Learning · CI/CD

Pipeline security

Secrets, runners, supply chain, and least privilege — hardening CI/CD so the pipeline is not the weakest door.

CI/CD systems are privileged attack surface: they hold secrets and can push to production. Treat them accordingly.

Secrets in CI

Store credentials in the platform’s secret store, scoped to environments and repositories. Rotate. Prefer short-lived OIDC/federation to clouds over long-lived static keys when available. Never echo secrets into logs.

Runner hygiene

Use ephemeral, patched runners. Lock down what jobs can access (network, privileged Docker). Shared long-lived VMs with docker.sock and prod kubeconfigs are a breach waiting for a malicious PR.

Supply chain

  • pin actions/plugins by digest or verified version
  • scan images and dependencies in CI
  • sign artifacts when your org supports verification at deploy time
  • least privilege for deploy identities (per env, per service)

Branch protection and reviews

Required reviews and signed commits where policy demands. Protect against self-approval of dangerous workflow changes. CI config is code — review it like production code.

Audit

Who deployed what, when, from which pipeline? Keep logs. Incident response needs that trail more often than people expect.

A secure app with an open CI system is not secure.

← CI/CD