Zero trust in cloud infrastructure: Implementing secure CI/CD Pipelines

Kadulla, Sumanth (2025) Zero trust in cloud infrastructure: Implementing secure CI/CD Pipelines. World Journal of Advanced Research and Reviews, 26 (2). pp. 450-457. ISSN 2581-9615

[thumbnail of WJARR-2025-1662.pdf] Article PDF
WJARR-2025-1662.pdf - Published Version
Available under License Creative Commons Attribution Non-commercial Share Alike.

Download ( 512kB)

Abstract

Zero Trust architecture represents a fundamental shift in securing cloud infrastructure, particularly within CI/CD pipelines where traditional perimeter-based security approaches increasingly fail against sophisticated threats. This technical article explores how implementing Zero Trust principles—"never trust, always verify"—creates robust protection throughout the software delivery lifecycle. The implementation spans across multiple dimensions: securing modern CI/CD tools including GitHub Actions, Azure DevOps, and GitLab; establishing comprehensive identity and access management with just-in-time privileged access; leveraging PowerShell for security automation; and ensuring robust container security across Docker and Kubernetes environments. Each dimension contributes to a defense-in-depth strategy that addresses the unique challenges of cloud-native environments. The article demonstrates how explicit verification of all access requests, regardless of origin, combined with fine-grained permissions, continuous monitoring, and automated compliance validation creates significantly enhanced security postures. For organizations undergoing digital transformation with automated software delivery pipelines, adopting these Zero Trust methodologies ensures application integrity throughout the development lifecycle while maintaining the agility benefits that make cloud environments valuable in the first place.

Item Type: Article
Official URL: https://doi.org/10.30574/wjarr.2025.26.2.1662
Uncontrolled Keywords: Zero Trust Architecture; CI/CD Security; Cloud Infrastructure; Container Orchestration; Identity Management
Depositing User: Editor WJARR
Date Deposited: 27 Jul 2025 15:29
Related URLs:
URI: https://eprint.scholarsrepository.com/id/eprint/2562