only use s3.access_key and s3.secret_key properties if defined, otherwise let aws client do default lookups (to allow using iam roles for ecs tasks)