Open cardosec

Case ED0C1D · Cloud · L3 Applied

Secrets in CI/CD

Practise as: Explain it · Interview · Deep dive

Interview questionHow should a CI pipeline authenticate to a cloud account to deploy?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Long-lived cloud keys stored as CI secrets leak via logs, forks, compromised actions or insiders
  2. Use OIDC federation: the CI job gets a signed identity token and exchanges it for short-lived cloud credentials
  3. Scope trust to repo, branch and environment claims so a fork or feature branch cannot assume the deploy role
  4. Pin third-party actions to commit SHAs; a compromised action runs with your secrets
  5. Scan commits for secrets (pre-commit and server-side) and rotate anything that ever touched git history

If the interviewer pushes back

  • What happens if the OIDC trust policy only checks the repository owner, not the repo and branch?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.