Over-Permissioned CI/CD Role with Cross-Account Trust
- Business Impact
- A CI/CD role held broad administrative permissions and trusted an external account, allowing anyone who compromised the pipeline or the peer account to assume administrative access across production.
- Recommendation
- Scope the role to the minimum permissions required by the pipeline, tighten the trust policy with an external ID and source restrictions, and add monitoring for privileged role assumption.