Teastaíonn rúndiamhair (eochracha API, dintiúir imshuites, focail fhaire bunachair, comharthaí) ó phíopaláin CI/CD chun a thógáil agus a imshuiteoir — ach is riocht an-gheal a bheith á láimhseáil go míthuisceanach. Coimeádann bainistíochta rúndiamhair cearta slán trí fhad an phíopalain.
An fhadhb: ní foláir go bhforbair rúndiamhair a nochtadh riamh
Pipelines need credentials, but secrets are a major security risk if mishandled:
⚠️ NEVER hardcode secrets in code, pipeline config files, or commit them to Git
(committed secrets are exposed in history — even if "removed" later)
⚠️ NEVER print secrets in logs (pipeline logs may be visible/stored)
→ Leaked CI/CD secrets (deploy keys, cloud credentials) can compromise entire systems.
