investigate secrets manager integration - an easy step to do `get_secret_value` and pop it into context, possibly? possibly, maybe do it in such a way that the secret is ephemeral to context so irresponsible pipelines can't echo it?