systems-manager/latest/userguide/integration-ps-secretsmanager.html 12 13 - https://www.vaultproject.io/ 14 15