Cloud roles can replace copied long-lived keys
The long-lived cloud access key copied into a config file is one of the most reliable ways organisations get breached.
The alternative is for the workload to assume a role and receive short-lived credentials automatically, with nothing to copy and nothing to leak. The keys stop existing rather than being better protected, which is a much stronger position. Where this is available it removes an entire class of incident rather than mitigating it.
More on Cloud IAM
- Resource policies create a second authorisation surfaceThe thing has a policy too
- Permission boundaries cap delegated powerGrant what you like. It stops at the rail
- Organisation guardrails prevent dangerous local choicesThe wrong setting is not on the dial
- Cross-account trust expands the identity perimeterYour perimeter now runs round their office
- Console access and workload access are different pathsTwo doors, one room
- Unused cloud permissions are latent attack pathsStill wired
