Gitea Actions Runner Security: Isolate act Runner Jobs and Scope Their Tokens
Design Gitea Actions around runner trust, container and host boundaries, ephemeral execution, GITEA_TOKEN permissions, and safe action dependencies.
tag
15 posts
Design Gitea Actions around runner trust, container and host boundaries, ephemeral execution, GITEA_TOKEN permissions, and safe action dependencies.
Deploy a static site to GitHub Pages through an explicit build artifact and deployment job, with correct permissions, environments, and failure diagnostics.
Compare Hugo and Zola through configuration, templates, output directories, preview URLs, version pinning, and safe artifact promotion, not speed slogans.
Build a Trivy workflow that scans dependencies and final images, records scanner inputs, and triages CVEs without treating findings as proof of exploitability.
Design Actions caches as untrusted build inputs, separate fork and release trust, avoid secret leakage, and validate restore-key behavior before promotion.
Build safer self-hosted Actions capacity with one-job ephemeral runners, scoped runner groups, external log retention, and autoscaling failure controls.
Federate GitLab CI jobs to AWS with short-lived OIDC credentials, narrowly scoped IAM trust, protected deployment rules, and auditable role sessions.
Build reusable GitLab CI components with validated inputs, collision-safe jobs, deliberate version pins, and tests that catch breaking pipeline changes.
Design GitLab CI DAGs that avoid duplicate pipelines, transfer explicit artifacts, and serialize production deployments without hiding release races.
Protect production deployments in GitLab with explicit environment declarations, authorized deployers, approval rules, serialized jobs, and audit-ready controls.
Keep Jenkins Pipelines recoverable and scalable by separating controller orchestration from agent work and choosing durability settings by job criticality.
Build, test, distribute, and promote Packer machine images with pinned inputs, launch checks, regional validation, and an auditable rollback path.
Control GitHub Actions job overlap, pending-run replacement, and deployment queues with precise concurrency groups, cancellation rules, and safe workflow design.
Use .terraform.lock.hcl to pin provider selections, verify checksums, review upgrades, and keep plans consistent across CI and developer machines.
Build repeatable Terraform module tests with plan and apply runs, provider mocks, input matrices, assertions, and explicit controls for real infrastructure.