We discuss CloudShell persistence of compute, data, and access, based on building a Cloud Village CTF at DC33. We’ll look at overcoming console/non-API/API barriers, automation of a non-API service, IAM obfuscation, logging/monitoring, user lock out, overcoming file/container resets, and backdoors.