TL;DR: CI/CD pipelines concentrate secrets because they gate production access, scale automation, and influence engineering practice, according to Defakto Security, while GitGuardian data shows leaked secrets rose by 23 million from 2023 to 2024 and 70% of 2022 leaks remained active in 2025. The real control problem is treating long-lived secrets as governable once pipelines become the access layer for everything else.
At a glance
What this is: This is a viewpoint piece on why CI/CD pipelines have become the strategic control point for secrets sprawl, with the central finding that pipelines concentrate authentication risk and amplify the spread of long-lived secrets.
Why it matters: It matters because CI/CD is where many teams can most quickly reduce NHI exposure, remove standing credential dependencies, and change how production access is governed across engineering groups.
By the numbers:
- The number of leaked secrets increased by 23 million from 2023 to 2024.
- 70% of leaked secrets detected in 2022 remain active in 2025.
Context
CI/CD pipelines are the operational layer where software changes are built, tested, and promoted into production, which also makes them the place where many secrets are consumed and reused. When those pipelines rely on API keys, passwords, and other long-lived credentials, the governance problem shifts from isolated secret storage to control over the access path itself.
The article's core claim is that secrets sprawl is not just a storage issue but an architectural one. CI/CD systems are central to NHI governance because they link deployment automation, infrastructure access, and shared engineering practice, so any weakness there multiplies across teams and environments.
Key questions
Q: What breaks when CI/CD pipelines rely on static secrets?
A: Static secrets create a reusable attack path into production infrastructure. Once they are copied into workflow files, logs, runner images, or environment variables, a single compromise can expose broad access long after the original job finishes. That is why pipeline secrets should be treated as production identity, not temporary configuration.
Q: Why do CI/CD pipelines create secret governance risk?
A: Because they combine stored credentials, automated execution, and broad operational access in one place. If a pipeline can read a secret and use it to perform a privileged action, the secret becomes a standing access path. That risk grows when variables, logs, artifacts, or runner environments expose the credential beyond the intended job.
Q: How do teams know whether secret sprawl is getting better?
A: Look for fewer static credentials in pipelines, less secret reuse across jobs, and a shrinking set of exceptions that still require manual handling. If a team merely moves secrets into a vault but keeps the same runtime dependency, the risk has not materially changed. The signal of improvement is removal, not relocation.
Q: Should organisations prioritise pipeline identity before broader secrets cleanup?
A: Yes, when CI/CD is the gateway to production, because changes there affect many downstream teams at once. Fixing pipeline identity first gives faster risk reduction than chasing individual leaked secrets one by one. That sequencing is especially useful where platform teams can enforce one pattern centrally.
Technical breakdown
Why CI/CD becomes the secrets control point
CI/CD pipelines sit between code change and production access, so they often need credentials for cloud APIs, deployment targets, artifact stores, and configuration systems. That puts them in the middle of authentication for both humans and non-human identities. When a pipeline uses long-lived secrets, the secret becomes the access layer, not just a stored credential. In NHI terms, the pipeline is acting as a credential broker for deployment work, which makes inventory, rotation, and offboarding more complex because the same secret may be shared across jobs, teams, or environments.
Practical implication: treat CI/CD as an access governance tier, not a storage location.
Why secret managers reduce exposure but do not remove it
Secret managers centralise storage, but they do not eliminate the dependency on secrets inside the delivery path. If the pipeline still retrieves, injects, or passes credentials at runtime, the trust model still depends on the secret existing and remaining valid. This creates a second-order problem: teams often solve sprawl by moving secrets into another system, then inherit new exposure points, operational latency, and blast radius if the manager is compromised. The control issue is not just where the secret sits, but whether the workflow still requires a static credential at all.
Practical implication: use secret managers as containment, not as the endpoint of the governance model.
How identity-first pipelines replace static credentials
Identity-first infrastructure changes the pipeline from a secret holder to an identity consumer. Instead of storing a reusable API key or password, the job authenticates with a pipeline identity and receives short-lived, scoped credentials or attested access for the task at hand. This aligns better with Zero Standing Privilege because access is issued for execution, not kept indefinitely. The technical shift matters because it reduces the number of secrets that can leak, narrows the lifetime of any credential, and makes access decisions more directly tied to the workload or action that needs them.
Practical implication: replace static secrets with short-lived, task-scoped identities wherever the pipeline supports it.
Threat narrative
Attacker objective: The attacker wants durable access to production-adjacent systems so they can steal more secrets, alter deployments, or move laterally through the delivery chain.
- Entry occurs when attackers obtain a reusable secret from a pipeline, repository, configuration file, or related automation path.
- Escalation follows when that secret grants access to deployment systems, cloud APIs, or production resources that were supposed to be tightly controlled.
- Impact is broad because one compromised pipeline credential can expose multiple environments, teams, and downstream services through shared automation.
Breaches seen in the wild
- tj-actions/changed-files compromise 2025: A stolen bot token let attackers poison tj-actions/changed-files so pipelines printed their CI/CD secrets to public logs (CVE-2025-30066).
- CircleCI breach 2023: Malware stole a CircleCI engineer's SSO session; attackers exfiltrated customers' CI/CD secrets and keys, forcing a platform-wide rotation.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
CI/CD is the secrets governance choke point: Secrets sprawl becomes operationally material when pipelines are the place where access begins, not just where credentials are stored. That makes the pipeline the most efficient place to discover, constrain, and phase out long-lived secrets. For identity teams, the strategic question is not how to manage every leaked secret equally, but where a single control point can reshape the largest share of access behaviour.
Secret managers are a containment layer, not a lifecycle answer: Centralised vaulting reduces chaos, but it does not change the fact that reusable secrets still exist, circulate, and expire outside the vault boundary. The governance gap is lifecycle fragmentation, where provisioning, use, rotation, and revocation are handled as separate concerns. Practitioners should read that as a signal that the control plane needs to move closer to issuance, not just storage.
Long-lived credential dependency is the real architectural liability: The article correctly treats static API keys and passwords as the lowest common denominator of application authentication, and that denominator gets worse as AI integrations add more machine-to-machine access. This is where CI/CD governance connects NHI and application security: once the pipeline becomes the default trust broker, every new integration inherits the same fragile secret model unless the identity layer changes.
Identity-first delivery changes culture as well as control: The strongest point in the article is that engineering practice follows pipeline defaults. When the delivery system uses dynamic identities, teams stop normalising static secret reuse and start treating ephemeral access as the baseline. That makes CI/CD not only a technical enforcement point but also the place where access culture is reset for the wider programme.
Strategic control point, not tactical cleanup: Organisations that start with CI/CD are choosing leverage over volume. That is the right lens for NHI governance because the goal is to reduce the number of secrets that can exist in the first place, then govern the remainder with clear lifecycle ownership. Practitioners should prioritise the gateway where access is granted, because that is where reduction compounds fastest.
From our research library:
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
- Read next: Ultimate Guide to NHIs — Static vs Dynamic Secrets
What this signals
Pipeline identity is becoming the practical substitute for static secret governance: When CI/CD systems are the access layer, the programme question changes from how to store secrets more safely to how to issue access without leaving reusable credentials behind. That shift matters because it brings NHI governance into the same control plane as deployment, where leverage is highest. Teams that still treat pipeline secrets as a local engineering issue will keep rediscovering the same exposure patterns.
Secrets sprawl is now an identity architecture problem, not a vaulting problem: A vault can reduce visibility gaps, but it cannot by itself remove the runtime dependence on long-lived credentials. The stronger programme signal is whether pipeline workflows are moving toward short-lived, task-scoped access and away from shared tokens. That is the distinction between containing sprawl and eliminating the conditions that create it.
For practitioners
- Audit CI/CD secret dependencies Map every pipeline, runner, and deployment action that still depends on API keys, passwords, or shared tokens so you can see where static credentials remain part of the delivery path.
- Replace reusable credentials with short-lived identities Move pipelines toward task-scoped identities and attested access so the pipeline requests what it needs at execution time instead of storing secrets for reuse.
- Centralise pipeline identity governance Define one policy for how CI/CD identities are issued, scoped, reviewed, and revoked across teams so platform teams can roll out changes consistently.
- Use secret managers as a transitional control Keep secret managers for residual credentials that cannot yet be removed, but set a retirement path for any secret that still lives in code, config files, or CI/CD tools.
Key takeaways
- CI/CD pipelines are where secrets concentrate because they connect code changes to production access and shared automation.
- Moving secrets into a manager helps with containment, but it does not eliminate the architectural dependence on reusable credentials.
- The most effective control move is to replace long-lived pipeline secrets with short-lived identities and centralised governance over issuance and revocation.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-02 — Secret Leakage | The article centres on secrets leaking and spreading through CI/CD pipelines. |
| NHI-07 — Long-Lived Secrets | The core argument is that reusable pipeline secrets create ongoing risk. | |
| NHI-05 — Overprivileged NHI | Pipeline credentials often accumulate broader access than the job actually needs. | |
| Recommendation — Scan CI/CD paths for exposed secrets and remove any credential that appears in code, logs, or configuration. Replace long-lived CI/CD secrets with short-lived credentials and retire static credentials wherever possible. Right-size pipeline entitlements so each workflow has only the permissions required for its task. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Authenticator lifecycle management directly applies to pipeline secrets and tokens. |
| Recommendation — Apply IA-5 to govern issuance, rotation, and revocation of CI/CD authenticators. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article describes how stolen pipeline secrets can lead to broader access and movement. |
| Recommendation — Map pipeline secret exposure to credential access and lateral movement in detection and response planning. | ||
Key terms
- CI/CD Pipeline Identity: The machine identity used by continuous integration and deployment systems to authenticate to code repositories, registries, and cloud environments during automated build and deployment.
- Secrets Sprawl: The uncontrolled proliferation of sensitive credentials, API keys, tokens, passwords, certificates, across codebases, cloud environments, CI/CD pipelines, and configuration files. In 2024, over 50 million leaked secrets were found on the dark web.
- Identity-First Infrastructure: An approach that replaces long-lived shared secrets with runtime identity and short-lived credentials. For CI/CD, it means systems authenticate through attested identity instead of copied values that can leak, linger, or be reused outside their intended purpose.
- Long-Lived Secret: A long-lived secret is a credential, token, API key, or certificate that remains valid for an extended period without frequent renewal. In NHI environments, it creates durable exposure because one leaked secret can keep granting access long after the original use case has changed.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on June 24, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org