Release signing depends on protecting signing keys
A signing key that lives in the CI system is available to whoever compromises the CI system.
That is the whole difficulty. Keys in hardware, with separate approval to use them, provide real assurance. Keys in an environment variable provide a signature that anybody with pipeline access can produce, which proves the pipeline ran rather than that anybody approved the release.
More on CI/CD security
- A deployment pipeline is a privileged production pathIt goes straight over the gate
- Code review does not protect a compromised runnerNobody looked inside the machine
- Forked code should not automatically receive secretsThe belt does not ask who sent it
- Branch protection does not protect every release pathThe gate only guards its own road
- Deployment credentials should match deployment scopeOne bolt across all three
- Build logs can become secret leaksThe log is a page, and people read pages
