How should I handle configuration and secrets in Amazon Web Services?
Configuration must be available to the application without exposing credentials in source control, logs or browser code. What belongs in the runtime and which access controls matter?