07 · Security · epic
Removing long-lived credentials
Static IAM access keys replaced with IAM roles across the platform's services, and Redis moved to TLS with a live dual-write cutover — the security debt that is easy to defer forever.
- 0
- static IAM keys left in Launch services
- 0
- downtime for the Redis cutover
The problem
The deployment agent, management service and background-jobs service authenticated to AWS and Fastly with long-lived access keys. Redis was in plaintext. Both are the kind of finding that is cheap to fix on day one and expensive to fix once an auditor is in the room.
What I did
I led the epic to remove the IAM key dependency, moving the services onto IAM roles for S3, Lambda, ECR and SQS access. The same argument applied to Redis, which I ran as a live cutover rather than a maintenance window: dual writes across old and new instances, a feature-flagged switchover, health checks on either side, and consistency checks to prove nothing was lost in between.
Around them: disabling GraphQL introspection on the public surface, stripping port numbers from remote addresses before audit logging, closing a VAPT finding on insecure identifier generation, verifying the impact of RBAC enablement, and the MongoDB 7.0 upgrade prerequisites.