Given the limitation of the access key that it doesn't require a passphrase and cannot be associated with an account. It can be the case that one still have the read access of the private repository after his/her account revoked. Or worse, the leaked private key can causes an unauthorised third party gains access to the private repository.
Is there a way to
- rotate the access key
- remind the admin/ creator of the key regarding the expiration of the key
- control the creation of the key on an approval basis
?