You can add many layers of indirection, but unless you're actually authenticating that a system service is using the credentials (and not, say, a user or a script) then it boils down to a long-lived token at the end.
You get to see that even with the regular public AWS/EC2. Instance roles are managed externally from the customers' points of view.
So, ultimately "keys to the castle" aka a long password?
But ultimately, any realistic design will eventually have systems that have to be trusted. It's just a question of isolating them.