- Organisation
- Government Digital Service, United Kingdom
- Predecessor
- service access using IAM users and long-lived access keys
- Destination
- IAM roles and Kubernetes pod identities where candidate services can adopt them
- Workload
- AWS IAM roles and Kubernetes pod identities
- Stage
- accepted decision
Verified platform change
GOV.UK accepted an architecture decision to retire IAM users and long-lived access keys as candidate services are identified and can move to roles or pod identities.
Transition
From: service access using IAM users and long-lived access keys
To: IAM roles and Kubernetes pod identities where candidate services can adopt them
Known unknowns
Accepted decision status is preserved. The source does not establish completed estate-wide retirement or an unconditional migration of every service.
Official sources
Updates
Source rechecked on 5 September 2026. The first-party GOV.UK evidence has not materially changed; Accepted decision status and conditional migration remain supported without an estate-wide completion claim.