Do you have a good reason for continuing to use passwords, though? It might be possible for you to go passwordless by using AWS's Kerberos service to allow application/service/database mutual authentication without needing passwords - and therefore - without needing password rotation.