Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “workload identity”
16 publicationsRun AI coding agents in GitHub Actions without exposing secrets
Treat the agent job as an untrusted-input processor. Follow the outside text from the trigger that admits it to the credentials it can reach, then split reading from writing so a successful injection reaches nothing worth stealing.
AI systems · GitHub / Anthropic / Google / Microsoft · By Cloud Security DeskKnow what service mesh mTLS proves about the caller
A mesh handshake proves that a peer held a key for a namespace and service account. It says nothing about the user or the operation, and permissive defaults, probes and waypoints open paths around it.
Workload security · Istio / Linkerd / Kubernetes / Google Cloud / Microsoft Azure / Amazon Web Services · By Cloud Security DeskCompare just-in-time privileged access in AWS, Azure and Google Cloud
Entra PIM and Google Cloud PAM make roles temporary natively, while AWS relies on TEAM or partner tools. All three end elevation by removing an assignment, and sessions, caches and minted tokens can keep running.
Identity & access · Amazon Web Services / Microsoft Azure / Microsoft Entra / Google Cloud · By Cloud Security DeskMap the OWASP Top 10 for Agentic Applications to cloud controls
Each OWASP agentic risk mapped to the controls AWS, Microsoft and Google document for their agent platforms, with a plain account of which risks no infrastructure setting can close.
AI systems · OWASP GenAI Security Project / Amazon Web Services / Microsoft Azure / Google Cloud · By Cloud Security DeskGive Kubernetes pods cloud credentials without static keys
EKS Pod Identity, IRSA, AKS Workload ID and Workload Identity Federation for GKE all swap a projected token for short-lived credentials. What leaks if you stop there is the node's own identity.
Identity & access · Amazon Web Services / Microsoft Azure / Google Cloud / Kubernetes · By Cloud Security DeskPrepare Azure automation for mandatory MFA on resource management
Azure now requires MFA for user accounts that write through Resource Manager. Find the scripts and pipelines that still sign in as people and move each one to a managed identity or federated credential.
Identity & access · Microsoft Azure / Microsoft Entra / GitHub / Azure DevOps / HashiCorp Terraform · By Cloud Security DeskLet AWS workloads call external services with IAM-issued tokens
IAM outbound identity federation lets an AWS role trade its credentials for a signed JWT instead of storing a vendor API key. AWS controls issuance; the receiving service's claim checks decide what the token is worth.
Identity & access · Amazon Web Services / AWS IAM / AWS STS / Microsoft Entra · By Cloud Security DeskLimit what Google Cloud principals can reach with principal access boundaries
Allow and deny policies sit on resources. A principal access boundary travels with the identity and limits which projects, folders and organizations it may touch, even where someone else granted it a role.
Identity & access · Google Cloud · By Cloud Security DeskGive AI agents their own identity instead of borrowed user tokens
An agent that replays a user's token is invisible in logs and cannot be revoked on its own. Give it a principal, delegate narrowly through token exchange, and use what Entra, AgentCore and Google now provide.
Identity & access · Microsoft Entra / Amazon Web Services / Google Cloud / IETF / Model Context Protocol · By Cloud Security DeskProtect and recover your AWS root account
Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.
Identity & access · AWS · By Cloud Security DeskGive Google Cloud teams access through IAM groups
Give Google Cloud teams IAM access through owned groups, choose a sensible resource scope, and verify migration and removal with practical checks.
Identity & access · Google Cloud · By Cloud Security DeskConnect to a Google Cloud VM with IAP and OS Login
Connect to a Linux VM through IAP and OS Login, check each permission and network layer, and remove old SSH paths with a tested recovery plan.
Identity & access · Google Cloud · By Cloud Security DeskWorkload federation across clouds needs separate trust decisions
Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.
Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security DeskShort SSH certificates still need explicit access boundaries
An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.
Identity & access · OpenSSH · By Cloud Security DeskQwen3.8-Flash-Next and GLM-5.3-Flash share a 3:1 long-context pattern
Both models replace most conventional attention layers with recurrent state and reserve sparse attention for periodic retrieval. Their differences lie in where they place capacity, how much neural computation they activate, and what their serving stacks must keep trustworthy.
AI systems · Resilience · By Umair Akbar and Ahmed ElshekhWhat changes when static keys disappear
Workload identity removes a secret, but it also moves trust into issuers, claims, audiences, and runtime attachment points.
Identity & access · Workload security · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed Elshekh