Case ED0C1D · Cloud · L3 Applied
Secrets in CI/CD
Practise as: Explain it · Interview · Deep dive
Interview questionHow should a CI pipeline authenticate to a cloud account to deploy?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Long-lived cloud keys stored as CI secrets leak via logs, forks, compromised actions or insiders
- Use OIDC federation: the CI job gets a signed identity token and exchanges it for short-lived cloud credentials
- Scope trust to repo, branch and environment claims so a fork or feature branch cannot assume the deploy role
- Pin third-party actions to commit SHAs; a compromised action runs with your secrets
- Scan commits for secrets (pre-commit and server-side) and rotate anything that ever touched git history
If the interviewer pushes back
- What happens if the OIDC trust policy only checks the repository owner, not the repo and branch?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.