Container and Serverless Security Review
Review build provenance, deployment access, runtime permissions, secrets, and investigation coverage across containers and functions. Includes a fillable PDF with worked examples and decision records.
Fillable PDF. Reviewed 2026-09-21. Includes practical guidance and reusable review records.
- Review the delivery and runtime paths: Review one workload and environment at a time. Mark checks that do not apply with a reason; container controls and managed-function controls are not interchangeable.
- Worked review / Document processor: Fictional example: a file upload triggers a function that calls a container service. Both use a broad storage role inherited from an early prototype.
- Workload review record: Repeat this sheet per workload. Use evidence-backed outcomes: verified, gap, unknown, or not applicable with a reason.
References
Examples are fictional. Adapt these materials to your environment; completing a worksheet is not a certification.
