Managing EC2 access keys and X.509 certificates can become challenging when you start to deal with large numbers of instances. Do any EC2 users here have good policies and/or tools for:
- rotating EC2 access keys and X.509 certificates
- preventing copies of keys / certs from proliferating onto instances and AMIs
- keeping the keys in a centralized location with the appropriate access ?
I created a script to manage multiple AWS accounts (tested on Mac and Linux): https://github.com/thalweg/aws-account