What it is

An AWS access key is a long-lived username and password for programs. An Azure client secret is the same idea for an app registration. Both can do whatever the attached identity is allowed to do, from a café Wi-Fi, until someone revokes them.

They are convenient. They also sit in .env files, Slack threads, CI variables from 2022, and laptops that go home on the GO train.

The replacement is a role or managed identity that the cloud hands out at runtime. No file. No spreadsheet. If the laptop is gone, the permission is gone with the session.

Why it matters in the meeting

When someone says “the pipeline needs keys,” ask whether it needs keys or whether it needs permission. Those are different shopping lists.

Bart is not trying to slow the sprint. He is asking whether last year’s intern still has a key that can read the customer bucket. If nobody can list the keys, the answer is we do not know.

Real world

Breaches that start with a key in GitHub are boring, which is why they keep working. The key was created for a demo. The demo shipped. The key did not retire.

AWS IAM Access Analyzer and Entra’s unused credential reports exist so you can find the keys nobody will admit they still have. Using them is less exciting than a new tool. It is also how you sleep.

In plain terms

A long-lived key is a password you cannot remember, stored somewhere you will forget. Prefer a role that expires when the work stops. If you must have a key, treat it like root: few, short-lived, and named after a person who still works here.

What to ask

  • Can we list every AWS access key and Azure client secret that can touch production, with an owner and an age?
  • Which of those have not been used in 90 days, and why do they still exist?
  • Does the CI system assume a role or a managed identity, or does it still paste a key?
  • If a laptop was stolen tonight, which keys would we rotate, and how long would that take?

You just knew a little more Jack than you did five minutes ago.

All concepts