Description
Putting AWS credentials in Lambda environment.variables leaves secrets in deployment configuration or Terraform state. They can also be exposed if the function logs its environment or configuration access is granted too broadly. An access key ID alone cannot authenticate API calls, but disclosure of its corresponding secret access key can allow misuse of the granted permissions.
Use the execution role’s temporary credentials when the function accesses AWS resources. This role is separate from the identity used to deploy the function.
Potential impact
- Valid credentials may be reused from another environment to perform permitted AWS operations.
- Secrets copied into code and deployment settings are difficult to replace and trace to their consumers.
- Revoking an exposed key can interrupt functions that still depend on it.
Remediation
- Remove access key IDs and secret access keys from environment variables, and give the execution role only the permissions it needs.
- Manage external-service secrets in Secrets Manager or as Systems Manager Parameter Store
SecureStringvalues, and restrict the function’s retrieval permissions. - Migrate consumers off exposed credentials, revoke them and investigate related activity. Address copies retained in source, state and logs.
Examples
These are partial examples. Set lambda_runtime to a supported runtime compatible with the deployment package and handler, and configure the referenced execution role separately.
Before
resource "aws_lambda_function" "lambda_function" {
filename = "lambda_function_payload.zip"
function_name = "lambda_function_name"
role = aws_iam_role.iam_for_lambda.arn
handler = "exports.test"
runtime = var.lambda_runtime
environment {
variables = {
foo = "AKIAIOSFODNN7EXAMAAA"
}
}
}
The foo variable contains an illustrative string resembling an access key ID. The value does not establish that the credentials are valid; do not pass real long-term credentials this way.
After
resource "aws_lambda_function" "lambda_function" {
filename = "lambda_function_payload.zip"
function_name = "lambda_function_name"
role = aws_iam_role.iam_for_lambda.arn
handler = "exports.test"
runtime = var.lambda_runtime
environment {
variables = {
foo = "test"
}
}
}
The foo value becomes an ordinary string. This does not configure the execution role’s permissions or revoke an already exposed key; perform those steps separately.