{
  "slug": "cloud",
  "name": "Cloud object storage",
  "category": "Infrastructure",
  "summary": "Review cloud storage and service access through attributable ownership, least privilege, destination policy, and auditable configuration.",
  "scope": "Defensive study and review of artifacts supplied by their owner. Record missing evidence as an open question.",
  "inputs": [
    "Cloud account and resource inventory",
    "IAM and storage policies",
    "Approved architecture and egress requirements"
  ],
  "review": [
    {
      "title": "Establish ownership",
      "body": "Tie each bucket, service identity, and integration to a documented account, environment, and responsible owner before drawing conclusions."
    },
    {
      "title": "Review effective policy",
      "body": "Evaluate identity, resource, network, and conditional policies together for the exact action and tenant context."
    },
    {
      "title": "Constrain service egress",
      "body": "Apply an explicit destination policy plus independent network controls for server-side requests."
    },
    {
      "title": "Audit change paths",
      "body": "Ensure configuration changes, public sharing, and credential rotation leave reviewable records and safe defaults."
    }
  ],
  "outputs": [
    "Attributed asset inventory",
    "Effective-permission review",
    "Egress and audit controls"
  ],
  "pitfalls": [
    "Calling an internet-visible asset owned without attribution",
    "Reviewing IAM policies in isolation",
    "Using a network control as the only destination check"
  ],
  "references": {
    "resources": [
      {
        "id": "aws-iam-machine-identity-best-practices",
        "title": "AWS IAM security best practices for workload identities",
        "url": "https://vulns.co/research/resources/aws-iam-machine-identity-best-practices/"
      },
      {
        "id": "owasp-server-request-destination-boundaries",
        "title": "OWASP Server-Side Request Forgery Prevention",
        "url": "https://vulns.co/research/resources/owasp-server-request-destination-boundaries/"
      },
      {
        "id": "nist-sp-800-190-container-isolation-guide",
        "title": "NIST SP 800-190: Application Container Security Guide",
        "url": "https://vulns.co/research/resources/nist-sp-800-190-container-isolation-guide/"
      }
    ],
    "diagrams": [
      {
        "id": "server-request-destination-policy",
        "title": "Layer server-request destination controls",
        "url": "https://vulns.co/research/diagrams/server-request-destination-policy/"
      },
      {
        "id": "workload-identity-tenant-scope",
        "title": "Keep workload authority tenant-scoped",
        "url": "https://vulns.co/research/diagrams/workload-identity-tenant-scope/"
      }
    ],
    "reports": [
      {
        "id": "shopify-exchange-request-isolation-2019",
        "title": "Shopify Exchange screenshot service crossed internal boundaries",
        "url": "https://vulns.co/research/reports/shopify-exchange-request-isolation-2019/"
      },
      {
        "id": "meta-service-identity-secrets-trust-boundary-2026",
        "title": "Meta service-identity exposure amplified by excessive secret access",
        "url": "https://vulns.co/research/reports/meta-service-identity-secrets-trust-boundary-2026/"
      },
      {
        "id": "google-actifio-driver-service-identity-isolation-2025",
        "title": "Actifio driver execution exposed excessive shared-service authority",
        "url": "https://vulns.co/research/reports/google-actifio-driver-service-identity-isolation-2025/"
      }
    ]
  },
  "provenance": {
    "publisher": "vulns.co / GK Data",
    "guide_updated": "2026-10-11",
    "library_as_of": "2026-10-04",
    "library_commit": "d5550c7891119cf1379e235721541c947850a3b3"
  },
  "url": "https://vulns.co/skills/cloud/",
  "markdown_url": "https://vulns.co/skills/cloud/SKILL.md"
}
