This Q/A discussion was centred on CI/CD security practices, with a focus on GitHub Actions. Key points included the importance of securing workflows, limiting permissions, and managing secrets effectively. Concerns were raised about the default settings in GitHub for Teams, where any branch can access secrets, potentially leading to security issues. The conversation highlighted the need for better auditing, logging and monitoring of actions. As well as the application of having a "zero trust" mentality for anything coming into your pipeline. Using GitHub Enterprise was recommended for enhanced security, particularly for managing environments and protecting secrets. The group also discussed challenges with self-hosted runners and the complexity of securing roles in GitHub OIDC for use in AWS.
Cloud Posse holds public "Office Hours" every Wednesday at 11:30am PST to answer questions on all things related to DevOps, Terraform, Kubernetes, CICD. Basically, it's like an interactive "Lunch & Learn" session where we get together for about an hour and talk shop. These are totally free and just an opportunity to ask us (or our community of experts) any questions you may have.
You can register here: https://cloudposse.com/office-hours
Join the conversation:
https://slack.cloudposse.com/
Find out how we can help your company:
https://cloudposse.com/quiz
https://cloudposse.com/accelerate/
Learn more about Cloud Posse:
https://cloudposse.com
https://github.com/cloudposse
https://sweetops.com/
https://newsletter.cloudposse.com
https://podcast.cloudposse.com/
#officehours,#cloudposse,#sweetops,#devops,#sre,#terraform,#kubernetes,#aws