Secure CI/CD Pipelines: Threats and Hardening
Learn to harden CI/CD: OIDC instead of stored keys, scoped tokens, SHA pinned actions, Vault secrets, Jenkins hardening, signing, and audit logs.
What You'll Learn
Understanding Why Pipelines Are High-Value Targets
What a build job can reach Your CI/CD pipeline holds more access than almost any person in the company.
Mapping the CI/CD Attack Surface
How pipelines get compromised Most pipeline breaches follow a handful of paths, and each has a direct fix.
Replacing Stored Cloud Keys with OIDC Federation
How OIDC federation works OIDC federation lets a job prove its identity to AWS with a token GitHub signs, instead of presenting a stored access key.
Limiting What Each Workflow Can Do
Setting the default token to read only Every workflow gets a GITHUB_TOKEN that can act on your repository.
Hardening Runners
Choosing hosted or self-hosted runners GitHub hosted runners start from a clean virtual machine for every job and are discarded afterwards, which...
Managing Secrets with HashiCorp Vault
Deciding between GitHub Secrets and Vault GitHub Secrets is a good answer for a few static values, especially when you scope them to an environment.
Skills You'll Master
Curriculum Index12 topics
Understanding Why Pipelines Are High-Value Targets
What a build job can reach Your CI/CD pipeline holds more access than almost any person in the company.
Mapping the CI/CD Attack Surface
How pipelines get compromised Most pipeline breaches follow a handful of paths, and each has a direct fix.
Replacing Stored Cloud Keys with OIDC Federation
How OIDC federation works OIDC federation lets a job prove its identity to AWS with a token GitHub signs, instead of...
Limiting What Each Workflow Can Do
Setting the default token to read only Every workflow gets a GITHUB_TOKEN that can act on your repository.
Hardening Runners
Choosing hosted or self-hosted runners GitHub hosted runners start from a clean virtual machine for every job and are...
Managing Secrets with HashiCorp Vault
Deciding between GitHub Secrets and Vault GitHub Secrets is a good answer for a few static values, especially when you...
Hardening Jenkins Pipelines
Applying the baseline Jenkins settings Jenkins is common in enterprises and powerful, and a misconfigured instance is a...
Signing, Verifying, and Gating Releases
Signing images from the pipeline Signing proves an image came from your pipeline and has not been altered since.
Putting It Together: A Secure Pipeline
The stages and what each one blocks The pipeline runs in a fixed order, and each stage can stop the next.
Auditing and Monitoring the Pipeline
What GitHub records and where You cannot investigate a compromise without a record of what happened.
Running the Hands-On Lab: Build a Secure Pipeline End to End
Before you start This lab builds the pipeline from this module for a tiny web app: OIDC into AWS, a scanned and signed...
Quick Reference and Common Mistakes
Quick reference Common mistakes Keeping a long lived cloud access key in repository secrets is the mistake that turns a...
Career Impact
Roles that use the skills in this module.
- High Demand
DevSecOps Engineer
₹12L - ₹30L a year
- High Demand
DevOps Engineer
₹8L - ₹22L a year
- Growing
Platform Engineer
₹15L - ₹28L a year
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
A stored key is valid for years and works from anywhere if it leaks. With OIDC, each job asks AWS for credentials that last about an hour and only work for the repository and branch you trust, so there is nothing long lived to steal.
A version tag is a movable pointer, and attackers have rewritten tags to point at malicious code. A full commit SHA is immutable, so the code you reviewed is the code that runs.
Only if it never runs code from the pull request. It runs with the base repository's secrets and write token, so checking out and running a fork's code in that trigger is a well known way to leak secrets.
GitHub Secrets is fine for a few static values. Vault pays off when you need dynamic, short lived credentials, central policy, and an audit trail of every read across many pipelines.