contentintech

Cloud Security Cheatsheet

Quick reference for cloud security — IAM policy patterns, storage hardening, and CLI audit commands.

IAMS3Shared ResponsibilitySecrets
NotesCheatsheet

Shared Responsibility

Identity, access, and data are always yours regardless of service model.

LayerIaaSPaaSSaaS
Hardware / networkProviderProviderProvider
OS / runtimeYouProviderProvider
App codeYouYouProvider
IAM / dataYouYouYou

IAM Best-Practice Checklist

  1. MFA on root/owner; never use root for daily tasks.
  2. Roles with temporary credentials over long-lived access keys.
  3. No wildcards — scope Action and Resource tightly.
  4. One role per workload; no shared credentials.
  5. Rotate keys, review access, remove unused identities regularly.
  6. Deny by default; grant explicitly.

Least-Privilege Policy Snippet

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": ["s3:GetObject", "s3:PutObject"],
    "Resource": "arn:aws:s3:::my-app-uploads/*"
  }]
}

Storage Hardening

  1. Enable account-level Block Public Access.
  2. Private ACLs by default; use pre-signed URLs for sharing.
  3. Encryption at rest (SSE-KMS) on every bucket/container.
  4. Enforce TLS-only access via bucket policy.
  5. Enable access logging and object versioning.

Provider Terminology

ConceptAWSAzureGCP
Object storageS3Blob StorageCloud Storage
Compute VMEC2Virtual MachinesCompute Engine
Virtual networkVPCVNetVPC
FirewallSecurity GroupNSGFirewall Rules
SecretsSecrets ManagerKey VaultSecret Manager
Audit logCloudTrailActivity LogCloud Audit Logs
Threat detectionGuardDutyDefender for CloudSecurity Command Center

Audit CLI Commands

GoalCommand
List buckets (AWS)aws s3api list-buckets
Bucket ACL (AWS)aws s3api get-bucket-acl --bucket B
Who am I (AWS)aws sts get-caller-identity
List role assignments (Azure)az role assignment list
List storage accounts (Azure)az storage account list
Get IAM policy (GCP)gcloud projects get-iam-policy PID
List buckets (GCP)gcloud storage buckets list

Secrets & KMS Quick Reference

# AWS Secrets Manager
aws secretsmanager get-secret-value --secret-id db/password
aws secretsmanager rotate-secret --secret-id db/password

# Azure Key Vault
az keyvault secret show --vault-name MyVault --name db-pass

# GCP Secret Manager
gcloud secrets versions access latest --secret=db-pass

# Rules: never hardcode; rotate on schedule; enforce IMDSv2 to
# block SSRF theft of instance role creds at 169.254.169.254

Common Misconfig → Fix

MisconfigurationFix
Public storage bucketEnable Block Public Access; private ACLs
Wildcard IAM policyScope actions + resource ARNs; least privilege
Long-lived access keysUse roles / temporary credentials; rotate
SSH open to 0.0.0.0/0Restrict source; use bastion / SSM
Hardcoded secretsMove to secrets manager; scan repos
IMDSv1 enabledEnforce IMDSv2 (token required)
Unencrypted volume/DBEnable KMS encryption at rest
No audit loggingEnable CloudTrail / Activity / Audit Logs
Privileged K8s podsDrop privileges; RBAC; image scanning

Section navigation