Review AWS credentials in Lambda environment variables

Keep long-term AWS credentials out of Lambda environment variables and use temporary credentials from the execution role.

Description

Putting AWS credentials in Lambda environment.variables leaves secrets in deployment configuration or Terraform state. They can also be exposed if the function logs its environment or configuration access is granted too broadly. An access key ID alone cannot authenticate API calls, but disclosure of its corresponding secret access key can allow misuse of the granted permissions.

Use the execution role’s temporary credentials when the function accesses AWS resources. This role is separate from the identity used to deploy the function.

Potential impact

  • Valid credentials may be reused from another environment to perform permitted AWS operations.
  • Secrets copied into code and deployment settings are difficult to replace and trace to their consumers.
  • Revoking an exposed key can interrupt functions that still depend on it.

Remediation

  • Remove access key IDs and secret access keys from environment variables, and give the execution role only the permissions it needs.
  • Manage external-service secrets in Secrets Manager or as Systems Manager Parameter Store SecureString values, and restrict the function’s retrieval permissions.
  • Migrate consumers off exposed credentials, revoke them and investigate related activity. Address copies retained in source, state and logs.

Examples

These are partial examples. Set lambda_runtime to a supported runtime compatible with the deployment package and handler, and configure the referenced execution role separately.

Before

hcl
resource "aws_lambda_function" "lambda_function" {
  filename      = "lambda_function_payload.zip"
  function_name = "lambda_function_name"
  role          = aws_iam_role.iam_for_lambda.arn
  handler       = "exports.test"
  runtime       = var.lambda_runtime

  environment {
    variables = {
      foo = "AKIAIOSFODNN7EXAMAAA"
    }
  }
}

The foo variable contains an illustrative string resembling an access key ID. The value does not establish that the credentials are valid; do not pass real long-term credentials this way.

After

hcl
resource "aws_lambda_function" "lambda_function" {
  filename      = "lambda_function_payload.zip"
  function_name = "lambda_function_name"
  role          = aws_iam_role.iam_for_lambda.arn
  handler       = "exports.test"
  runtime       = var.lambda_runtime

  environment {
    variables = {
      foo = "test"
    }
  }
}

The foo value becomes an ordinary string. This does not configure the execution role’s permissions or revoke an already exposed key; perform those steps separately.

References