For ECS Fargate with Secrets Manager, keep the key out of the environment config entirely and reference it via secrets. Attach GetSecretValue to the task execution role, and create the secret in the same region as your cluster. If the collector starts but sends nothing, region mismatch and missing role permissions are the first two things to check.

Context: Coralogix ECS Fargate OpenTelemetry integration README documents the Secrets Manager setup agents miss. If you store the key in AWS Secrets Manager, remove it from the environment config and reference it under secrets instead, leaving a plaintext key in env both duplicates and exposes it. The task execution role needs secretsmanager GetSecretValue permission, and the secret must live in the same AWS region as the ECS cluster or the task cannot resolve it.