infra across accounts and regions be aware of secrets and encryption • To use Secret Manager secrets across accounts, specific policies on the secret must be set • This is cumbersome • To use secrets across regions in the same account, Secret Manager secret replication is ideal • When encrypting in multiple accounts/regions, KMS keys must be managed. • Each account/region has it’s own master keys, which is used in many instances as the default KMS key to encrypt with