Step 1Map the line
Repos, workflows, runners, secrets and deploy targets.
ATALAIALet's list every workflow, runner and secret first.
PLATFORM23 workflows, two shared runners, and secrets in every repo.
Leaves the roomMap: 23 workflows, 4 runners, 31 secrets
Step 2Follow the keys
Which step can reach which secret and which environment.
ATALAIAThis deploy token is visible to every job, tests included.
PLATFORMIt's one token for all environments. Easier to rotate.
ATALAIAAnd easier to steal. A test step can deploy to production.
Leaves the room1 token reaches prod from every job
Step 3Break it on paper
How a malicious PR, action or runner would move.
ATALAIAA fork PR runs on the shared runner, and the runner keeps its cache.
DEV LEADSo a malicious PR could poison the next build?
ATALAIAYes. And this action is pinned to a tag. Whoever owns it can move the tag.
Leaves the roomAttack path: fork PR → runner → prod
Step 4Harden the templates
Pinned actions, scoped tokens, ephemeral runners, protected workflows.
PLATFORMNew template: actions pinned by SHA, one token per environment.
ATALAIAEphemeral runners for forks, and CODEOWNERS on workflow files.
DEV LEADWe roll it out to the 23 repos, one PR each.
Leaves the roomTemplate: pinned SHAs, scoped tokens, ephemeral runners
- ATALAIA
- PLATFORM
- DEV LEAD
- DEVELOPER