My service on AWS connects without a single key in the .env
Published on August 31, 2026
𝗠𝘆 𝘀𝗲𝗿𝘃𝗶𝗰𝗲 𝗼𝗻 𝗔𝗪𝗦 𝗰𝗼𝗻𝗻𝗲𝗰𝘁𝘀 𝘄𝗶𝘁𝗵𝗼𝘂𝘁 𝗮 𝘀𝗶𝗻𝗴𝗹𝗲 𝗸𝗲𝘆 𝗶𝗻 𝘁𝗵𝗲 .𝗲𝗻𝘃
On my local machine I need credentials to talk to AWS. In production I define none — and it works just the same 😅
At my current job, when I develop from my machine I assume an 𝗜𝗔𝗠 𝗿𝗼𝗹𝗲 with a 𝗹𝗲𝗮𝘀𝘁 𝗽𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲 𝗽𝗼𝗹𝗶𝗰𝘆 and use that role's temporary credentials to connect to the services. But the day I deployed that same service inside AWS, I didn't define any of those variables… and it kept connecting just fine 💻
The reason is that the 𝗔𝗪𝗦 𝗦𝗗𝗞 doesn't look for credentials in a single place. It walks a 𝗰𝗵𝗮𝗶𝗻 𝗼𝗳 𝗽𝗿𝗼𝘃𝗶𝗱𝗲𝗿𝘀, in order 👇
1️⃣ Environment variables — what I use locally
2️⃣ The ~/.aws/credentials profile
3️⃣ The 𝗜𝗔𝗠 𝗿𝗼𝗹𝗲 𝗮𝘁𝘁𝗮𝗰𝗵𝗲𝗱 𝘁𝗼 𝘁𝗵𝗲 𝗶𝗻𝘀𝘁𝗮𝗻𝗰𝗲 — what happens in production
When the service runs inside AWS with an attached role, the SDK asks the 𝗶𝗻𝘀𝘁𝗮𝗻𝗰𝗲 𝗺𝗲𝘁𝗮𝗱𝗮𝘁𝗮 for temporary credentials and rotates them on its own. There's never a key written down anywhere.
And that's the good part 🔥
🔐 Zero secrets in the .env — if someone gets into the server, there's nothing to steal
🔁 Credentials rotate themselves, without me touching anything
🎯 The role carries only the exact permissions that service needs — 𝗹𝗲𝗮𝘀𝘁 𝗽𝗿𝗶𝘃𝗶𝗹𝗲𝗴𝗲 for real, not in theory
Defining AWS keys inside AWS is solving by hand something the platform already solves for you 💪
Champion, does your service on AWS still connect with keys in environment variables, or have you already attached a role? 🤔
Keep flying, Champions! ✈️