Intent-Aware Authorization for Zero Trust CI/CD

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
1. Verfasser: Avirneni, Surya Teja
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866912337958535168
author Avirneni, Surya Teja
author_facet Avirneni, Surya Teja
contents This paper introduces intent-aware authorization for Zero Trust CI/CD systems. Identity establishes who is making the request, but additional signals are required to decide whether access should be granted. We describe a control loop architecture where policy engines such as OPA and Cedar evaluate runtime context, justification, and human approvals before issuing access credentials. The system builds on SPIFFE-based workload identity and credential brokers, and enables fine-grained, auditable authorization. This is the third paper in a series on Zero Trust CI/CD design patterns.
format Preprint
id arxiv_https___arxiv_org_abs_2504_14777
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Intent-Aware Authorization for Zero Trust CI/CD
Avirneni, Surya Teja
Cryptography and Security
Software Engineering
This paper introduces intent-aware authorization for Zero Trust CI/CD systems. Identity establishes who is making the request, but additional signals are required to decide whether access should be granted. We describe a control loop architecture where policy engines such as OPA and Cedar evaluate runtime context, justification, and human approvals before issuing access credentials. The system builds on SPIFFE-based workload identity and credential brokers, and enables fine-grained, auditable authorization. This is the third paper in a series on Zero Trust CI/CD design patterns.
title Intent-Aware Authorization for Zero Trust CI/CD
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2504.14777