TL;DR: Add MFA to AWS root user. If you don't have MFA with root AND your email server of root email is hosted in same AWS account, it gets tricky to recover.
Sidenote, I was shocked to see "There was an AWS keypair saved in the CI secrets that hadn't been used since 2022."
Sidenote, I was shocked to see "There was an AWS keypair saved in the CI secrets that hadn't been used since 2022."