ECS Credential Chain
IMDSv2 (Instance Metadata Service v2) — token-based:
Container SDK (aws-sdk-rust)
→ ECS credential endpoint: 169.254.170.2/v2/credentials/{id}
→ ECS agent
→ STS AssumeRole (task role)
→ Returns temporary credentials (AccessKey, SecretKey, SessionToken, Expiry)
The SDK refreshes credentials automatically ~5 minutes before expiry.
No credential files, no environment variables required.