Beaver Duty

Beaver Duty

Logs of Duty: Zero Trust (except for the CI)

Lock down your engineers. Leave the pipeline wide open.

Matt's avatar
Matt
Aug 11, 2025
∙ Paid
Share

Rule #1: Enforce MFA everywhere, except for CI service accounts. Humans must rotate passwords every 30 days. Meanwhile, your CI pipeline logs in as root using an unencrypted secret last updated five years ago.

Rule #2: Don’t give developers prod access. They can’t SSH into production. But their YAML files on their CIs can still delete all your VMs. That’…

This post is for paid subscribers

Already a paid subscriber? Sign in
© 2025 Matt
Privacy ∙ Terms ∙ Collection notice
Start writingGet the app
Substack is the home for great culture