Temporary credentials shrink the theft window
A credential that expires in an hour is worth far less to whoever steals it than one that never expires.
That is the entire argument, and it is unusually clean. Long-lived keys copied into a script three years ago are still valid today and nobody knows where they all are. Short-lived credentials, issued on demand, turn a permanent liability into a brief one. The work is in the plumbing to issue them, not in the idea.
More on Passwords and secrets
- Password length beats decorative complexityAdd wheels, not squiggles
- Forced rotation can create predictable passwordsOnly one character moves
- Salts make identical passwords look differentOne grain each
- Every secret copy creates another secret to protectEvery copy needs its own guard
- Secrets in source control have a long memoryThe deletion is just another commit
- Environment variables are not secret vaultsA label on the outside of the bag
