Pipelines that reach what they must — and nothing else. Ephemeral identities, private deploy targets, zero credential sprawl.
Deploy keys, cloud credentials, and tokens stored in CI variables live for years and get copied into forks.
The runner sits where it can reach everything — so a compromised dependency can too.
When ten pipelines share one service account, audit logs can't say which job touched production.
Each job joins the tailnet with a short-lived, pre-authenticated key. It expires when the job ends — nothing to rotate or leak.
The frontend pipeline reaches the CDN API; the database migration job reaches the DB. Neither can touch the other's targets.
Staging and production keep private endpoints. Runners connect as tailnet peers — no public ingress for robots.
GitHub Actions, GitLab CI, and Jenkins orbs/actions generate and use ephemeral keys automatically.
Flow logs record which pipeline identity connected where — attribution by construction.
Runners in your account, your VPC, or a homelab — the control plane stays ours, the compute stays yours.