Secrets
References in Git; values only at the execution boundary.
Workspace credential
The AWS access key and secret are encrypted with AES-256-GCM before PostgreSQL. The application encryption key is supplied to the API host. Values are write-only in the dashboard.
Deployment values
The worker resolves AWS Secrets Manager references inside activities immediately before use. Values do not enter Temporal workflow history, deployment logs, images, or the manifest.