CI/CD Platform · View 21 of 22 · Assurance
The ordering that matters
- The audit record is written before the secret value is returned, never after. A read that cannot be recorded does not happen.
- The refusal for an untrusted class is an explicit, distinct outcome, not an empty value. A job that silently receives no secret fails later with a misleading error.
- Revocation is pushed at job end and does not wait for token expiry, so a leaked token's useful life is the job's life rather than the TTL.
Realisation
- Job identity binds tenant, repository, ref and trust class, and is minted per job with the job's TTL.
- Cloud access is obtained by exchanging that identity for a short-lived role rather than by holding a stored credential.
- Registered secret values are redacted on the log path out of the sandbox.
Risks
- Redaction is best-effort against a build that deliberately encodes a secret before printing it. It protects against accident, not against intent — which is why an untrusted run is given nothing to print.