Serverless Security Guide: Lambda, Fargate & Beyond
Serverless offloads infrastructure but shifts the attack surface onto event sources, IAM, dependencies, and secrets. This 2026 guide covers the real threat model for AWS Lambda, Fargate, Azure Functions, and Google Cloud Functions — and the toolchain that actually works.
How Can Serverless Improve Security?
Serverless genuinely raises the baseline — provided you understand what shifts and what doesn't:
- No OS patching: the cloud provider owns the kernel, container runtime, and language runtime.
- Ephemeral workloads: short execution lifetime limits persistence for most malware.
- Function-level identity: every function gets its own execution role, enabling fine-grained least privilege.
- Default no inbound: most serverless functions aren't reachable from the internet unless you explicitly expose them.
What doesn't change: application-level vulnerabilities, overprivileged IAM, exposed secrets, and vulnerable dependencies all remain your responsibility.
The Serverless Threat Model
Six risks every serverless deployment should defend against:
- Event injection — untrusted event payloads (S3 keys, SQS messages, API Gateway requests) treated as safe.
- Overprivileged function roles — the function has IAM access well beyond what it needs.
- Vulnerable dependencies — Lambda layers and container images carrying CVEs.
- Hardcoded secrets — tokens embedded in function code or environment variables.
- Insecure configurations — public S3 triggers, open API Gateway, broad resource policies.
- DoS and billing abuse — malicious actors triggering functions to drive cost or starve concurrency.
AWS Lambda Security
AWS Lambda remains the serverless default. The must-have controls in 2026:
- Per-function IAM roles with scoped
ResourceARNs — no wildcards. - Scan every Lambda layer and container image for CVEs and secrets at build time.
- Enforce AWS Lambda SnapStart signing (Java/Python) to resist supply-chain tampering.
- Enable X-Ray + CloudTrail Data Events for every function; alert on anomalous invocation patterns.
- Resource-based policies that explicitly list which services can invoke each function.
- Reserved concurrency to cap blast radius during abuse events.
See AWS CSPM for AWS-wide posture checks.
AWS Fargate Serverless Security
Fargate runs full containers without node management — closer to "serverless containers." Security controls to apply:
- Scan container images for OS and application vulnerabilities before pushing to ECR.
- Task IAM roles scoped per task definition — never share across workloads.
- Secrets via Secrets Manager / Parameter Store, never in environment variables plain-text.
- Read-only root filesystem on task definitions wherever possible.
- VPC endpoint policies to restrict which AWS services the task can reach.
- Enable Fargate ephemeral storage encryption with a customer-managed KMS key for regulated workloads.
Secrets Detection in Serverless Applications
Serverless makes secret leakage subtle: a function's environment variables are visible in the console to anyone with lambda:GetFunctionConfiguration, and ephemeral workloads can commit secrets to logs without the usual EC2-level log visibility.
Three layers of defense:
- Pre-commit + CI scanning — secret scanning tools catch hardcoded credentials before deploy.
- Runtime SSM / Secrets Manager retrieval instead of plaintext env vars.
- Log scrubbing + CloudTrail monitoring for exfiltration patterns.
Azure Functions & Google Cloud Functions
Same threat model, different primitives. Azure Functions ties into Entra ID managed identities (equivalent to IAM roles); Cloud Functions uses Google service accounts. Pay particular attention to function app-level identity in Azure (every function in the app shares the identity by default — split apps to achieve per-function identity). On GCP, use cloudfunctions:invoke IAM conditions to restrict invokers.
Best Serverless Security Tools in 2026
- TigerGate — Lambda, Fargate, Azure Functions, and Cloud Functions coverage. Scans code + images, checks IAM, monitors runtime. See serverless security.
- Prisma Cloud (serverless defender) — enterprise-grade runtime for Lambda.
- Datadog Serverless Monitoring + Security — strong observability-first option.
- Snyk Lambda — SCA on function dependencies.
- Sysdig Secure for serverless — eBPF-oriented runtime detection.
- AWS Native (Lambda PowerTuning + Config + Security Hub) — AWS-only baseline.
FAQ
Does CNAPP cover serverless?
Mature CNAPPs cover Lambda, Fargate, Azure Functions, and Cloud Functions as part of their workload inventory. Depth varies — ask vendors for a demo on your actual function portfolio.
Can I use eBPF for Lambda runtime security?
Not directly — AWS doesn't expose the Lambda host kernel. CloudWatch Logs + X-Ray + Lambda Insights are the primary runtime signal. For Fargate (which runs containers), eBPF-adjacent approaches work via EventBridge + custom instrumentation.
How is serverless security different from container security?
Containers give you kernel-level visibility; serverless does not. You lose runtime depth but gain patch offloading. For regulated workloads needing eBPF visibility, consider Fargate over Lambda.
Secure Your Serverless Stack
TigerGate covers Lambda, Fargate, Azure Functions, and Cloud Functions — plus the surrounding IAM, API Gateway, and event sources.
Start Free Trial