Description
Access keys are long-term credentials, so remove keys that are no longer used. Keeping an old and a new key briefly during rotation can be necessary.
Potential impact
Old keys complicate credential management and can be exposed and misused even when no longer needed.
Remediation
Confirm that the new key works, then deactivate and remove the old key. Use IAM roles and temporary credentials where possible.
Examples
The examples compare two keys for one user with a single key. Replace the Keybase value with the actual recipient’s public key.
Before
hcl
resource "aws_iam_access_key" "primary" {
user = aws_iam_user.lb.name
pgp_key = "keybase:some_person_that_exists"
}
resource "aws_iam_access_key" "secondary" {
user = aws_iam_user.lb.name
pgp_key = "keybase:some_person_that_exists"
}
resource "aws_iam_user" "lb" {
name = "loadbalancer"
path = "/system/"
}
After
hcl
resource "aws_iam_user" "example" {
name = "loadbalancer"
path = "/system/"
tags = {
tag-key = "tag-value"
}
}
resource "aws_iam_access_key" "primary" {
user = aws_iam_user.example.name
pgp_key = "keybase:some_person_that_exists"
}