A deployment pipeline is a privileged production path
Whatever can deploy to production has production's power, whether or not anyone thinks of it that way.
It holds credentials that reach live systems, it runs automatically, and it is often configurable by anybody who can commit. That combination is unusual: a highly privileged actor whose instructions are editable by a wide group. Protecting production while leaving the thing that writes to production open is a common and consequential gap.
More on CI/CD security
- Code review does not protect a compromised runnerNobody looked inside the machine
- Forked code should not automatically receive secretsThe belt does not ask who sent it
- Branch protection does not protect every release pathThe gate only guards its own road
- Deployment credentials should match deployment scopeOne bolt across all three
- Build logs can become secret leaksThe log is a page, and people read pages
- Self-hosted runners inherit local trustYou gave the job a desk indoors
