Review active access keys for an IAM user

Confirm the owner and purpose of IAM access keys and remove unnecessary long-term credentials.

Description

aws_iam_access_key manages access keys for IAM users. user = "root" refers to an IAM user named root, not the AWS account root user. The name alone does not establish account-wide permissions or credential disclosure.

An active access key and its corresponding secret access key form long-term credentials for authenticating AWS requests. Review their actual permissions and consumers, and prefer temporary IAM role credentials for automation.

Potential impact

  • If a valid key pair is disclosed, the IAM user’s permissions can be misused from another environment.
  • Unused active keys leave unnecessary means of authentication available.
  • Revoking keys with unknown owners or consumers can interrupt services.

Remediation

  • Review the IAM user’s key status, last use and permissions, and migrate required tasks to role-based access.
  • Verify that replacement access works before deactivating and deleting unnecessary keys. Restrict retained keys to least privilege and protect secret values and Terraform state.
  • Separately check for and remove access keys belonging to the actual AWS account root user, and enable MFA for that user.

Examples

These partial examples compare IAM access-key ownership. Supply a valid public key for the intended recipient in pgp_key.

Before

hcl
resource "aws_iam_access_key" "root_access_key" {
  user    = "root"
  pgp_key = "keybase:some_person_that_exists"
  status  = "Active"
}

This creates an active key for an existing IAM user named root. It does not create an access key for the AWS account root user.

After

hcl
resource "aws_iam_user" "automation_user" {
  name = "loadbalancer"
  path = "/system/"
}

resource "aws_iam_access_key" "automation_access_key" {
  user    = aws_iam_user.automation_user.name
  pgp_key = "keybase:some_person_that_exists"
}

This creates an automation IAM user and a new key. Omitting status defaults to Active; the example does not deactivate or delete the old key. Configure required permissions, secret-key delivery and old-key cleanup separately.

References