5 ms·
Install scripts typically have access to build environments.
by burnthrow 6y ago
Install scripts typically have access to build environments.
- deleted 6y ago[deleted]
- jessaustin 6y agoOf course you're right in many situations, but in general secrets should not be allowed in build environments. If one doesn't expend the effort to limit permissions in the production environment, however, it's no different.
- paledot 6y agoDatabase credentials hopefully not, but the build environment will almost certainly have access to a private git repo somewhere.
- dtech 6y agoI've never seen a CI/CD without secrets, how else are you going to access private repos, access some live dependency during e2e testing or deploy the binary to its target?
- enigmo 6y agoI've used multiple that run the build in a sandbox without secrets. One of them didn't even mount in the .git directory, it just propagated some commit info via environment variables. I also like to split the publishing of artifacts from the deployment process to make sure it's repeatable. This also ensures that the CI pipeline doesn't have direct access to production.
- plorkyeran 6y agoYou isolate the stages which require secrets from the stages that run untrusted code. One step has access to your SSH private key and runs git clone. The next step runs the actual build without access to any secrets. A third step has access to the secret key required to publish the result. It's certainly more complicated to set up than a simple "the CI system invokes a single shell script that does everything" build, but it's not actually that complicated and every CI system I've used has supported doing this.
- IshKebab 6y agoYeah I've never seen anyone go to that much effort in practice.