Skip to main content
Valkyrie uses your AWS credentials for artifact storage, logs, sandbox-provider secrets, and optional post-run integrations. In managed AWS execution, local credentials are used only by local operations such as uploading an agent. Scope local permissions to the configured S3 bucket. For access-key execution, also scope permissions to the CloudWatch log groups, Lambda functions, and Secrets Manager secrets that the installation uses.
In access-key execution, the SDK and CLI send AWS credentials to the configured tracker through X-Harness-* headers. Connect only to a trusted tracker and use HTTPS outside local development.