Home / Companies / Harness / Blog / Post Details
Content Deep Dive

Building a Zero Trust Service for CI/CD Pipelines

Blog post from Harness

Post Details
Company
Date Published
Author
Rishabh Gupta All this author’s posts
Word Count
2,446
Company Posts That Month
40
Language
English
Hacker News Points
-
Post removed?
No
Summary

In response to the increasing threat of security breaches in CI/CD pipelines, such as the SolarWinds and Codecov incidents, Harness developed the Zero Trust Service (ZTS) to enhance security by verifying every task before execution. This customer-controlled authorization layer intercepts tasks, evaluates them through a chain of policy validators, and decides whether to allow or deny execution, thereby addressing the gap in traditional defenses that operate at the control plane level. ZTS is built to integrate seamlessly with existing security frameworks and tools, offering extensibility through pluggable interfaces and observability via Prometheus metrics, all while ensuring compliance with regulatory standards like NIST SP 800-218. By running alongside Delegates in customer infrastructure, ZTS provides a robust security mechanism that protects against malicious pipeline modifications, maintaining the integrity of CI/CD operations.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Zero Trust 7 227 74 28 +13%
Secrets Management 4 2,472 449 128 -3%
AI Agents 3 5,949 1,325 249 -4%
Kubernetes 3 2,550 356 111 +22%
Observability 3 3,826 727 190 -10%
MCP 2 7,781 805 204 +0%
Platform Engineering 2 1,257 305 77 -22%
LLM 1 7,115 1,261 236 +13%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.