Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “managed identity”

14 publications
Technical guideSource-based analysis

Give Kubernetes pods cloud credentials without static keys

EKS Pod Identity, IRSA, AKS Workload ID and Workload Identity Federation for GKE all swap a projected token for short-lived credentials. What leaks if you stop there is the node's own identity.

Identity & access · Amazon Web Services / Microsoft Azure / Google Cloud / Kubernetes · By Cloud Security Desk
Technical guideSource-based analysis

Prepare Azure automation for mandatory MFA on resource management

Azure now requires MFA for user accounts that write through Resource Manager. Find the scripts and pipelines that still sign in as people and move each one to a managed identity or federated credential.

Identity & access · Microsoft Azure / Microsoft Entra / GitHub / Azure DevOps / HashiCorp Terraform · By Cloud Security Desk
Technical guideSource-based analysis

Build an inventory of non-human identities across cloud accounts

Find every service account, service principal, role and key across AWS, Entra and Google Cloud, then record the owner, credential type, privilege and last use that turn a list into decisions.

Identity & access · Amazon Web Services / Microsoft Entra / Microsoft Azure / Google Cloud / OWASP · By Cloud Security Desk
Technical guideSource-based analysis

Encrypt Kubernetes Secrets at rest with a KMS v2 provider

KMS v2 keeps etcd copies and backups unreadable without an external key, but it does not stop API readers. Configure it, compare what EKS, AKS and GKE already do, and finish key rotations with a rewrite.

Workload security · Kubernetes / Amazon EKS / AWS KMS / Azure Kubernetes Service / Azure Key Vault / Google Kubernetes Engine / Cloud KMS · By Cloud Security Desk
Technical guideSource-based analysis

Let AWS workloads call external services with IAM-issued tokens

IAM outbound identity federation lets an AWS role trade its credentials for a signed JWT instead of storing a vendor API key. AWS controls issuance; the receiving service's claim checks decide what the token is worth.

Identity & access · Amazon Web Services / AWS IAM / AWS STS / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Run code written by AI agents inside a disposable sandbox

Treat agent-generated code as untrusted input. Pick a microVM or user-space kernel boundary, keep egress and credentials off by default, and destroy the session when the user or conversation ends.

AI systems · Amazon Web Services / Microsoft Azure / Google Cloud / Firecracker / gVisor / OWASP · By Cloud Security Desk
Technical guideSource-based analysis

Give AI agents their own identity instead of borrowed user tokens

An agent that replays a user's token is invisible in logs and cannot be revoked on its own. Give it a principal, delegate narrowly through token exchange, and use what Entra, AgentCore and Google now provide.

Identity & access · Microsoft Entra / Amazon Web Services / Google Cloud / IETF / Model Context Protocol · By Cloud Security Desk
Technical guideSource-based analysis

Get an alert when Google Cloud project access changes

Build a Google Cloud log-based alert for project IAM changes, verify the filter and notification channel, and understand incident limits.

Detection & response · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Give Azure readers access to one resource group

Assign Reader without granting write access or assuming it grants data access.

Identity & access · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Read an Azure Key Vault secret from a VM without a password

Set up one system-assigned VM identity and a vault-scoped secret permission.

Identity & access · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Connect to Azure OpenAI without an API key

Prove Entra-based inference with a scoped runtime identity before disabling local authentication.

AI systems · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Recover a deleted Azure Key Vault secret

Distinguish secret recovery from vault recovery and verify versioned application references.

Resilience · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Prove Azure Storage private access from DNS to authorization

Check the exact storage subresource, resolve its normal hostname from the application, and test public access and data permissions as separate boundaries.

Workload security · Azure · By Cloud Security Desk
Research reportDesk publication

Qwen3.8-Flash-Next and GLM-5.3-Flash share a 3:1 long-context pattern

Both models replace most conventional attention layers with recurrent state and reserve sparse attention for periodic retrieval. Their differences lie in where they place capacity, how much neural computation they activate, and what their serving stacks must keep trustworthy.

AI systems · Resilience · By Umair Akbar and Ahmed Elshekh