Allows you to generate and store encryption keys
Key Management Service (KMS)
Keys managed by AWS
Encryption keys
Used to create encrypted EBS volumes
KMS
Hardware security module used to generate encryption keys
CloudHSM
Dedicated hardware for security that generates and manages your own encryption keys
CloudHSM
Manages and retrieves secrets (passwords or keys) that encrypts secrets at rest
Secrets Manager
Allows you to retrieve database credentials with an API call
Secrets Manager