Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “rbac”

8 publications
Technical guideSource-based analysis

Give Azure readers access to one resource group

Assign Reader without granting write access or assuming it grants data access.

Identity & access · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Read an Azure Key Vault secret from a VM without a password

Set up one system-assigned VM identity and a vault-scoped secret permission.

Identity & access · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Get an Azure alert when a role assignment changes

Detect successful RBAC changes and test alert delivery without expanding a production role.

Detection & response · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Recover a deleted Azure Key Vault secret

Distinguish secret recovery from vault recovery and verify versioned application references.

Resilience · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Keep Kubernetes audit records useful without logging secrets

Design a question-led Kubernetes audit policy with explicit body limits, rule precedence, lifecycle stages and provider-specific acceptance checks.

Detection & response · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Give Kubernetes admission webhooks an explicit failure contract

Treat an admission webhook as a control-plane dependency with explicit behavior for denial, call failure, mutation and the changes needed to repair it.

Workload security · Kubernetes · By Cloud Security Desk
Technical guideSource-based analysis

Choosing isolation for a Kubernetes tenant

A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.

Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security Desk
Technical guideSource-based analysis

Roll out Kubernetes Pod Security Admission without surprises

Stage namespace enforcement around the Pods a controller will create next, with explicit policy versions, runtime checks, and narrowly owned exceptions.

Workload security · Kubernetes · By Cloud Security Desk