Skip to content

Cloud Secrets Manager Comparison

Public reference for skret’s supported and roadmap backends. Numbers below use a representative scale: 340 secrets, 30k reads/month, ap-southeast-1 (Singapore) region.

RankBackendCost/monthFree tierFit
1AWS SSM Parameter Store (Standard)$0.0010k params + free Std APIPrimary
2OCI Vault (software-protected)$0.00150 secrets permanentTier-1 roadmap
3Azure Key Vault (Standard)$0.09None (effectively free at scale)Tier-1 roadmap
4GCP Secret Manager$20.106 versions + 10k ops/monthTier-2 roadmap
5AWS SSM Advanced$17.15NoneFallback for >4 KB
6AWS Secrets Manager$136.1530-day/secret trialOnly for managed rotation
  1. Two backends are genuinely free at this scale: AWS SSM Parameter Store (Standard) and OCI Vault (software-protected). Both viable as defaults.
  2. AWS Secrets Manager is ~1,500× more expensive than SSM Standard at this scale, with benefits (managed rotation) that most configuration secrets do not require.
  3. GCP Secret Manager costs ~$20/month — reasonable for multi-cloud parity, but 200× more expensive than the free options with overlapping features.
FeatureAWS SSM StdOCI VaultAzure KV StdGCP SMAWS Secrets Mgr
Max value size4 KB25 KB25 KB64 KB64 KB
Versioning100 fixed40 / secretunlimitedunlimited + aliasesunlimited
Automatic rotation4-step lifecyclevia Event GridPub/Sub triggersLambda (managed)
Cross-region replicationManualManualGeo-redundant (premium)Auto / user-managedAuto replica
Audit logCloudTrailOCI AuditAzure MonitorCloud AuditCloudTrail
Private networkPrivateLinkService GatewayPrivate EndpointVPC-SCPrivateLink
KMS integrationaws/ssm freeSoftware/HSM keysManaged HSMCMEKaws/secretsmanager
IAM modelIAM policiesIAM + compartmentsRBAC + Azure ADIAM + conditionsIAM policies
API rate limit40 TPS sharedSoft-limited2k req/10s90k read/min10k TPS
Go SDK maturityGA (v2)GAGA (track-2)GAGA (v2)
BackendSOC 2ISO 27001FedRAMP HighHIPAAPCI-DSS
AWS SSM
OCI Vault
Azure Key Vault
GCP Secret Manager
AWS Secrets Manager
BackendSingaporeTokyoSeoulMumbaiSydney
AWS SSMap-southeast-1ap-northeast-1ap-northeast-2ap-south-1ap-southeast-2
OCI Vaultap-singapore-1ap-tokyo-1ap-seoul-1ap-mumbai-1ap-sydney-1
Azure KVsoutheastasiajapaneastkoreacentralcentralindiaaustraliaeast
GCP SMasia-southeast1asia-northeast1asia-northeast3asia-south1australia-southeast1
AWS Secrets Managerap-southeast-1ap-northeast-1ap-northeast-2ap-south-1ap-southeast-2

Solo developer (1 repo × 20 secrets × 100 reads/day)

Section titled “Solo developer (1 repo × 20 secrets × 100 reads/day)”
BackendMonthly cost
AWS SSM Standard$0
OCI Vault$0 (within 150 free cap)
Azure Key Vault~$0.01
GCP Secret Manager~$0.84 (14 active versions × $0.06)
AWS Secrets Manager~$8.00

Small team (5 repos × 30 secrets × 5,000 reads/day)

Section titled “Small team (5 repos × 30 secrets × 5,000 reads/day)”
BackendMonthly cost
AWS SSM Standard$0
OCI Vault$0 (within 150 free cap)
Azure Key Vault~$0.45
GCP Secret Manager~$9
AWS Secrets Manager~$60

Large scale (100 repos × 50 secrets × 100,000 reads/day)

Section titled “Large scale (100 repos × 50 secrets × 100,000 reads/day)”
BackendMonthly cost
AWS SSM Standard$0 to ~$1.50 (may need Higher Throughput)
OCI Vault$0 (software keys; verify billing)
Azure Key Vault~$0.90
GCP Secret Manager~$300
AWS Secrets Manager~$2,000

AWS SSM Parameter Store (Standard) is skret’s default:

  • $0/month at any realistic scale under 10k parameters.
  • SecureString with AWS-managed KMS key is free.
  • CloudTrail audit is included.
  • 4 KB limit covers the vast majority of configuration secrets. The rare oversized items (TLS certs, JSON blobs) can use a secondary backend via overrides: in .skret.yaml.

Users with existing OCI tenancy can set OCI Vault (software-protected) as default with equivalent cost. Tier-2 and Tier-3 backends come online as skret’s provider registry expands.