Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “managed identity”
14 publicationsGive Kubernetes pods cloud credentials without static keys
EKS Pod Identity, IRSA, AKS Workload ID and Workload Identity Federation for GKE all swap a projected token for short-lived credentials. What leaks if you stop there is the node's own identity.
Identity & access · Amazon Web Services / Microsoft Azure / Google Cloud / Kubernetes · By Cloud Security DeskPrepare Azure automation for mandatory MFA on resource management
Azure now requires MFA for user accounts that write through Resource Manager. Find the scripts and pipelines that still sign in as people and move each one to a managed identity or federated credential.
Identity & access · Microsoft Azure / Microsoft Entra / GitHub / Azure DevOps / HashiCorp Terraform · By Cloud Security DeskBuild an inventory of non-human identities across cloud accounts
Find every service account, service principal, role and key across AWS, Entra and Google Cloud, then record the owner, credential type, privilege and last use that turn a list into decisions.
Identity & access · Amazon Web Services / Microsoft Entra / Microsoft Azure / Google Cloud / OWASP · By Cloud Security DeskEncrypt Kubernetes Secrets at rest with a KMS v2 provider
KMS v2 keeps etcd copies and backups unreadable without an external key, but it does not stop API readers. Configure it, compare what EKS, AKS and GKE already do, and finish key rotations with a rewrite.
Workload security · Kubernetes / Amazon EKS / AWS KMS / Azure Kubernetes Service / Azure Key Vault / Google Kubernetes Engine / Cloud KMS · By Cloud Security DeskLet AWS workloads call external services with IAM-issued tokens
IAM outbound identity federation lets an AWS role trade its credentials for a signed JWT instead of storing a vendor API key. AWS controls issuance; the receiving service's claim checks decide what the token is worth.
Identity & access · Amazon Web Services / AWS IAM / AWS STS / Microsoft Entra · By Cloud Security DeskRun code written by AI agents inside a disposable sandbox
Treat agent-generated code as untrusted input. Pick a microVM or user-space kernel boundary, keep egress and credentials off by default, and destroy the session when the user or conversation ends.
AI systems · Amazon Web Services / Microsoft Azure / Google Cloud / Firecracker / gVisor / OWASP · By Cloud Security DeskGive AI agents their own identity instead of borrowed user tokens
An agent that replays a user's token is invisible in logs and cannot be revoked on its own. Give it a principal, delegate narrowly through token exchange, and use what Entra, AgentCore and Google now provide.
Identity & access · Microsoft Entra / Amazon Web Services / Google Cloud / IETF / Model Context Protocol · By Cloud Security DeskGet an alert when Google Cloud project access changes
Build a Google Cloud log-based alert for project IAM changes, verify the filter and notification channel, and understand incident limits.
Detection & response · Google Cloud · By Cloud Security DeskGive Azure readers access to one resource group
Assign Reader without granting write access or assuming it grants data access.
Identity & access · Azure · By Cloud Security DeskRead an Azure Key Vault secret from a VM without a password
Set up one system-assigned VM identity and a vault-scoped secret permission.
Identity & access · Azure · By Cloud Security DeskConnect to Azure OpenAI without an API key
Prove Entra-based inference with a scoped runtime identity before disabling local authentication.
AI systems · Azure · By Cloud Security DeskRecover a deleted Azure Key Vault secret
Distinguish secret recovery from vault recovery and verify versioned application references.
Resilience · Azure · By Cloud Security DeskProve Azure Storage private access from DNS to authorization
Check the exact storage subresource, resolve its normal hostname from the application, and test public access and data permissions as separate boundaries.
Workload security · Azure · By Cloud Security DeskQwen3.8-Flash-Next and GLM-5.3-Flash share a 3:1 long-context pattern
Both models replace most conventional attention layers with recurrent state and reserve sparse attention for periodic retrieval. Their differences lie in where they place capacity, how much neural computation they activate, and what their serving stacks must keep trustworthy.
AI systems · Resilience · By Umair Akbar and Ahmed Elshekh