Hacker News new | ask | show | jobs
by twistedpair 1727 days ago
I've been eyeing this for a while. My biggest hangup is that CI/CD is a major attack (e.g. supply chain) vector. If you use CI/CD for deploys, then a lot of highly privileged creds are in play.

I'd really prefer if GH made and managed the K8s operator (e.g. the most popular infra provisioning tool) themselves.