Bắt đầu ngayBắt đầu miễn phí

Swap a stored key for a role

The report-archiver function works. It also carries a long-lived access key in its environment variables, created once for one script and never touched since.

Nothing here needs to be built. The function already has an execution role, and that role can read the bucket. The key is the problem: it sits at the top of the credential provider chain, ahead of anything the role supplies, so while it is there the role is ignored.

Use the Credential chain repair app to delete the stored key, then invoke the function and read the credential it reports.

Which statement matches what you saw?

Bài tập này là một phần của khóa học

Using AWS Security for Developers

Xem khóa học

Bài tập tương tác thực hành

Biến lý thuyết thành hành động với một trong các bài tập tương tác của chúng tôi

Bắt đầu bài tập