Secrets in CI: Workflow and infrastructure
Binds CI jobs to cloud roles through OIDC, forbids long-lived PATs in logs and artifacts, locks secrets to protected environments, and isolates fork pull requests from production credentials.
Defines zero-downtime secret rotation by publishing a new secret under a key identifier, dual-accepting old and new material during a measured grace window, and revoking the old secret only after observed coverage.