Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “reader”

60 publications
Technical guideSource-based analysis

Recover a deleted Azure Key Vault secret

Distinguish secret recovery from vault recovery and verify versioned application references.

Resilience · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Keep Kubernetes audit records useful without logging secrets

Design a question-led Kubernetes audit policy with explicit body limits, rule precedence, lifecycle stages and provider-specific acceptance checks.

Detection & response · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Keep Terraform plans and state inside the change boundary

Protect Terraform plans and state as sensitive artifacts, and bind production approval to the specific plan, dependencies, workspace and apply identity that will be used.

Workload security · HashiCorp / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Make PostgreSQL point in time recovery reproducible

Build a version-aware recovery chain from protected base backups and WAL through timeline selection, isolated replay and application acceptance.

Resilience · PostgreSQL · By Cloud Security Desk
Technical guideSource-based analysis

Choose who can share an inference prefix cache

Choose the principals allowed to share prefix state, then carry that decision through request routing, offload, transfer and restore.

AI systems · vLLM / NVIDIA · By Cloud Security Desk
Technical guideSource-based analysis

Set explicit trust boundaries for Entra partner access

Accepting another tenant’s authentication claims is a specific trust decision, not blanket approval of its users, devices or access to your applications.

Identity & access · Microsoft · By Cloud Security Desk
Technical guideSource-based analysis

Read VPC Flow Logs without overclaiming network evidence

Interpret aggregation, address translation, skipped records and delivery clocks before turning a VPC flow record into an incident conclusion.

Detection & response · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Plan Kubernetes drains around the disruption budget

Review selector scope, current status, unhealthy Pod handling and replacement capacity before treating a blocked drain as a reason to bypass availability controls.

Resilience · Kubernetes · By Cloud Security Desk
Technical guideSource-based analysis

Catch late security events without replaying every alert

Separate event time, ingestion time and execution health so delayed records can be evaluated without turning every broader lookback into a replay.

Detection & response · Microsoft Sentinel / Microsoft Defender · By Cloud Security Desk
Technical guideSource-based analysis

Keep build credentials out of the image and its evidence

A temporary BuildKit secret mount controls credential delivery, not everything a build command can do with the credential or leave in its outputs.

Workload security · Docker / GitHub · By Cloud Security Desk
Technical guideSource-based analysis

Give persistent agent memory an admission boundary

Separate conversational candidates from admitted memory, preserve their permitted audience, and make derived summaries repairable.

AI systems · LangChain · By Cloud Security Desk
Technical guideSource-based analysis

Diagnose NAT gateway port exhaustion before adding capacity

Match allocation errors to destination tuples and gateway mode before changing connection pools, addresses or routes.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Isolate document parsing before RAG ingestion

Give document parsing a bounded worker, then admit its extracted content separately before embedding or indexing.

AI systems · Apache Tika / Kubernetes / gVisor · By Cloud Security Desk
Technical guideSource-based analysis

Separate stopping a fault experiment from recovering the service

Plan AWS FIS around separate evidence for stopping execution, removing fault effects and accepting the recovered application.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Investigate denied access at an AWS VPC endpoint

Use CloudTrail network activity evidence to distinguish endpoint-policy violations from routing failures and downstream authorization problems.

Detection & response · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Find the EBS limit behind a slow database

Separate volume operation rate, byte rate, instance bandwidth and snapshot initialization before changing storage for a slow database.

Resilience · AWS · By Cloud Security Desk
Research reportSource-based analysis

Find the shared dependencies behind a cloud outage

Use the June 2025 Google Cloud and Cloudflare reports to review shared runtime, control, identity and recovery dependencies without turning one outage into a provider ranking.

Resilience · Google Cloud / Cloudflare / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Passkey deployment needs a recovery design

A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.

Identity & access · NIST / FIDO Alliance / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Choosing isolation for a Kubernetes tenant

A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.

Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security Desk
Technical guideSource-based analysis

Security evidence for AI release decisions

A release approval should identify the changed application, the claims its tests support and the evidence that expires when a model, prompt, data path or runtime changes.

AI systems · By Cloud Security Desk
Research noteSource-based analysis

What coding benchmarks can prove about a model

A coding benchmark result depends on its tasks, harness and tests. A reproducible count of SWE-bench Verified shows why the denominator belongs beside every comparison.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

A controlled return from the SQS dead letter queue

Repair the failure, check consumer compatibility and return failed work with a bounded rate, observable stop conditions and business reconciliation.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Testing Sigma detections before a backend change

Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.

Detection & response · SigmaHQ · By Cloud Security Desk
Technical guideSource-based analysis

Certificate renewal under shorter validity limits

Use the public TLS issuance schedule to review authorization, renewal, deployment and independent verification of the certificate an endpoint actually serves.

Resilience · CA/Browser Forum / Let's Encrypt / AWS · By Cloud Security Desk