Beaver Duty

Beaver Duty

Logs of Duty: Zero Trust (except for the CI)

Lock down your engineers. Leave the pipeline wide open.

Matt's avatar
Matt
Aug 11, 2025
∙ Paid

Rule #1: Enforce MFA everywhere, except for CI service accounts. Humans must rotate passwords every 30 days. Meanwhile, your CI pipeline logs in as root using an unencrypted secret last updated five years ago.

Rule #2: Don’t give developers prod access. They can’t SSH into production. But their YAML files on their CIs can still delete all your VMs. That’…

User's avatar

Continue reading this post for free, courtesy of Matt.

Or purchase a paid subscription.
© 2026 Matt · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture