Literally every single "security" framework uses God-mode long-lived tokens for non-human identities.
(Except for SPIFFE, but that's a niche thing and used only for Kubernetes bullshit.)
The whole field of "security" is a farce staffed by clowns.
The only special permission that services (actually, the AWS accounts that they use) inside the AWS have is access to "service principals". The service roles inside customer accounts then use them to grant access.
AWS IAM is painful, but it shows that you can design a secure permission system.
You get to see that even with the regular public AWS/EC2. Instance roles are managed externally from the customers' points of view.
So, ultimately "keys to the castle" aka a long password?
But ultimately, any realistic design will eventually have systems that have to be trusted. It's just a question of isolating them.