Review access keys for an IAM user named root

Distinguish an IAM user named root from the AWS account root user and verify the key’s actual owner, permissions and exposure.

Description

The user argument of aws_iam_access_key is an IAM user name. Setting user = "root" does not create credentials for the AWS account root user. The presence of an active key alone does not establish secret disclosure or account-wide permissions.

If an actual access key ID and secret access key are exposed, however, the IAM user’s permitted operations can be misused. Confirm the owner, consumers and permissions, and review whether a long-term key is necessary.

Potential impact

  • Someone who obtains a valid key pair can perform AWS operations allowed for the IAM user.
  • Unnecessary active keys increase opportunities for long-term credential exposure.
  • Broad access to state files or deployment outputs can expose secret access keys.

Remediation

  • Prefer temporary role credentials for automation and grant retained IAM keys only the permissions they need.
  • Restrict access to secrets and Terraform state. If actual disclosure is confirmed, migrate consumers, revoke the key and investigate related API activity.
  • Separately check for and remove AWS account root-user access keys. Renaming an IAM user does not clean up actual root credentials.

Examples

These partial examples require the IAM user receiving the key to exist already.

Before

hcl
resource "aws_iam_access_key" "example" {
  user   = "root"
  status = "Active"
}

This creates an active key for an IAM user named root. Its actual policies determine permissions; the name does not confer AWS account root authority.

After

hcl
resource "aws_iam_access_key" "example" {
  user = "some-user"
}

This changes the target user to some-user. Omitting status still defaults to Active, so this is not a key-deactivation change. Review the target user’s permissions and need for the key separately.

References