#key-management
Wiki 2
- Ephemeral Credentials Short-lived credentials (≤1 day) where rotation is structural rather than scheduled — minted per session, expire on their own
- You Don't Want Long-Lived Keys Ludwig's case for ephemeral credentials over rotation, with EC2 Instance Connect, PyPI Trusted Publishers, and SSO as patterns