Skip to main content

mapping-pod-to-cloud-credential-reach

Map what cloud identity a compromised pod can reach and what that identity can then do: a pod bound to a workload identity or role far broader than it needs, a node instance role reachable from any pod through the node metadata endpoint, a service-account token mounted into a pod that federates to cloud, and the chain from one pod's credential to another cloud resource or identity. Covers Kubernetes on cloud where pods obtain cloud credentials through workload identity federation, mounted tokens, or the node role, and where a pod compromise becomes cloud access. Use when pods hold or can reach cloud credentials and the blast radius of a pod compromise is the question. The compromised pod is the source, the cloud resource its credential reaches is the sink, and the over-broad or reachable credential is the bug.

الانتقال إلى التثبيت

معلومات المصدر

المستودع
UnboundCompute/security-agent-skills
آخر نشاط في المصدر
٢٨ أغسطس ٢٠٢٦ في ١٦:٣٤
لغة SKILL.md المكتشفة
الإنجليزية
النجوم
٤
التفرعات
٢

خيارات التثبيت

يُحدَّد Prompt الذي يراجع المصدر أولًا بشكل افتراضي. يمكنك التبديل إلى أمر مباشر أو تنزيل نسخة محلية.

مراجعة ملفات المصدر

اقرأ SKILL.md وأي ملفات مرافقة يعرضها SkillsMP قبل أن تقرر التثبيت.