TTokenTimerintokentimer.hashnode.dev·Sep 28 · 2 min readGitLab Deploy Token Metadata Belongs in a Reviewable InventoryA GitLab deploy token created without an expiry date stays valid until it is revoked. That can be intentional. It becomes a problem when the team cannot say which project still uses it, who owns it, o00
TTokenTimerintokentimer.hashnode.dev·Sep 6 · 8 min read768 Leaked AWS Keys Had Full Admin Access. Most Were Years OldAn AWS key can disappear from a public repository and still work in AWS. The credential still has an identity, a permission set, unknown copies, and possibly live dependencies. Removing that authentic00
TTokenTimerintokentimer.hashnode.dev·Aug 28 · 6 min readAWS Access Keys Don’t Expire: Govern the Exceptions, Not Just the Rotation DateAn AWS IAM user access key can remain valid long after the workload, integration, or person that needed it is gone. The credential does not know that a migration finished or a pipeline was replaced. U00