Deployment credentials should match deployment scope
A pipeline that deploys one service should not hold credentials that can change everything.
Broad credentials are convenient because one set works everywhere, and they mean compromising the least important pipeline yields access to the most important environment. Scoping per service and per environment is more setup and is what makes the blast radius match the job.
More on CI/CD security
- A deployment pipeline is a privileged production pathIt goes straight over the gate
- Code review does not protect a compromised runnerNobody looked inside the machine
- Forked code should not automatically receive secretsThe belt does not ask who sent it
- Branch protection does not protect every release pathThe gate only guards its own road
- Build logs can become secret leaksThe log is a page, and people read pages
- Self-hosted runners inherit local trustYou gave the job a desk indoors
