IAMmedium3-5 years

A service on ECS reads an access key and secret from `application.properties` (injected from a CI variable) to talk to S3 and Secrets Manager. You are asked to 'harden' it. What should replace the key, how does the SDK find credentials with no configuration, and what does the policy on the new identity look like?

A service on AWS should never hold an access key. It should run as a role: on ECS a task role, on EC2 an instance profile, on EKS a service account mapped to a role (IRSA or Pod Identity), on Lambda an execution role. The platform hands the SDK temporary credentials for that role and rotates them, and the SDK's default credential chain finds them on its own, which is why S3Client.create() works in production with nothing in application.properties. The role's policy is then the service's whole permission set, written with least privilege: PutObject on the uploads prefix and GetSecretValue on one secret, nothing else. The key goes away entirely, and then gets deactivated and deleted.

The lesson behind it →
More on IAM