Review the number of access keys for an IAM user

Remove unnecessary IAM access keys.

Description

Access keys are long-term credentials, so remove keys that are no longer used. Keeping an old and a new key briefly during rotation can be necessary.

Potential impact

Old keys complicate credential management and can be exposed and misused even when no longer needed.

Remediation

Confirm that the new key works, then deactivate and remove the old key. Use IAM roles and temporary credentials where possible.

Examples

The examples compare two keys for one user with a single key. Replace the Keybase value with the actual recipient’s public key.

Before

hcl
resource "aws_iam_access_key" "primary" {
  user    = aws_iam_user.lb.name
  pgp_key = "keybase:some_person_that_exists"
}

resource "aws_iam_access_key" "secondary" {
  user    = aws_iam_user.lb.name
  pgp_key = "keybase:some_person_that_exists"
}

resource "aws_iam_user" "lb" {
  name = "loadbalancer"
  path = "/system/"
}

After

hcl
resource "aws_iam_user" "example" {
  name = "loadbalancer"
  path = "/system/"

  tags = {
    tag-key = "tag-value"
  }
}

resource "aws_iam_access_key" "primary" {
  user    = aws_iam_user.example.name
  pgp_key = "keybase:some_person_that_exists"
}

References