Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “workload identity”

16 publications
Technical guideSource-based analysis

Run AI coding agents in GitHub Actions without exposing secrets

Treat the agent job as an untrusted-input processor. Follow the outside text from the trigger that admits it to the credentials it can reach, then split reading from writing so a successful injection reaches nothing worth stealing.

AI systems · GitHub / Anthropic / Google / Microsoft · By Cloud Security Desk
Technical guideSource-based analysis

Know what service mesh mTLS proves about the caller

A mesh handshake proves that a peer held a key for a namespace and service account. It says nothing about the user or the operation, and permissive defaults, probes and waypoints open paths around it.

Workload security · Istio / Linkerd / Kubernetes / Google Cloud / Microsoft Azure / Amazon Web Services · By Cloud Security Desk
Technical guideSource-based analysis

Compare just-in-time privileged access in AWS, Azure and Google Cloud

Entra PIM and Google Cloud PAM make roles temporary natively, while AWS relies on TEAM or partner tools. All three end elevation by removing an assignment, and sessions, caches and minted tokens can keep running.

Identity & access · Amazon Web Services / Microsoft Azure / Microsoft Entra / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Map the OWASP Top 10 for Agentic Applications to cloud controls

Each OWASP agentic risk mapped to the controls AWS, Microsoft and Google document for their agent platforms, with a plain account of which risks no infrastructure setting can close.

AI systems · OWASP GenAI Security Project / Amazon Web Services / Microsoft Azure / Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Give Kubernetes pods cloud credentials without static keys

EKS Pod Identity, IRSA, AKS Workload ID and Workload Identity Federation for GKE all swap a projected token for short-lived credentials. What leaks if you stop there is the node's own identity.

Identity & access · Amazon Web Services / Microsoft Azure / Google Cloud / Kubernetes · By Cloud Security Desk
Technical guideSource-based analysis

Prepare Azure automation for mandatory MFA on resource management

Azure now requires MFA for user accounts that write through Resource Manager. Find the scripts and pipelines that still sign in as people and move each one to a managed identity or federated credential.

Identity & access · Microsoft Azure / Microsoft Entra / GitHub / Azure DevOps / HashiCorp Terraform · By Cloud Security Desk
Technical guideSource-based analysis

Let AWS workloads call external services with IAM-issued tokens

IAM outbound identity federation lets an AWS role trade its credentials for a signed JWT instead of storing a vendor API key. AWS controls issuance; the receiving service's claim checks decide what the token is worth.

Identity & access · Amazon Web Services / AWS IAM / AWS STS / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Limit what Google Cloud principals can reach with principal access boundaries

Allow and deny policies sit on resources. A principal access boundary travels with the identity and limits which projects, folders and organizations it may touch, even where someone else granted it a role.

Identity & access · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Give AI agents their own identity instead of borrowed user tokens

An agent that replays a user's token is invisible in logs and cannot be revoked on its own. Give it a principal, delegate narrowly through token exchange, and use what Entra, AgentCore and Google now provide.

Identity & access · Microsoft Entra / Amazon Web Services / Google Cloud / IETF / Model Context Protocol · By Cloud Security Desk
Technical guideSource-based analysis

Protect and recover your AWS root account

Protect AWS root access with MFA, current recovery contacts, separate daily administration, and a clear plan for Organizations member accounts.

Identity & access · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Give Google Cloud teams access through IAM groups

Give Google Cloud teams IAM access through owned groups, choose a sensible resource scope, and verify migration and removal with practical checks.

Identity & access · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Connect to a Google Cloud VM with IAP and OS Login

Connect to a Linux VM through IAP and OS Login, check each permission and network layer, and remove old SSH paths with a tested recovery plan.

Identity & access · Google Cloud · By Cloud Security Desk
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Short SSH certificates still need explicit access boundaries

An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.

Identity & access · OpenSSH · By Cloud Security Desk
Research reportDesk publication

Qwen3.8-Flash-Next and GLM-5.3-Flash share a 3:1 long-context pattern

Both models replace most conventional attention layers with recurrent state and reserve sparse attention for periodic retrieval. Their differences lie in where they place capacity, how much neural computation they activate, and what their serving stacks must keep trustworthy.

AI systems · Resilience · By Umair Akbar and Ahmed Elshekh
Technical guideIllustrative analysis

What changes when static keys disappear

Workload identity removes a secret, but it also moves trust into issuers, claims, audiences, and runtime attachment points.

Identity & access · Workload security · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed Elshekh