Deployment access key with production write access reported exposed in a public gist
- Why
- An access key granting write access to production deployment resources was reported exposed outside the organization
- What
- aws-access-key/AKIA…Q9LX (access key of machine user ci-deployer)
- Who
- Owner: Web platform team (declared by tag)
- Where
- Exposure reported through the ingestion API from a public gist · AWS account prod-core
- How
- Key created 412 days ago and never rotated; activity ingested after the exposure shows it still in use
- Blast radius
- Write on 14 resources · can assume the production deploy role · effective access, an upper bound
- Recommendation
- Revoke the key at AWS now, reissue as a short-lived role session scoped to the deploy job
- Action
- Propose revoke for second-person approval · notify owner · quarantine the identity in the platform
- Evidence
- Exposure record · access key metadata · ingested activity (30 days)