Join our Newsletter — 33% off our NHI Course

Securing CI/CD Pipelines With OIDC: Step-by-Step Tutorial

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: GitGuardian’s analysis of CircleCI’s breach shows how CI/CD platforms can concentrate secrets, making stored passwords, embedded keys, and ad hoc secret handling a single compromise point. The practical shift is toward ephemeral access, external secret retrieval, and trust boundaries that do not rely on pipeline-stored credentials.

Editorial analysis by NHI Mgmt Group, based on content published by GitGuardian: “Securing your CI/CD: an OIDC Tutorial”.

Key questions

Q: What breaks when CI/CD pipelines rely on static secrets?

A: Static secrets create a reusable attack path into production infrastructure.

Q: Why do long-lived credentials increase risk in modern build and deployment pipelines?

A: Long-lived credentials increase risk because they can be stolen, replayed, and reused across the build path after initial compromise.

Q: How do security teams know whether OIDC is actually reducing CI/CD risk?

A: OIDC is working when workflows use short-lived tokens, the target system validates claims such as audience and repository, and no reusable secrets remain in contexts or environment variables.

Practitioner guidance

  • Replace static CI/CD credentials with OIDC federation Use claim-bound, short-lived tokens for cloud and service access instead of storing reusable passwords or keys in pipelines.
  • Move secrets out of pipeline storage Store credentials in a dedicated secrets manager and let workflows retrieve them at runtime rather than through project variables or contexts.
  • Constrain token trust with repository and audience claims Bind each workflow identity to the smallest practical scope so only the intended repo, job, and environment can assume access.

Bottom line: CI/CD secret exposure is dangerous because the build system can become a single point of compromise for many downstream credentials.

What's in the full article

GitGuardian's full article covers the implementation detail this post intentionally leaves for the source:

  • Step-by-step OIDC configuration for GitHub Actions and AWS.
  • Vault JWT auth setup with bound claims for repository-scoped access.
  • Hands-on workflow examples that retrieve secrets without embedding passwords in CI/CD.
  • Command-level examples for creating and validating Vault secrets and roles.

👉 Read GitGuardian's analysis of CI/CD secret exposure and OIDC controls →

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 10 months ago by GitGuardian
This topic was modified 10 months ago by Abdelrahman
This topic was modified 4 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21545
 

CI/CD secret storage is an identity governance failure, not just a tooling issue: when pipelines hold reusable credentials, the platform becomes part of the trust boundary for every system it can reach. That creates a concentration problem for NHI governance because the same secret may authenticate builds, deployments, and cloud actions. The practitioner conclusion is simple: if the CI/CD system is breached, the credential estate is already overexposed.

A few things that frame the scale:

  • 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
  • 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.

A question worth separating out:

Q: What should teams do first after discovering that a CI pipeline may have exposed secrets?

A: The first response is to revoke and reissue any credentials, tokens, or keys that may have been exposed in the affected CI process. Teams should also verify the authenticity of build scripts and review repositories, docker images, and pipeline logs for hard coded secrets. Rapid secret rotation reduces the window for reuse while investigation continues.

👉 Read our full editorial: CI/CD secret exposure shows why OIDC beats long-lived credentials



   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.