Logo The David Page
  • Home
  • About
  • North Star
  • Recent Posts
  • Posts
Logo Inverted Logo
  • Tags
  • Amazon Bedrock
  • Arm64
  • AWS
  • Azure
  • Azure CLI
  • Benchmark
  • CDN
  • CloudFront
  • CloudWatch
  • Containers
  • Cost Optimization
  • Databases
  • Docker
  • DynamoDB
  • EC2
  • ECR
  • FinOps
  • Front Door
  • Gemini API
  • Glacier
  • Graviton
  • IAM
  • Kubernetes
  • Lambda
  • NAT Gateway
  • Networking
  • Node.js
  • Observability
  • Performance
  • Privilege Escalation
  • Rate Limiting
  • RDS
  • RDS Proxy
  • Reliability
  • S3
  • Scalability
  • Security
  • Serverless
  • Software Architecture
  • Storage
  • System Design
  • Troubleshooting
  • VPC
  • WAF
Hero Image
AWS Lambda's /tmp Directory Isn't as Clean as You Think

Assuming every Lambda invocation runs in a fresh, isolated environment is a very reasonable guess. It’s also wrong. “Fresh environment” is carrying a lot of weight in that sentence. A lot of developers write Lambda functions on the assumption that each invocation starts in a completely clean, isolated sandbox — new environment, empty disk, nothing left behind from whatever ran before. That assumption is exactly what “serverless” seems to promise. It isn’t quite what happens.

  • AWS
  • Lambda
  • Serverless
  • Security
Sunday, August 2, 2026 Read
Hero Image
The IMDSv2 Hop Limit Trap When Running Containers on EC2

Switching to IMDSv2 is the right security move, full stop. Do it on an EC2 instance running Docker containers, though, and the app inside loses access to its IAM Role credentials immediately. Turns out “do the secure thing” has a body count. Upgrading from IMDSv1 to IMDSv2 is standard, correct security guidance — it closes off a real class of credential-theft attacks against the EC2 instance metadata service. But flipping that switch on an instance that runs its application inside a Docker container can break AWS SDK access instantly, with no obvious explanation in the error message.

  • AWS
  • EC2
  • Security
  • Containers
  • Docker
Saturday, August 1, 2026 Read
Hero Image
iam:PassRole + Wildcard: The Privilege Escalation Hiding in Plain Sight

A developer account with nothing but lambda:CreateFunction and a wildcard iam:PassRole can walk itself up to full Administrator — no exploit, no misconfigured bucket, just permissions doing exactly what they were asked to do. No exploit. No CVE. Just IAM doing exactly what you told it to. This one doesn’t show up as a vulnerability scan finding or a CVE — it’s a permissions grant that looks completely reasonable in a policy review, right up until someone connects the dots.

  • AWS
  • IAM
  • Security
  • Privilege Escalation
Saturday, August 1, 2026 Read
Navigation
  • About
  • North Star
  • Recent Posts
Contact me:
  • hi@thedavidlee.space

© 2026 David Lee.