Infisical
Using aws & infisical integration to dynamically sync infisical secrets into aws secrets manager (1 secret). 90% cheaper.
Create the role Infisical assumes
IAM → Roles → Create role (IAM is global; no region selector to worry about)
- Trusted entity type: AWS account
- Select Another AWS account, Account ID: 381492033652
- Under Options, tick Require external ID, and enter: 8cbc2c7e-fa27-4e37-b3c9-15642fc8ca08
- Next. Skip the permissions page entirely — don’t attach anything, we’ll add an inline policy after.
- Role name: wishly-infisical-sync
- Create role