Home / Companies / Blacksmith / Blog / January 2025

January 2025 Summaries

1 posts from Blacksmith

Filter
Month: Year:
Post Summaries Back to Blog
GitHub Actions secrets are encrypted variables used to protect sensitive CI/CD data such as API keys, tokens, and database credentials, with repository, environment, and organization scopes offering different levels of access and control. GitHub encrypts secrets, decrypts them only during relevant workflow runs, applies precedence rules across scopes, and masks known secret values in logs, though derived, encoded, or dynamically generated values may still require additional protection. Recommended practices include enforcing least-privilege access, using protected environments with reviewer approvals and branch restrictions for production deployments, auditing access regularly, adopting consistent descriptive naming, avoiding hardcoded credentials, and using secret-scanning tools. The text highlights OpenID Connect as a safer alternative to long-lived cloud credentials because it exchanges workflow-specific identity tokens for short-lived permissions, while also recommending regular credential rotation and incident-response drills. For larger or multi-platform deployments, external secret-management systems such as HashiCorp Vault, Infisical, and Doppler can provide centralized control, automated rotation, detailed auditing, and more granular access policies.
Jan 15, 2025 1,984 words in the original blog post.