Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD
Fuente:
arXiv
Saved in:
| Main Author: | |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866916699126628352 |
|---|---|
| author | Avirneni, Surya Teja |
| author_facet | Avirneni, Surya Teja |
| contents | Credential brokers offer a way to separate identity from access in CI/CD systems. This paper shows how verifiable identities issued at runtime, such as those from SPIFFE, can be used with brokers to enable short-lived, policy-driven credentials for pipelines and workloads. We walk through practical design patterns, including brokers that issue tokens just in time, apply access policies, and operate across trust domains. These ideas help reduce static permissions, improve auditability, and support Zero Trust goals in deployment workflows. This is the second paper in a three-part series on secure CI/CD identity architecture. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2504_14761 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD Avirneni, Surya Teja Cryptography and Security Software Engineering Credential brokers offer a way to separate identity from access in CI/CD systems. This paper shows how verifiable identities issued at runtime, such as those from SPIFFE, can be used with brokers to enable short-lived, policy-driven credentials for pipelines and workloads. We walk through practical design patterns, including brokers that issue tokens just in time, apply access policies, and operate across trust domains. These ideas help reduce static permissions, improve auditability, and support Zero Trust goals in deployment workflows. This is the second paper in a three-part series on secure CI/CD identity architecture. |
| title | Decoupling Identity from Access: Credential Broker Patterns for Secure CI/CD |
| topic | Cryptography and Security Software Engineering |
| url | https://arxiv.org/abs/2504.14761 |