Skip to content

Improve forensics ephemeral cloud workload evidence gates#1548

Open
bnpl7 wants to merge 1 commit into
UnitOneAI:mainfrom
bnpl7:improve/forensics-checklist-ephemeral-cloud-workloads
Open

Improve forensics ephemeral cloud workload evidence gates#1548
bnpl7 wants to merge 1 commit into
UnitOneAI:mainfrom
bnpl7:improve/forensics-checklist-ephemeral-cloud-workloads

Conversation

@bnpl7
Copy link
Copy Markdown

@bnpl7 bnpl7 commented Jun 6, 2026

Summary

  • Adds evidence gates for ephemeral cloud workloads including Kubernetes and managed container workloads (spec, events, logs, container statuses, image digests, etc.), as well as serverless workloads (versions, environment configurations, deployment package hashes, execution roles, triggers).
  • Addresses mutable tag and alias vulnerabilities (e.g. relying on :latest or prod aliases rather than immutable SHA-256 digests or version IDs) by introducing verification findings (EPHEMERAL-WL-01 through EPHEMERAL-WL-05) and required fields.
  • Updates the Findings Classification section to escalate ephemeral workload metadata and container/log capture priority (Critical/High) due to rapid recycling risk.
  • Expands Section 5 (Output Format) report template to include a structured "Ephemeral Cloud Workloads" section with a clear metric table.
  • Adds "Pitfall 6: Relying on Mutable Tags and Aliases for Ephemeral Workloads" to the Common Pitfalls section.
  • Appends references for Kubernetes pods, AWS Lambda versions, and NIST SP 800-190.

Bounty Info

Addresses #1395.

I have read and agree to the CONTRIBUTING.md bounty terms. Preferred payment method: PayPal, to be provided privately after acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant