Review active IAM user access keys

Remove unnecessary IAM user access keys and use temporary credentials where possible.

Description

IAM user access keys are long-term credentials. Keeping unnecessary keys active increases the opportunity for disclosure or misuse. An active key is not evidence of a leak, and an access key ID alone cannot authenticate requests: the corresponding secret access key is also required.

Prefer federation and temporary credentials for people and roles for workloads. Where a long-term key is necessary, manage its owner, purpose, usage and permissions. Root user access keys are not an alternative.

Potential impact

  • Disclosure of an active key and its secret can allow misuse of the user's permitted actions.
  • Unused keys complicate credential management, while disabling a key without checking its dependencies can interrupt services.

Remediation

  1. Check the key's actual owner and usage, and move required automation to roles or temporary credentials.
  2. Test replacement authentication before deactivating unnecessary keys, then delete them after confirming normal operation. Replace and revoke suspected exposed credentials and investigate their use.
  3. Apply least privilege to keys that must remain and keep their secrets out of repositories, logs and source code.

Examples

These examples use the current IAM user access key module to change the same key's state. Supply the actual IAM user and a key ID belonging to that user. Configure separate AWS authentication for running the module.

Before

yaml
- name: Enable a selected IAM user access key
  amazon.aws.iam_access_key:
    user_name: "{{ iam_user_name }}"
    id: "{{ access_key_id }}"
    state: present
    active: true

This enables the selected key. Confirm that it serves a legitimate operational need.

After

yaml
- name: Disable a selected IAM user access key
  amazon.aws.iam_access_key:
    user_name: "{{ iam_user_name }}"
    id: "{{ access_key_id }}"
    state: present
    active: false

This deactivates the same key without deleting it. Verify dependent workloads and the key's actual state.

References