Intent-Aware Authorization for Zero Trust CI/CD
Fuente:
arXiv
Gespeichert in:
| 1. Verfasser: | |
|---|---|
| Format: | Preprint |
| Veröffentlicht: |
2025
|
| Schlagworte: | |
| Online-Zugang: | |
| Tags: |
Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
|
| _version_ | 1866912337958535168 |
|---|---|
| author | Avirneni, Surya Teja |
| author_facet | Avirneni, Surya Teja |
| contents | This paper introduces intent-aware authorization for Zero Trust CI/CD systems. Identity establishes who is making the request, but additional signals are required to decide whether access should be granted. We describe a control loop architecture where policy engines such as OPA and Cedar evaluate runtime context, justification, and human approvals before issuing access credentials. The system builds on SPIFFE-based workload identity and credential brokers, and enables fine-grained, auditable authorization. This is the third paper in a series on Zero Trust CI/CD design patterns. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2504_14777 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Intent-Aware Authorization for Zero Trust CI/CD Avirneni, Surya Teja Cryptography and Security Software Engineering This paper introduces intent-aware authorization for Zero Trust CI/CD systems. Identity establishes who is making the request, but additional signals are required to decide whether access should be granted. We describe a control loop architecture where policy engines such as OPA and Cedar evaluate runtime context, justification, and human approvals before issuing access credentials. The system builds on SPIFFE-based workload identity and credential brokers, and enables fine-grained, auditable authorization. This is the third paper in a series on Zero Trust CI/CD design patterns. |
| title | Intent-Aware Authorization for Zero Trust CI/CD |
| topic | Cryptography and Security Software Engineering |
| url | https://arxiv.org/abs/2504.14777 |