Skip to main content

Secure CI/CD Pipelines: Threats and Hardening

Learn to harden CI/CD: OIDC instead of stored keys, scoped tokens, SHA pinned actions, Vault secrets, Jenkins hardening, signing, and audit logs.

~3 hours
12 Topics
Hands-on Scenarios

What You'll Learn

Understanding Why Pipelines Are High-Value Targets

What a build job can reach Your CI/CD pipeline holds more access than almost any person in the company.

Mapping the CI/CD Attack Surface

How pipelines get compromised Most pipeline breaches follow a handful of paths, and each has a direct fix.

Replacing Stored Cloud Keys with OIDC Federation

How OIDC federation works OIDC federation lets a job prove its identity to AWS with a token GitHub signs, instead of presenting a stored access key.

Limiting What Each Workflow Can Do

Setting the default token to read only Every workflow gets a GITHUB_TOKEN that can act on your repository.

Hardening Runners

Choosing hosted or self-hosted runners GitHub hosted runners start from a clean virtual machine for every job and are discarded afterwards, which...

Managing Secrets with HashiCorp Vault

Deciding between GitHub Secrets and Vault GitHub Secrets is a good answer for a few static values, especially when you scope them to an environment.

Skills You'll Master

CICDGITHUB-ACTIONSOIDCVAULTPIPELINE-SECURITY

Curriculum Index12 topics

1

Understanding Why Pipelines Are High-Value Targets

What a build job can reach Your CI/CD pipeline holds more access than almost any person in the company.

2

Mapping the CI/CD Attack Surface

How pipelines get compromised Most pipeline breaches follow a handful of paths, and each has a direct fix.

3

Replacing Stored Cloud Keys with OIDC Federation

How OIDC federation works OIDC federation lets a job prove its identity to AWS with a token GitHub signs, instead of...

4

Limiting What Each Workflow Can Do

Setting the default token to read only Every workflow gets a GITHUB_TOKEN that can act on your repository.

5

Hardening Runners

Choosing hosted or self-hosted runners GitHub hosted runners start from a clean virtual machine for every job and are...

6

Managing Secrets with HashiCorp Vault

Deciding between GitHub Secrets and Vault GitHub Secrets is a good answer for a few static values, especially when you...

7

Hardening Jenkins Pipelines

Applying the baseline Jenkins settings Jenkins is common in enterprises and powerful, and a misconfigured instance is a...

8

Signing, Verifying, and Gating Releases

Signing images from the pipeline Signing proves an image came from your pipeline and has not been altered since.

9

Putting It Together: A Secure Pipeline

The stages and what each one blocks The pipeline runs in a fixed order, and each stage can stop the next.

10

Auditing and Monitoring the Pipeline

What GitHub records and where You cannot investigate a compromise without a record of what happened.

11

Running the Hands-On Lab: Build a Secure Pipeline End to End

Before you start This lab builds the pipeline from this module for a tiny web app: OIDC into AWS, a scanned and signed...

12

Quick Reference and Common Mistakes

Quick reference Common mistakes Keeping a long lived cloud access key in repository secrets is the mistake that turns a...

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

    ₹12L - ₹30L a year

    High Demand
  • DevOps Engineer

    ₹8L - ₹22L a year

    High Demand
  • Platform Engineer

    ₹15L - ₹28L a year

    Growing
See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

A stored key is valid for years and works from anywhere if it leaks. With OIDC, each job asks AWS for credentials that last about an hour and only work for the repository and branch you trust, so there is nothing long lived to steal.

A version tag is a movable pointer, and attackers have rewritten tags to point at malicious code. A full commit SHA is immutable, so the code you reviewed is the code that runs.

Only if it never runs code from the pull request. It runs with the base repository's secrets and write token, so checking out and running a fork's code in that trigger is a well known way to leak secrets.

GitHub Secrets is fine for a few static values. Vault pays off when you need dynamic, short lived credentials, central policy, and an audit trail of every read across many pipelines.