Pipeline Secrets
Short-lived credentials, workload identity, and why the CI system is a prime target.
5 to work through
-
beginner
A build script echoes a deployment token into the pipeline log. The log is private to the engineering team. Is the token compromised?
2 min answer -
intermediate
A build pipeline needs credentials to deploy. What is the safe design, and what is the most common leak?
2 min answer -
advanced
A team stores no credentials in its repository. The cloud role is assumed through OIDC federation, the registry token lives in a managed secret store, and the build never prints it. Over one weekend an attacker publishes a malicious version of the team's package, and the audit trail shows the push came from the team's own pipeline. Trace how, and name the structural fix.
3 min answer -
advanced
Between 31 January and 1 April 2021 an altered Codecov Bash Uploader script exfiltrated the environment variables of every CI job that ran it, and was discovered by a customer comparing the script's checksum against the published one. What is the underlying architectural failure, and which changes remove the class rather than the instance?
3 min answer -
advanced
How should secrets be handled in a delivery pipeline, and what is the strongest available approach?
2 min answer
4 terms in this topic
Fork-Triggered Build
A continuous-integration trigger that runs a workflow in the base repository's privileged context while its inputs come from an outside contributor -…
practicePipeline Credential Scope
Granting a pipeline short-lived, narrowly scoped identity for exactly the environment it is deploying to, rather than a long-lived key.
conceptUntrusted Build Step
Any pipeline step whose code you do not control and did not review - a downloaded script, a third-party action, a plugin - which runs with the whole …
protocolWorkload Identity Federation
A pipeline proving what it is with a short-lived signed token from its own platform, so no long-lived cloud credential is ever stored.
Neighbouring topics
Delivery & Release Engineering
General material on getting a change from commit to production safely and often.
Pipeline Architecture
Stages, fan-out, caching, and the difference between a pipeline and a long script.
Build Reproducibility
Pinned inputs and hermetic builds, so one commit cannot produce two different artifacts.
Artifact Management
Immutable versioned outputs, promotion between repositories, and retention policy.
Environment Strategy
How many environments earn their cost, what each proves, and what none of them prove.
Branching Models
GitFlow, trunk and release branches as delivery constraints rather than Git preferences.
Continuous Integration Discipline
Integrating to the mainline daily, and the test speed and review culture that requires.
Deployment Strategies
Rolling, blue-green, canary and shadow, and the traffic and state each one assumes.
Progressive Delivery
Separating deploy from release, and exposing a change to users in controlled increments.
Rollback & Forward Fix
When reversing is genuinely possible, and designing so that it usually is.
Database Migration Under CD
Expand-contract, backwards-compatible schema change, and migrations that cannot roll back.
GitOps
Declared desired state in version control, with a reconciler closing the gap continuously.
IaC Modules & Drift
Reusable infrastructure modules, state ownership, and detecting what changed out of band.
Policy as Code
Encoding standards as automated admission and plan-time checks instead of review comments.
Supply-Chain Provenance
SBOMs, signed artifacts, attestation, and knowing what actually went into a build.
Deployment Gates
Automated verification between stages, and the difference between a gate and a delay.
Flow Metrics
Work in progress, flow time and flow efficiency — where a change waits rather than moves.
Change Management vs CD
Reconciling CAB-era controls with continuous delivery without pretending either away.
Multi-Region Rollout
Ordering regions, bake time, and stopping a bad change before it becomes global.