Skip to content
Cloud Security DeskSearch
Menu

Research topic

Workload security

Runtime context decides whether a control matters.

26 publications

Field guidance for Kubernetes, machine identity, service boundaries, and modern application infrastructure.

View every topic

From the desk

26 publications
Technical guide · September 12, 2026 · Source-based analysis

Keep an S3 bucket private with Block Public Access

Enable S3 Block Public Access while preserving approved readers. Review the four settings, private CloudFront origins, and practical access tests.

Technical guide · September 12, 2026 · Source-based analysis

Remove public SSH access from an EC2 security group

Remove internet-wide EC2 SSH rules after testing Session Manager or restricted SSH. Check all groups, IPv6, fresh sessions, and recovery access.

Technical guide · September 12, 2026 · Source-based analysis

Keep a Google Cloud Storage bucket private

Use public access prevention and uniform bucket-level access for Cloud Storage, then test IAM readers, signed links, and application dependencies.

Technical guide · September 12, 2026 · Source-based analysis

Require authentication between Cloud Run services

Configure Cloud Run service-to-service authentication with a dedicated caller identity, the right ID token audience, and useful negative tests.

Technical guide · September 12, 2026 · Source-based analysis

Check and stop anonymous access to Azure blobs

Understand account and container settings and prove both anonymous denial and intended app access.

Technical guide · September 12, 2026 · Source-based analysis

Restrict SSH and RDP access with an Azure network security group

Inspect effective rules, preserve the approved management path and test a fresh connection.

Technical guide · September 2, 2026 · Source-based analysis

Keep Terraform plans and state inside the change boundary

Protect Terraform plans and state as sensitive artifacts, and bind production approval to the specific plan, dependencies, workspace and apply identity that will be used.

Technical guide · September 2, 2026 · Source-based analysis

Separate webhook authenticity from permission to process it

Verify webhook authenticity at intake, then make durable acceptance, duplicate handling and permission to change business state separate decisions.

Technical guide · September 2, 2026 · Source-based analysis

Keep build credentials out of the image and its evidence

A temporary BuildKit secret mount controls credential delivery, not everything a build command can do with the credential or leave in its outputs.

Technical guide · September 2, 2026 · Source-based analysis

Design RDS IAM authentication around the connection pool

Generate IAM database tokens for the physical connections that need them, and keep token validity separate from the lifetime of an already-established SQL session.

Technical guide · September 2, 2026 · Source-based analysis

Finish S3 multipart uploads with verifiable object integrity

Keep an owned part manifest and verify the complete object result, because successful part transfers and an initial HTTP 200 are not sufficient completion evidence.

Technical guide · September 2, 2026 · Source-based analysis

Give Kubernetes admission webhooks an explicit failure contract

Treat an admission webhook as a control-plane dependency with explicit behavior for denial, call failure, mutation and the changes needed to repair it.

Technical guide · August 28, 2026 · Source-based analysis

Choosing isolation for a Kubernetes tenant

A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.

Technical guide · August 28, 2026 · Source-based analysis

Make secret rotation reach every running application

Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.

Technical guide · August 28, 2026 · Source-based analysis

Design an outbound fetch service that contains SSRF

A URL check is only the first decision. The fetch worker must contact the approved destination, recheck redirects and limit the authority of every request.

Technical guide · August 28, 2026 · Source-based analysis

Turn SBOM and VEX records into patch decisions

A VEX statement is an assertion about a specific product and vulnerability. Match its scope and conditions before using it to suppress a finding.

Technical guide · August 28, 2026 · Source-based analysis

Prepare cloud workloads for hybrid post-quantum TLS

Hybrid support in a library is not proof that every TLS hop uses it. Verify negotiation, compatibility and fallback while keeping certificate authentication separate.

Technical guide · August 28, 2026 · Source-based analysis

Know when AWS KMS encryption needs an envelope

KMS Encrypt has small plaintext limits. Follow the data key and encrypted-message format when an application needs to protect larger payloads.

Technical guide · Published August 28, 2026 · Source-based analysisSeries August 10, 2026

Prove Azure Storage private access from DNS to authorization

Check the exact storage subresource, resolve its normal hostname from the application, and test public access and data permissions as separate boundaries.

Technical guide · Published August 28, 2026 · Source-based analysisSeries July 1, 2026

Keep tenant data out of reusable AWS Lambda state

Reuse clients and connections deliberately, while keeping request identity, temporary files, and initialization snapshots inside clearly defined data lifetimes.

Technical guide · Published August 28, 2026 · Source-based analysisSeries May 22, 2026

Verify container provenance before admitting a pinned image

Use the digest to identify the artifact, then check who signed it, which builder produced it, and which evidence survived promotion into the deployment registry.

Technical guide · Published August 28, 2026 · Source-based analysisSeries April 12, 2026

Require EC2 IMDSv2 without breaking container credentials

Separate metadata token requirements from response hop limits, then verify both existing instances and future launches before declaring the migration complete.

Technical guide · Published August 28, 2026 · Source-based analysisSeries March 3, 2026

Test Kubernetes egress policies beyond a successful DNS lookup

Separate DNS resolution, source egress, destination ingress, and application identity when testing Kubernetes network isolation.

Technical guide · Published August 28, 2026 · Source-based analysisSeries January 22, 2026

Roll out Kubernetes Pod Security Admission without surprises

Stage namespace enforcement around the Pods a controller will create next, with explicit policy versions, runtime checks, and narrowly owned exceptions.

Questions answered

  1. What does Cloud Security Desk cover under Workload security?

    Field guidance for Kubernetes, machine identity, service boundaries, and modern application infrastructure.

    Supporting context

    Runtime context decides whether a control matters.

  2. Why does the workload security topic matter to cloud security?

    Runtime context decides whether a control matters. This topic applies that principle to practical control evidence and review decisions.

  3. Which control questions belong to Workload security?

    Research belongs here when its central evidence, failure mode, or operational decision falls within the workload security boundary described on this page.

  4. How many workload security publications are available?

    This page currently lists 26 publications assigned to Workload security.

  5. How should readers use the Workload security research?

    Start with the publication closest to the control, platform, or evidence gap under review, then follow its findings, limitations, numbered sources, related work, and downloadable material.

  6. Can workload security overlap other research topics?

    Yes. A publication can appear under several topics when one evidence path crosses multiple control boundaries; each publication page identifies its complete scope.

    Supporting context