Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “admission control”

10 publications
Technical guideSource-based analysis

Plan the move from ingress-nginx to Gateway API

Ingress-nginx is archived and will not be patched again. Contain the old controller, inventory the behaviors your clients depend on, and cut over to Gateway API with evidence and a rollback path.

Workload security · Kubernetes / Google Cloud / AWS / Azure · By Cloud Security Desk
Technical guideSource-based analysis

Plan for the backlog that follows a regional cloud outage

AWS fixed the DNS fault behind its October 2025 us-east-1 outage within three hours, yet recovery ran into the afternoon. Design retries, queues and capacity automation for that second phase.

Resilience · Amazon Web Services · By Cloud Security Desk
Technical guideSource-based analysis

Count tokens before sending a prompt to Amazon Bedrock

Count a Bedrock prompt for the chosen model, check endpoint support, distinguish context and output limits, and verify usage without logging prompts.

AI systems · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Isolate document parsing before RAG ingestion

Give document parsing a bounded worker, then admit its extracted content separately before embedding or indexing.

AI systems · Apache Tika / Kubernetes / gVisor · By Cloud Security Desk
Technical guideSource-based analysis

Give Kubernetes admission webhooks an explicit failure contract

Treat an admission webhook as a control-plane dependency with explicit behavior for denial, call failure, mutation and the changes needed to repair it.

Workload security · Kubernetes · By Cloud Security Desk
Technical guideSource-based analysis

Choosing isolation for a Kubernetes tenant

A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.

Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security Desk
Technical guideSource-based analysis

Where fine tuning data needs a trust boundary

A training dataset can preserve its checksum and still teach the wrong behavior. Admission controls need to separate origin, transformation, approved use and the model change they produce.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Error budgets for controlled service degradation

Protect essential work under load while counting rejected and degraded requests against the service promise that users were actually given.

Resilience · Google / Envoy · By Cloud Security Desk
Research noteSource-based analysis

Stop retries from amplifying an outage

Count attempts across the complete request path, give retries a finite owner and budget, and define how repeated intent avoids duplicate side effects.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Verify container provenance before admitting a pinned image

Use the digest to identify the artifact, then check who signed it, which builder produced it, and which evidence survived promotion into the deployment registry.

Workload security · Kubernetes / Docker / Sigstore · By Cloud Security Desk