Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “rate”

125 publications
Technical guideSource-based analysis

Design RDS IAM authentication around the connection pool

Generate IAM database tokens for the physical connections that need them, and keep token validity separate from the lifetime of an already-established SQL session.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Isolate document parsing before RAG ingestion

Give document parsing a bounded worker, then admit its extracted content separately before embedding or indexing.

AI systems · Apache Tika / Kubernetes / gVisor · By Cloud Security Desk
Technical guideSource-based analysis

Separate stopping a fault experiment from recovering the service

Plan AWS FIS around separate evidence for stopping execution, removing fault effects and accepting the recovered application.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Prove Identity Center permission changes reached every account

A permission-set change is complete only when the intended accounts, account-local policies, provisioning results and assignments have converged.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Investigate denied access at an AWS VPC endpoint

Use CloudTrail network activity evidence to distinguish endpoint-policy violations from routing failures and downstream authorization problems.

Detection & response · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Finish S3 multipart uploads with verifiable object integrity

Keep an owned part manifest and verify the complete object result, because successful part transfers and an initial HTTP 200 are not sufficient completion evidence.

Workload security · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Decide what happens when an AI guardrail fails

Distinguish denial, incomplete checks and late results, then decide what may cross each protected release point.

AI systems · Algolia / TrueFoundry / Conductor · By Cloud Security Desk
Technical guideSource-based analysis

Find the EBS limit behind a slow database

Separate volume operation rate, byte rate, instance bandwidth and snapshot initialization before changing storage for a slow database.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Restrict device code sign-in without breaking approved clients

Restrict device-code authentication through an explicit client and resource policy, and test the tracked sessions that can outlive the initial browser approval.

Identity & access · Microsoft / IETF · By Cloud Security Desk
Technical guideSource-based analysis

Keep GitHub audit streaming continuous across maintenance

Plan audit-stream maintenance around native history, pause buffers, receiver acceptance and duplicate-aware evidence receipts.

Detection & response · GitHub / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Give Kubernetes admission webhooks an explicit failure contract

Treat an admission webhook as a control-plane dependency with explicit behavior for denial, call failure, mutation and the changes needed to repair it.

Workload security · Kubernetes · By Cloud Security Desk
Research reportSource-based analysis

Find the shared dependencies behind a cloud outage

Use the June 2025 Google Cloud and Cloudflare reports to review shared runtime, control, identity and recovery dependencies without turning one outage into a provider ranking.

Resilience · Google Cloud / Cloudflare / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Passkey deployment needs a recovery design

A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.

Identity & access · NIST / FIDO Alliance / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

A defensible cloud patch queue starts with exploitation evidence

Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.

Detection & response · CISA / NIST / FIRST · By Cloud Security Desk
Technical guideSource-based analysis

Choosing isolation for a Kubernetes tenant

A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.

Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security Desk
Technical guideSource-based analysis

Security evidence for AI release decisions

A release approval should identify the changed application, the claims its tests support and the evidence that expires when a model, prompt, data path or runtime changes.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Recovery objectives that match the cloud service

Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.

Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security Desk
Technical guideSource-based analysis

Entra emergency access that survives normal sign-in failure

A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.

Identity & access · Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

What cloud snapshots cannot preserve

Separate live execution, persisted disk and provider records before an authorized containment decision destroys evidence that a snapshot cannot recover.

Detection & response · AWS / NIST · By Cloud Security Desk
Technical guideSource-based analysis

Make secret rotation reach every running application

Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.

Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Research noteSource-based analysis

What coding benchmarks can prove about a model

A coding benchmark result depends on its tasks, harness and tests. A reproducible count of SWE-bench Verified shows why the denominator belongs beside every comparison.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

A controlled return from the SQS dead letter queue

Repair the failure, check consumer compatibility and return failed work with a bounded rate, observable stop conditions and business reconciliation.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Rotate Entra application certificates with proof of adoption

A renewed certificate can exist in Key Vault while a running client still uses the old key. Define the evidence that makes application rotation complete.

Identity & access · Microsoft Entra / Azure Key Vault · By Cloud Security Desk