Amazon Web Services
You create an IAM role in your account that trusts SKE only when a unique external ID is presented. SKE receives short-lived credentials from AWS STS. No access keys are exchanged.
{
"Effect": "Allow",
"Principal": { "AWS": "arn:aws:iam::<ske-account>:root" },
"Action": "sts:AssumeRole",
"Condition": {
"StringEquals": { "sts:ExternalId": "<your-external-id>" }
}
}To revoke access, delete the role or remove its trust statement.