#key-management

Wiki 2

  • Ephemeral Credentials Short-lived credentials (≤1 day) where rotation is structural rather than scheduled — minted per session, expire on their own
  • You Don't Want Long-Lived Keys Ludwig's case for ephemeral credentials over rotation, with EC2 Instance Connect, PyPI Trusted Publishers, and SSO as patterns