Pipeline security
Secrets, runners, supply chain, and least privilege — hardening CI/CD so the pipeline is not the weakest door.
CI/CD systems are privileged attack surface: they hold secrets and can push to production. Treat them accordingly.
Secrets in CI
Store credentials in the platform’s secret store, scoped to environments and repositories. Rotate. Prefer short-lived OIDC/federation to clouds over long-lived static keys when available. Never echo secrets into logs.
Runner hygiene
Use ephemeral, patched runners. Lock down what jobs can access (network, privileged Docker). Shared long-lived VMs with docker.sock and prod kubeconfigs are a breach waiting for a malicious PR.
Supply chain
- pin actions/plugins by digest or verified version
- scan images and dependencies in CI
- sign artifacts when your org supports verification at deploy time
- least privilege for deploy identities (per env, per service)
Branch protection and reviews
Required reviews and signed commits where policy demands. Protect against self-approval of dangerous workflow changes. CI config is code — review it like production code.
Audit
Who deployed what, when, from which pipeline? Keep logs. Incident response needs that trail more often than people expect.
A secure app with an open CI system is not secure.