Introduction
The CI has access to the prod environment for one purpose: deploying new artifacts. That access must be scoped to deployment and locked for everything else. Even with properly isolated CI infrastructure, mistakes happen — a leak of its secrets must not become a jump from CI to prod.
Case …
Continue reading