secretsmgr handbook
Editor sign-in

Cloud misconfiguration is outside our reach

With KMS custody, your cloud provider decides whether a workload's identity claim is genuine. If that trust policy is too loose, through a generic audience or a subject pattern matched by prefix, an attacker can obtain your machine principal's private key, and our client is never consulted. We refuse the configurations we can see (onboarding a machine) and re-check what the provider's API exposes, but the authority is theirs. Review those policies as carefully as you would review a grant.