Rollback needs the same security as rollout
The path used to go back is a path to production, and it is usually less controlled than the one used to go forward.
It gets built in a hurry, used under pressure, and exempted from approval because speed matters during an incident. That makes it an attractive route: fewer checks, same power. Whatever protects deployment should protect the undo.
More on CI/CD security
- A deployment pipeline is a privileged production pathIt goes straight over the gate
- Code review does not protect a compromised runnerNobody looked inside the machine
- Forked code should not automatically receive secretsThe belt does not ask who sent it
- Branch protection does not protect every release pathThe gate only guards its own road
- Deployment credentials should match deployment scopeOne bolt across all three
- Build logs can become secret leaksThe log is a page, and people read pages
