CI/CD secrets
Pipelines need credentials to nearly everything they deploy to, which makes them the most credential-rich systems in the organisation.
Registries, cloud accounts, production environments, code signing. They sit in a system configurable by many people and frequently visible in logs. Scoping them per environment and per service, and issuing them short-lived, is what stops one pipeline compromise reaching everything.
Checked against the primary source.
