CI/CD secrets

Pipelines need credentials to nearly everything they deploy to, which makes them the most credential-rich systems in the organisation.

Registries, cloud accounts, production environments, code signing. They sit in a system configurable by many people and frequently visible in logs. Scoping them per environment and per service, and issuing them short-lived, is what stops one pipeline compromise reaching everything.

Checked against the primary source.

More on Supply chain & third parties