Credentials in Secret Manager. Configuration in Parameter Manager.
The same split AWS draws between Secrets Manager and Parameter Store — provider-independent reasoning.
Secret Manager
API keys, passwords, private keys — exposure IS the incident. Strict access control, rotation.
Parameter Manager
Connection strings, feature flags — JSON/YAML validated, can reference a secret inline. Preview status — verify before depending on it.
Configuration changes far more often than credentials. Treating both identically either over-audits routine config or under-protects real secrets.