Los pipelines de CI/CD necesitan secretos (claves API, credenciales de despliegue, contraseñas de base de datos, tokens) para compilar e implementar — pero manejarlos de forma insegura es un riesgo serio. El manejo adecuado de secretos mantiene las credenciales seguras en todo el pipeline.
Por qué es importante
Pipelines need credentials, but secrets are a major security risk if mishandled:
⚠️ NEVER hardcode secrets in code, pipeline config files, or commit them to Git
(committed secrets are exposed in history — even if "removed" later)
⚠️ NEVER print secrets in logs (pipeline logs may be visible/stored)
→ Leaked CI/CD secrets (deploy keys, cloud credentials) can compromise entire systems.
