Safeguard
Tag

service-accounts

Safeguard articles tagged "service-accounts" — guides, analysis, and best practices for software supply chain and application security.

7 articles

Cloud Security

The Kubernetes Token Nobody Asked For

Every pod gets a token that authenticates to the API server, whether the application inside it ever calls the API or not. It sits there anyway, readable by anything that can read a file in the container, because the default is on.

Sep 18, 20265 min read
Compliance

Every Production System Has Accounts Nobody Created on Purpose

The demo tenant from the launch, the test user from a 2023 bug, the seed administrator that shipped with the first deployment. None appear on an access review, because reviews enumerate employees and these live in the product's own user table.

Sep 18, 20265 min read
Compliance

Your Quarterly Access Review Revoked Nothing

Managers approve everything because the task as presented cannot be done well: uninterpretable entitlement names, no usage data, and a default that costs nothing while the alternative breaks a colleague's Friday.

Sep 17, 20266 min read
Application Security

GCP IAM security best practices

GCP IAM misconfigurations, not exploits, cause most cloud breaches. Here is how to enforce least privilege, lock down service accounts, and audit access.

Jun 19, 20267 min read
Container Security

K8s RBAC Blast Radius in Supply Chain Attacks

How Kubernetes RBAC determines what a supply chain attack can actually do once a compromised workload runs, and the RBAC patterns that meaningfully reduce blast radius.

Feb 16, 20268 min read
Cloud Security

How to implement least privilege for GCP service accounts

A step-by-step guide to auditing, scoping, and enforcing least privilege service accounts GCP-wide — including key rotation and IAM audit workflows.

Feb 7, 20267 min read
Cloud Security

Applying least-privilege principles to GCP IAM roles

Predefined roles, custom roles, IAM Recommender, and service account hygiene: a practical guide to applying GCP IAM least privilege without breaking production.

Jan 12, 20267 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.