Secure
Overview
Finding and fixing security issues before they become incidents.
Cloud Native
- GKE Cluster Configuration — Private GKE cluster setup, Workload Identity…
- GKE Security Hardening Guide — GKE security hardening guide with Pulumi.
- IAM Configuration — Least-privilege IAM roles for GKE nodes…
- Network Security — Secure GKE networking with VPC-native IP…
- Runtime Security — Pod Security Standards and admission controllers…
- Workload Identity Federation Implementation — Workload Identity Federation implementation guide.
GitHub Actions Security Patterns Hub
Complete security patterns for GitHub Actions…
- Action Pinning Overview — Why pinning GitHub Actions to SHA-256…
- Complete Workflow Examples — Copy-paste hardened CI/CD workflows with SHA-pinned…
- Environment Protection Patterns — Deployment protection with environment protection rules…
- Ephemeral Runner Patterns — Disposable runner patterns for GitHub Actions.
- GITHUB_TOKEN Permissions Overview — Understanding GITHUB_TOKEN scope, default permissions, and…
- GitHub Actions Security Cheat Sheet — Quick reference for GitHub Actions security…
- Hardened CI Workflow — Production-ready CI workflow examples with all…
- Hardened Deployment Workflow — Production-ready deployment workflow examples with OIDC…
- Hardened Release Workflow — Production-ready release workflow examples with signed…
- OIDC Federation Patterns — Secretless authentication to cloud providers using…
- Reusable Workflow Security — Secure reusable workflow patterns for GitHub…
- Runner Group Management — Runner group organization strategies for GitHub…
- Secret Management Overview — Understanding GitHub Actions secret types, storage…
- Secret Rotation Patterns — Automated secret rotation for GitHub Actions.
- Secret Scanning Integration — GitHub secret scanning configuration, push protection…
- Security Scanning Workflows — Comprehensive security scanning examples with SAST…
- Self-Hosted Runner Hardening — Comprehensive hardening steps for self-hosted GitHub…
- Self-Hosted Runner Security Overview — Understanding the threat model for self-hosted…
- Third-Party Action Risk Assessment — Structured framework for evaluating GitHub Actions…
- Workflow Trigger Security — Secure GitHub Actions trigger patterns for…
GitHub Core App Setup
Configure organization-level GitHub Apps for secure…
- Storing Credentials — Securely store GitHub App credentials across…
Go Security Tooling
Standard Go security toolkit: race detector…
OpenSSF Scorecard Achievement Guide
Complete OpenSSF Scorecard achievement guide.
Risk Management
- Risk Prioritization Framework for Engineers — Risk prioritization framework for engineers.
Full Reference
Full text: reference.md. Raw sources: library/. Live: docs.