Skip to main content

AWS Secret Manager

info

โœจ This is an Enterprise Feature

Enterprise Pricing

Contact us here to get a free trial

Store your proxy keys in AWS Secret Manager.

FeatureSupportDescription
Reading Secretsโœ…Read secrets e.g OPENAI_API_KEY
Writing Secretsโœ…Store secrets e.g Virtual Keys

Proxy Usageโ€‹

  1. Save AWS Credentials in your environment
os.environ["AWS_ACCESS_KEY_ID"] = ""  # Access key
os.environ["AWS_SECRET_ACCESS_KEY"] = "" # Secret access key
os.environ["AWS_REGION_NAME"] = "" # us-east-1, us-east-2, us-west-1, us-west-2
  1. Enable AWS Secret Manager in config.
general_settings:
master_key: os.environ/litellm_master_key
key_management_system: "aws_secret_manager" # ๐Ÿ‘ˆ KEY CHANGE
key_management_settings:
hosted_keys: ["litellm_master_key"] # ๐Ÿ‘ˆ Specify which env keys you stored on AWS

  1. Run proxy
litellm --config /path/to/config.yaml

Using K/V pairs in 1 AWS Secretโ€‹

You can read multiple keys from a single AWS Secret using the primary_secret_name parameter:

general_settings:
key_management_system: "aws_secret_manager"
key_management_settings:
hosted_keys: [
"OPENAI_API_KEY_MODEL_1",
"OPENAI_API_KEY_MODEL_2",
]
primary_secret_name: "litellm_secrets" # ๐Ÿ‘ˆ Read multiple keys from one JSON secret

The primary_secret_name allows you to read multiple keys from a single AWS Secret as a JSON object. For example, the "litellm_secrets" would contain:

{
"OPENAI_API_KEY_MODEL_1": "sk-key1...",
"OPENAI_API_KEY_MODEL_2": "sk-key2..."
}

This reduces the number of AWS Secrets you need to manage.