An EC2 instance can get there metadata from an HTTP GET up to "169.254.169.254". If an instance has correctly assigned the IAM role, it can automatically "discover" its API credentials.
But they are temporary and should be updated periodically. Boto does this automatically if they expire in less than 5 minutes after verification.
Sometimes the update can be very long (a couple of minutes). Before moving on to this system, is there a period during which both current and βfutureβ credentials can be used, or are current credentials invalid when I request new ones?
source share