DevSecOpsGitHub ActionsCI/CDCloud Security
Hardening GitHub Actions CI/CD for Production Workloads
A practical guide to securing GitHub Actions workflows: OIDC token authentication, pinned SHAs, least-privilege permissions, and secret management.
CI/CD pipelines have become one of the most targeted vectors in modern software supply-chain attacks. When attackers gain execution privileges inside an automated runner, they can exfiltrate production secrets, tamper with release artifacts, or inject malicious dependencies.
1. Eliminate Long-Lived Cloud Credentials with OIDC
Rather than storing long-lived AWS_SECRET_ACCESS_KEY credentials in repository secrets, use OpenID Connect (OIDC) to federate directly with cloud IAM:
permissions:
id-token: write # Required for requesting the JWT
contents: read
steps:
- name: Configure AWS Credentials via OIDC
uses: aws-actions/configure-aws-credentials@v4
with:
role-to-assume: arn:aws:iam::123456789012:role/GitHubActionsDeploymentRole
aws-region: us-east-1
2. Restrict Runner GITHUB_TOKEN Permissions
By default, jobs should inherit only read permissions. Explicitly grant write access only to the scopes strictly required:
# Global default at top of workflow
permissions: {}
jobs:
build:
permissions:
contents: read
packages: write