Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “role”

84 publications
Technical guideSource-based analysis

Keep Kubernetes audit records useful without logging secrets

Design a question-led Kubernetes audit policy with explicit body limits, rule precedence, lifecycle stages and provider-specific acceptance checks.

Detection & response · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Keep Terraform plans and state inside the change boundary

Protect Terraform plans and state as sensitive artifacts, and bind production approval to the specific plan, dependencies, workspace and apply identity that will be used.

Workload security · HashiCorp / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Bind confidential GPU inference to a verified key release

Require composite evidence, owner policy and verified recipient binding before confidential inference receives protected key material.

AI systems · NVIDIA / Azure · By Cloud Security Desk
Technical guideSource-based analysis

Make PostgreSQL point in time recovery reproducible

Build a version-aware recovery chain from protected base backups and WAL through timeline selection, isolated replay and application acceptance.

Resilience · PostgreSQL · By Cloud Security Desk
Technical guideSource-based analysis

Choose who can share an inference prefix cache

Choose the principals allowed to share prefix state, then carry that decision through request routing, offload, transfer and restore.

AI systems · vLLM / NVIDIA · By Cloud Security Desk
Technical guideSource-based analysis

Set explicit trust boundaries for Entra partner access

Accepting another tenant’s authentication claims is a specific trust decision, not blanket approval of its users, devices or access to your applications.

Identity & access · Microsoft · By Cloud Security Desk
Research noteSource-based analysis

Embeddings still need a sensitive data boundary

Treat vector access as a derived-data release decision, with separate permissions for retrieval, debugging and bulk export.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Bind OAuth tokens to the client that presents them

DPoP can make possession of an access token insufficient for use, provided the issuer, client and resource server implement the same proof and key-binding contract.

Identity & access · IETF / Google · By Cloud Security Desk
Technical guideSource-based analysis

Catch late security events without replaying every alert

Separate event time, ingestion time and execution health so delayed records can be evaluated without turning every broader lookback into a replay.

Detection & response · Microsoft Sentinel / Microsoft Defender · By Cloud Security Desk
Technical guideSource-based analysis

Keep build credentials out of the image and its evidence

A temporary BuildKit secret mount controls credential delivery, not everything a build command can do with the credential or leave in its outputs.

Workload security · Docker / GitHub · By Cloud Security Desk
Technical guideSource-based analysis

Keep S3 presigned access inside an explicit delegation window

Treat an S3 presigned URL as a reusable delegation whose usable lifetime depends on the signer, the request and the policies that still apply.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Find the Purview audit history your investigation can still retrieve

Resolve Purview audit availability at the record level by separating actor eligibility, retention policy, collection status, investigator scope and export limits.

Detection & response · Microsoft Purview / Microsoft 365 · By Cloud Security Desk
Technical guideSource-based analysis

Design RDS IAM authentication around the connection pool

Generate IAM database tokens for the physical connections that need them, and keep token validity separate from the lifetime of an already-established SQL session.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Separate stopping a fault experiment from recovering the service

Plan AWS FIS around separate evidence for stopping execution, removing fault effects and accepting the recovered application.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Prove Identity Center permission changes reached every account

A permission-set change is complete only when the intended accounts, account-local policies, provisioning results and assignments have converged.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Finish S3 multipart uploads with verifiable object integrity

Keep an owned part manifest and verify the complete object result, because successful part transfers and an initial HTTP 200 are not sufficient completion evidence.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Keep GitHub audit streaming continuous across maintenance

Plan audit-stream maintenance around native history, pause buffers, receiver acceptance and duplicate-aware evidence receipts.

Detection & response · GitHub / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Give Kubernetes admission webhooks an explicit failure contract

Treat an admission webhook as a control-plane dependency with explicit behavior for denial, call failure, mutation and the changes needed to repair it.

Workload security · Kubernetes · By Cloud Security Desk
Technical guideSource-based analysis

Passkey deployment needs a recovery design

A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.

Identity & access · NIST / FIDO Alliance / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

A defensible cloud patch queue starts with exploitation evidence

Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.

Detection & response · CISA / NIST / FIRST · By Cloud Security Desk
Technical guideSource-based analysis

Choosing isolation for a Kubernetes tenant

A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.

Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security Desk
Technical guideSource-based analysis

Security evidence for AI release decisions

A release approval should identify the changed application, the claims its tests support and the evidence that expires when a model, prompt, data path or runtime changes.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Recovery objectives that match the cloud service

Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.

Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security Desk