Susheel Thapa
Skip to content
>_ST
DevSecOpsGitHub ActionsCI/CDCloud Security

Hardening GitHub Actions CI/CD for Production Workloads

A practical guide to securing GitHub Actions workflows: OIDC token authentication, pinned SHAs, least-privilege permissions, and secret management.

CI/CD pipelines have become one of the most targeted vectors in modern software supply-chain attacks. When attackers gain execution privileges inside an automated runner, they can exfiltrate production secrets, tamper with release artifacts, or inject malicious dependencies.

1. Eliminate Long-Lived Cloud Credentials with OIDC

Rather than storing long-lived AWS_SECRET_ACCESS_KEY credentials in repository secrets, use OpenID Connect (OIDC) to federate directly with cloud IAM:

permissions:
  id-token: write # Required for requesting the JWT
  contents: read

steps:
  - name: Configure AWS Credentials via OIDC
    uses: aws-actions/configure-aws-credentials@v4
    with:
      role-to-assume: arn:aws:iam::123456789012:role/GitHubActionsDeploymentRole
      aws-region: us-east-1

2. Restrict Runner GITHUB_TOKEN Permissions

By default, jobs should inherit only read permissions. Explicitly grant write access only to the scopes strictly required:

# Global default at top of workflow
permissions: {}

jobs:
  build:
    permissions:
      contents: read
      packages: write