Question / Description: handing out long lived AWS S3 credentials to the retool (which we can be grabbed by any org user with a very simply created AI script – we’ve demo’d it) is unsafe.
Is there another way to authenticate Retool so it only gets short lived S3 creds and to ensure they can not be dumped from Environment?
Have you tried using User Level Permissions to control which users can use AWS S3 Resources and Queries?
If you need to use S3 creds with shorter lived permissions, I believe you would need to generate those on the AWS side and then add them to a resource.