Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “instance metadata”
4 publicationsTechnical guideSource-based analysisTechnical guideSource-based analysisTechnical guideSource-based analysisTechnical guideSource-based analysis
Give Kubernetes pods cloud credentials without static keys
EKS Pod Identity, IRSA, AKS Workload ID and Workload Identity Federation for GKE all swap a projected token for short-lived credentials. What leaks if you stop there is the node's own identity.
Identity & access · Amazon Web Services / Microsoft Azure / Google Cloud / Kubernetes · By Cloud Security DeskConnect to a Google Cloud VM with IAP and OS Login
Connect to a Linux VM through IAP and OS Login, check each permission and network layer, and remove old SSH paths with a tested recovery plan.
Identity & access · Google Cloud · By Cloud Security DeskRead VPC Flow Logs without overclaiming network evidence
Interpret aggregation, address translation, skipped records and delivery clocks before turning a VPC flow record into an incident conclusion.
Detection & response · AWS · By Cloud Security DeskRequire EC2 IMDSv2 without breaking container credentials
Separate metadata token requirements from response hop limits, then verify both existing instances and future launches before declaring the migration complete.
Workload security · AWS · By Cloud Security Desk