Description
aws_iam_access_key manages access keys for IAM users. user = "root" refers to an IAM user named root, not the AWS account root user. The name alone does not establish account-wide permissions or credential disclosure.
An active access key and its corresponding secret access key form long-term credentials for authenticating AWS requests. Review their actual permissions and consumers, and prefer temporary IAM role credentials for automation.
Potential impact
- If a valid key pair is disclosed, the IAM user’s permissions can be misused from another environment.
- Unused active keys leave unnecessary means of authentication available.
- Revoking keys with unknown owners or consumers can interrupt services.
Remediation
- Review the IAM user’s key status, last use and permissions, and migrate required tasks to role-based access.
- Verify that replacement access works before deactivating and deleting unnecessary keys. Restrict retained keys to least privilege and protect secret values and Terraform state.
- Separately check for and remove access keys belonging to the actual AWS account root user, and enable MFA for that user.
Examples
These partial examples compare IAM access-key ownership. Supply a valid public key for the intended recipient in pgp_key.
Before
resource "aws_iam_access_key" "root_access_key" {
user = "root"
pgp_key = "keybase:some_person_that_exists"
status = "Active"
}
This creates an active key for an existing IAM user named root. It does not create an access key for the AWS account root user.
After
resource "aws_iam_user" "automation_user" {
name = "loadbalancer"
path = "/system/"
}
resource "aws_iam_access_key" "automation_access_key" {
user = aws_iam_user.automation_user.name
pgp_key = "keybase:some_person_that_exists"
}
This creates an automation IAM user and a new key. Omitting status defaults to Active; the example does not deactivate or delete the old key. Configure required permissions, secret-key delivery and old-key cleanup separately.