Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “workload identity federation”

4 publications
Technical guideSource-based analysis

Give Kubernetes pods cloud credentials without static keys

EKS Pod Identity, IRSA, AKS Workload ID and Workload Identity Federation for GKE all swap a projected token for short-lived credentials. What leaks if you stop there is the node's own identity.

Identity & access · Amazon Web Services / Microsoft Azure / Google Cloud / Kubernetes · By Cloud Security Desk
Technical guideSource-based analysis

Prepare Azure automation for mandatory MFA on resource management

Azure now requires MFA for user accounts that write through Resource Manager. Find the scripts and pipelines that still sign in as people and move each one to a managed identity or federated credential.

Identity & access · Microsoft Azure / Microsoft Entra / GitHub / Azure DevOps / HashiCorp Terraform · By Cloud Security Desk
Technical guideSource-based analysis

Let AWS workloads call external services with IAM-issued tokens

IAM outbound identity federation lets an AWS role trade its credentials for a signed JWT instead of storing a vendor API key. AWS controls issuance; the receiving service's claim checks decide what the token is worth.

Identity & access · Amazon Web Services / AWS IAM / AWS STS / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk