|
|
|
|
|
by ownagefool
16 hours ago
|
|
This is correct, but there's additional nuance here, which is the security of your development pipeline plays a part in the production system too. Way back when, you'd see a lot of people stuff their jenkins in their dev account. There's no way that the system that builds, publishes and deploys your application should be treated as anything but as sensitive as the production system itself. ( To be fair there are mitigations such as reproducible builds, but you're now doing a bunch of engineering to tie in your deploy system. ) |
|