AWS wants long-term IAM access keys gone. In their place: temporary creds via IAM roles, IAM Identity Center, CloudShell, and OIDC integrations.
The push covers everything—CLI tools, local dev, compute, CI/CD, even old-school on-prem. The message is clear: rotate automatically, grant minimally, and stop treating static keys like they're safe.
Big picture: Shifting the default to short-lived creds and federated identity is not just a best practice—it’s the new norm.