Building a Zero Trust Service for CI/CD Pipelines
Blog post from Harness
In response to the increasing threat of security breaches in CI/CD pipelines, such as the SolarWinds and Codecov incidents, Harness developed the Zero Trust Service (ZTS) to enhance security by verifying every task before execution. This customer-controlled authorization layer intercepts tasks, evaluates them through a chain of policy validators, and decides whether to allow or deny execution, thereby addressing the gap in traditional defenses that operate at the control plane level. ZTS is built to integrate seamlessly with existing security frameworks and tools, offering extensibility through pluggable interfaces and observability via Prometheus metrics, all while ensuring compliance with regulatory standards like NIST SP 800-218. By running alongside Delegates in customer infrastructure, ZTS provides a robust security mechanism that protects against malicious pipeline modifications, maintaining the integrity of CI/CD operations.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Zero Trust | 7 | 227 | 74 | 28 | +13% |
| Secrets Management | 4 | 2,472 | 449 | 128 | -3% |
| AI Agents | 3 | 5,949 | 1,325 | 249 | -4% |
| Kubernetes | 3 | 2,550 | 356 | 111 | +22% |
| Observability | 3 | 3,826 | 727 | 190 | -10% |
| MCP | 2 | 7,781 | 805 | 204 | +0% |
| Platform Engineering | 2 | 1,257 | 305 | 77 | -22% |
| LLM | 1 | 7,115 | 1,261 | 236 | +13% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.