CI Secrets: From Masked Variables to OIDC Identity
How CI secrets leak from a masked variable, why masking isn't a security boundary, and how OIDC federation replaces long-lived keys with short-lived tokens.
How CI secrets leak from a masked variable, why masking isn't a security boundary, and how OIDC federation replaces long-lived keys with short-lived tokens.
Comment un credential cloud dans la CI finit par fuiter, pourquoi masquer une variable n'est pas une frontière de sécurité, et ce que change l'identité fédérée.
Les Secrets Kubernetes sont du base64, pas du chiffrement. Comment Sealed Secrets rend un manifeste committable, quand Vault vaut son coût, comment choisir.
Kubernetes Secrets are base64, not encryption. How Sealed Secrets make manifests git-safe, when external Vault earns its cost, and how to choose.