Skip to content
Kodvalley

Cybersecurity

Cloud & Kubernetes Security Review

Configuration review and penetration testing of AWS, Azure, Google Cloud and Kubernetes environments.

3 major clouds plus Kubernetes
CIS benchmark aligned checks
IaC reviewed before deployment

Scope

What we review

Most cloud incidents start with a setting, not a zero-day: a public bucket, an over-privileged role or a forgotten access key. We review how your cloud is configured and test what an attacker could reach from the outside and from a compromised account.

Identity and access

Roles, policies, keys and privilege escalation paths.

Data storage

Buckets, databases, snapshots and encryption.

Network exposure

Security groups, public endpoints and segmentation.

Kubernetes and containers

Cluster configuration, RBAC, images and secrets.

Infrastructure as code

Terraform and templates checked before they ship.

Logging and detection

Whether an attack would leave a trace you can see.

Platforms we assess

We work with read-only access wherever possible and agree every active test in advance.

Amazon Web Services

IAMS3EC2EKSLambdaOrganizations

Microsoft Azure

Entra IDStorageAKSKey VaultDefender

Google Cloud

IAMGCSGKECloud RunVPC

Kubernetes and IaC

RBACPod securityHelmTerraformCIS benchmarks

What you receive

  1. 01 Prioritised findings with fixes
  2. 02 Privilege escalation paths explained
  3. 03 CIS benchmark results
  4. 04 Infrastructure as code recommendations
  5. 05 Free re-test after remediation

Questions we often hear

Do you need administrator access?

No. Most of the review uses a read-only audit role. Active tests are agreed in advance and limited to the scope you approve.

Do we need permission from the cloud provider?

AWS, Azure and Google Cloud allow customers to test their own resources within their published policies. We follow those policies.

Can you check our Terraform before deployment?

Yes. Reviewing infrastructure as code catches problems before they reach production.