Cloud roles can replace copied long-lived keys

The long-lived cloud access key copied into a config file is one of the most reliable ways organisations get breached.

The alternative is for the workload to assume a role and receive short-lived credentials automatically, with nothing to copy and nothing to leak. The keys stop existing rather than being better protected, which is a much stronger position. Where this is available it removes an entire class of incident rather than mitigating it.

More on Cloud IAM