{"id":14361,"date":"2025-12-17T12:02:25","date_gmt":"2025-12-17T06:32:25","guid":{"rendered":"https:\/\/www.youstable.com\/blog\/?p=14361"},"modified":"2026-09-07T11:13:53","modified_gmt":"2026-09-07T05:43:53","slug":"how-to-monitor-secure-ci-cd-on-linux","status":"publish","type":"post","link":"https:\/\/www.youstable.com\/blog\/how-to-monitor-secure-ci-cd-on-linux\/","title":{"rendered":"How to Monitor &#038; Secure CI\/CD on Linux Server"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">To monitor and secure CI\/CD on a Linux server, combine host hardening (SSH, firewall, MAC policies), rigorous pipeline controls (scanning, signing, provenance), and continuous observability (logs, metrics, and alerts). Use least-privileged, ephemeral runners, secrets management, and artifact integrity checks to reduce blast radius, detect anomalies quickly, and prevent supply chain attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Modern teams rely on Linux to run build agents, runners, and orchestrators. This guide explains how to monitor &amp; secure CI\/CD on Linux server with step-by-step hardening, practical monitoring, and pipeline-level controls. You\u2019ll learn what to watch, how to respond, and which guardrails stop lateral movement and supply chain threats before production.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"what-ci-cd-on-linux-really-involves-and-why-its-a-target\"><strong>What CI\/CD on Linux Really Involves (and Why It\u2019s a Target)<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">CI\/CD servers hold code, secrets, tokens, and direct pathways to registries and production. Attackers target them to inject malicious code, steal credentials, or tamper with artifacts. A secure setup demands two pillars: hardened <a href=\"https:\/\/www.youstable.com\/blog\/configure-mongodb-on-linux\/\">Linux hosts<\/a> and defensible pipelines with monitoring from kernel to artifact.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"threat-model-key-risks-to-address\"><strong>Threat Model: Key Risks to Address<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Secrets leakage: tokens, SSH keys, cloud credentials exposed in logs or environment variables.<\/li>\n\n\n\n<li>Runner compromise: long-lived, privileged runners abused for lateral movement.<\/li>\n\n\n\n<li>Dependency and supply chain attacks: malicious packages, tampered images, unverified artifacts.<\/li>\n\n\n\n<li>Artifact integrity loss: unsigned builds, missing provenance, weak promotion gates.<\/li>\n\n\n\n<li>Privilege escalation: sudo misconfigurations, broad container privileges, weak SELinux\/AppArmor policies.<\/li>\n\n\n\n<li>Network egress misuse: exfiltration to unknown IPs or C2 servers from build nodes.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"monitoring-foundations-for-linux-based-ci-cd\"><strong>Monitoring Foundations for Linux-Based CI\/CD<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Monitoring must capture system events, process behavior, network activity, application logs, and pipeline metadata. Aim for centralization, correlation, and actionable alerts\u2014not just dashboards.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"system-telemetry-auditd-journald-and-ebpf\"><strong>System Telemetry: auditd, journald, and eBPF<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>auditd: track file changes, sudo, and policy violations.<\/li>\n\n\n\n<li>journald\/rsyslog: centralize system and service logs.<\/li>\n\n\n\n<li>eBPF\/Falco: detect suspicious runtime behavior (privileged containers, shell spawns from build tools).<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"metrics-and-traces-prometheus-and-exporters\"><strong>Metrics and Traces: Prometheus and Exporters<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Node Exporter: CPU, memory, disk, network baselines.<\/li>\n\n\n\n<li>Service exporters: Jenkins, GitLab Runner, or Kubernetes runners for job latency, queue lengths, failures.<\/li>\n\n\n\n<li>Grafana: build SLO dashboards (build success rate, time-to-merge, mean time to detect anomalies).<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"log-aggregation-and-siem\"><strong>Log Aggregation and SIEM<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Wazuh\/Elastic\/Splunk\/Graylog: centralize logs, correlate events, create alert rules.<\/li>\n\n\n\n<li>Forward runner\/job logs, authentication logs, registry events, and cloud audit trails for full context.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"hardening-the-linux-host-running-ci-cd\"><strong>Hardening the Linux Host Running CI\/CD<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"minimal-os-patching-and-services\"><strong>Minimal OS, Patching, and Services<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use a minimal Linux image; remove compilers and tools not needed by the runner.<\/li>\n\n\n\n<li>Enable automatic security updates and reboot strategies.<\/li>\n\n\n\n<li>Disable and mask unused services and sockets.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"ssh-and-network-lockdown\"><strong>SSH and Network Lockdown<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Key-only SSH, disable root login and passwords, use SSH CA or MFA where possible.<\/li>\n\n\n\n<li>Restrict ports with UFW\/nftables; limit egress to registries, VCS hosts, package mirrors.<\/li>\n\n\n\n<li>Enable fail2ban to block brute-force attempts.<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code># SSH hardening\nsudo sed -i 's\/^#?PasswordAuthentication.*\/PasswordAuthentication no\/' \/etc\/ssh\/sshd_config\nsudo sed -i 's\/^#?PermitRootLogin.*\/PermitRootLogin no\/' \/etc\/ssh\/sshd_config\necho \"AuthenticationMethods publickey\" | sudo tee -a \/etc\/ssh\/sshd_config\nsudo systemctl restart sshd\n\n# Basic firewall (UFW example)\nsudo ufw default deny incoming\nsudo ufw default allow outgoing\nsudo ufw allow OpenSSH\nsudo ufw enable\n\n# Fail2ban\nsudo apt-get update &amp;&amp; sudo apt-get install -y fail2ban\nsudo systemctl enable --now fail2ban\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"mandatory-access-control-and-sandboxing\"><strong>Mandatory Access Control and Sandboxing<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Enforce SELinux or AppArmor profiles for runners and build tools.<\/li>\n\n\n\n<li>Harden systemd units: restrict file system, network, capabilities, and set NoNewPrivileges.<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code># Example systemd hardening snippets for a runner service\n&#91;Service]\nNoNewPrivileges=yes\nPrivateTmp=yes\nProtectSystem=strict\nProtectHome=yes\nProtectKernelTunables=yes\nProtectControlGroups=yes\nCapabilityBoundingSet=\nRestrictSUIDSGID=yes\nRestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX\nSystemCallFilter=@system-service\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"least-privilege-and-filesystem-protections\"><strong>Least Privilege and Filesystem Protections<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create a dedicated system user for runners; avoid broad sudo privileges.<\/li>\n\n\n\n<li>Use mount options noexec, nosuid, nodev on temporary and workspace directories.<\/li>\n\n\n\n<li>Do not run Docker-in-Docker with privileged mode; prefer rootless Podman or isolated containers\/VMs.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"secrets-management\"><strong>Secrets Management<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Never store secrets in repos or plain environment variables.<\/li>\n\n\n\n<li>Use a vault (HashiCorp Vault, cloud secret stores) and short-lived tokens via OIDC.<\/li>\n\n\n\n<li>Scope credentials per project, branch, or environment; rotate automatically.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"securing-ci-cd-applications-jenkins-gitlab-github-actions-runners\"><strong>Securing CI\/CD Applications: Jenkins, GitLab, GitHub Actions Runners<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"jenkins-hardening\"><strong>Jenkins Hardening<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use Matrix-based security with SSO; disable the Script Console in production.<\/li>\n\n\n\n<li>Minimize and pin plugins; keep the core and plugins updated.<\/li>\n\n\n\n<li>Isolate agents with containers or dedicated VMs; do not share workspaces across projects.<\/li>\n\n\n\n<li>Secure credentials store; restrict access by folder and job.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"gitlab-runner-security\"><strong>GitLab Runner Security<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Register runners as locked; scope to specific projects.<\/li>\n\n\n\n<li>Use non-privileged Docker or rootless Podman executors; limit concurrent jobs.<\/li>\n\n\n\n<li>Protect branches\/tags; require approvals and signed commits.<\/li>\n\n\n\n<li>Isolate caches and artifacts per project; avoid shared directories.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"github-actions-self-hosted-runners\"><strong>GitHub Actions Self-Hosted Runners<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Prefer ephemeral runners that auto-remove after each job.<\/li>\n\n\n\n<li>Pin third-party actions by commit SHA; restrict allowed actions in organization settings.<\/li>\n\n\n\n<li>Use OIDC for cloud access; grant minimal IAM permissions per repository.<\/li>\n\n\n\n<li>Network-segment runners; apply egress policies and container sandboxing.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"pipeline-level-security-controls-devsecops\"><strong>Pipeline-Level Security Controls (DevSecOps)<\/strong><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"shift-left-scanning-and-supply-chain-safety\"><strong>Shift-Left Scanning and Supply Chain Safety<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>SAST\/Secrets: scan code and history (e.g., Gitleaks).<\/li>\n\n\n\n<li>Dependency\/Container: scan with Trivy or Grype on every build.<\/li>\n\n\n\n<li>SBOM and Signing: generate SBOM (Syft), sign images\/artifacts with Cosign, and record SLSA provenance.<\/li>\n\n\n\n<li>Policy-as-code: enforce IaC checks (Checkov), container policies (OPA\/Conftest).<\/li>\n<\/ul>\n\n\n\n<pre class=\"wp-block-code\"><code># GitHub Actions example: scan, SBOM, sign, and push\nname: build-secure\non: &#91;push]\njobs:\n  build:\n    runs-on: ubuntu-latest\n    permissions:\n      id-token: write\n      contents: read\n    steps:\n      - uses: actions\/checkout@&lt;commit-sha&gt;\n      - name: Build image\n        run: docker build -t $REGISTRY\/$IMAGE:$GIT_SHA .\n      - name: Trivy scan\n        uses: aquasecurity\/trivy-action@&lt;commit-sha&gt;\n        with:\n          image-ref: $REGISTRY\/$IMAGE:$GIT_SHA\n          vuln-type: 'os,library'\n      - name: Gitleaks secrets scan\n        uses: gitleaks\/gitleaks-action@&lt;commit-sha&gt;\n      - name: Generate SBOM (Syft)\n        run: syft $REGISTRY\/$IMAGE:$GIT_SHA -o spdx-json &gt; sbom.spdx.json\n      - name: Sign with cosign (keyless via OIDC)\n        run: cosign sign $REGISTRY\/$IMAGE:$GIT_SHA\n        env:\n          COSIGN_EXPERIMENTAL: \"1\"\n      - name: Push and attach SBOM\n        run: |\n          docker push $REGISTRY\/$IMAGE:$GIT_SHA\n          oras attach $REGISTRY\/$IMAGE:$GIT_SHA \n            --artifact-type application\/spdx+json sbom.spdx.json\n<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"promotion-gates-and-approvals\"><strong>Promotion Gates and Approvals<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Require CODEOWNERS approvals for sensitive paths.<\/li>\n\n\n\n<li>Block deploys unless scans pass and provenance is verified.<\/li>\n\n\n\n<li>Use environment protection rules, manual approvals, and change windows.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"ephemeral-environments-and-isolation\"><strong>Ephemeral Environments and Isolation<\/strong><\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Create per-PR ephemeral environments; destroy automatically after tests.<\/li>\n\n\n\n<li>Avoid shared runners for high-risk repos; prefer isolated VMs or containers.<\/li>\n\n\n\n<li>Segregate networks for build, staging, and production; restrict credentials by environment.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"actionable-alerts-for-ci-cd-on-linux\"><strong>Actionable Alerts for CI\/CD on Linux<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Multiple failed logins or new sudoers entries on a runner.<\/li>\n\n\n\n<li>Runner starts privileged containers or mounts host directories unexpectedly.<\/li>\n\n\n\n<li>Build tools spawning interactive shells (bash, sh) mid-pipeline.<\/li>\n\n\n\n<li>Outbound connections to unknown IPs or high-risk geographies.<\/li>\n\n\n\n<li>Changes to Jenkins plugins, GitLab Runner registrations, or GitHub runner settings.<\/li>\n\n\n\n<li>Auditd events for sensitive files: \/etc\/shadow, \/etc\/sudoers, SSH keys.<\/li>\n\n\n\n<li>Pipeline artifacts missing signatures or provenance; SBOM drift from baseline.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"incident-response-for-ci-cd-compromise\"><strong>Incident Response for CI\/CD Compromise<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Isolate the affected runner\/host; snapshot for forensics.<\/li>\n\n\n\n<li>Revoke tokens and credentials; rotate repository and cloud secrets.<\/li>\n\n\n\n<li>Invalidate and quarantine recent artifacts and container images.<\/li>\n\n\n\n<li>Audit commit history, build logs, and registry events for tampering.<\/li>\n\n\n\n<li>Rebuild runners from trusted images; redeploy with updated policies.<\/li>\n\n\n\n<li>Run a blameless postmortem; add new controls and alerts addressing the root cause.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"performance-cost-and-practical-tradeoffs\"><strong>Performance, Cost, and Practical Tradeoffs<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use lightweight agents (Node Exporter, journald forwarders) and sampling for high-volume eBPF events.<\/li>\n\n\n\n<li>Tier log retention: hot storage for 7\u201314 days, cold object storage for 90\u2013180 days.<\/li>\n\n\n\n<li>Automate baselining to reduce alert fatigue; tune rules per repo and team.<\/li>\n\n\n\n<li>Prefer ephemeral runners to minimize long-lived risk even if startup time increases slightly.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"quick-start-core-commands-and-config\"><strong>Quick-Start: Core Commands and Config<\/strong><\/h2>\n\n\n\n<pre class=\"wp-block-code\"><code># Enable unattended security updates (Debian\/Ubuntu)\nsudo apt-get update &amp;&amp; sudo apt-get install -y unattended-upgrades\nsudo dpkg-reconfigure -plow unattended-upgrades\n\n# auditd rules for critical files and sudo\nsudo apt-get install -y auditd audispd-plugins\necho '-w \/etc\/sudoers -p wa -k sudoers' | sudo tee \/etc\/audit\/rules.d\/ci.rules\necho '-w \/etc\/ssh\/sshd_config -p wa -k ssh' | sudo tee -a \/etc\/audit\/rules.d\/ci.rules\necho '-a always,exit -F arch=b64 -S execve -k exec' | sudo tee -a \/etc\/audit\/rules.d\/ci.rules\nsudo augenrules --load\nsudo systemctl restart auditd\n\n# Rootless Podman for safer builds\nsudo apt-get install -y podman\n# Run builds with a non-root user and --cap-drop=ALL where possible\n\n# journald to rsyslog\/remote\nsudo sed -i 's\/^#ForwardToSyslog=.*\/ForwardToSyslog=yes\/' \/etc\/systemd\/journald.conf\nsudo systemctl restart systemd-journald\n<\/code><\/pre>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"how-youstable-can-help\"><strong>How YouStable Can Help<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">As a <a href=\"https:\/\/www.youstable.com\/blog\/best-web-hosting-provider-in-india\/\">hosting provider<\/a> trusted by engineering teams, YouStable delivers hardened Linux servers, network segmentation, and 24\u00d77 <a href=\"https:\/\/www.youstable.com\/blog\/what-is-ci-cd-on-linux-server\/\">monitoring tailored for CI\/CD<\/a>. Our specialists help you deploy ephemeral runners, integrate SIEM and metrics, and implement scanning, signing, and provenance\u2014so your pipeline is fast, observable, and secure end-to-end.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"best-practices-checklist-tldr\"><strong>Best Practices Checklist (TL;DR)<\/strong><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Use minimal, patched Linux hosts with SSH key-only access and firewalls.<\/li>\n\n\n\n<li>Run ephemeral, least-privileged runners; avoid privileged containers.<\/li>\n\n\n\n<li>Centralize logs and metrics; create alerts for sudo, network egress, and container anomalies.<\/li>\n\n\n\n<li>Scan code, dependencies, and images; generate SBOM and sign artifacts.<\/li>\n\n\n\n<li>Verify provenance before deploy; enforce approvals and branch protections.<\/li>\n\n\n\n<li>Rotate secrets automatically; adopt OIDC and short-lived credentials.<\/li>\n\n\n\n<li>Practice incident response; rebuild from trusted images after compromise.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" class=\"wp-block-heading\" id=\"faqs-how-to-monitor-and-secure-ci-cd-on-linux-server\"><strong>FAQs: How to Monitor &amp; Secure CI\/CD on Linux Server<\/strong><\/h2>\n\n\n\t\t<section\t\thelp class=\"sc_fs_faq sc_card    \"\n\t\t\t\t>\n\t\t\t\t<h3 id=\"what-are-the-best-tools-to-monitor-ci-cd-on-linux\">What are the best tools to monitor CI\/CD on Linux?<\/h3>\t\t\t\t<div>\n\t\t\t\t\t\t<div class=\"sc_fs_faq__content\">\n\t\t\t\t\n\n<p class=\"wp-block-paragraph\">Use Prometheus + Grafana for metrics, Wazuh\/Elastic or Splunk for logs and SIEM, Falco or eBPF sensors for runtime detection, and the platform\u2019s exporters (Jenkins, GitLab Runner, Kubernetes). Centralize logs from runners, registries, and VCS and correlate with pipeline events.<\/p>\n\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section\t\thelp class=\"sc_fs_faq sc_card    \"\n\t\t\t\t>\n\t\t\t\t<h3 id=\"how-do-i-secure-a-self-hosted-github-actions-runner\">How do I secure a self-hosted GitHub Actions runner?<\/h3>\t\t\t\t<div>\n\t\t\t\t\t\t<div class=\"sc_fs_faq__content\">\n\t\t\t\t\n\n<p class=\"wp-block-paragraph\">Run ephemeral runners, restrict allowed actions, pin to commit SHAs, and use OIDC with minimal IAM. Sandbox jobs in non-privileged containers or VMs, segment networks, and forward all system and runner logs to SIEM. Disable long-lived credentials and shared workspaces.<\/p>\n\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section\t\thelp class=\"sc_fs_faq sc_card    \"\n\t\t\t\t>\n\t\t\t\t<h3 id=\"is-sbom-enough-or-do-i-need-slsa-provenance-too\">Is SBOM enough, or do I need SLSA provenance too?<\/h3>\t\t\t\t<div>\n\t\t\t\t\t\t<div class=\"sc_fs_faq__content\">\n\t\t\t\t\n\n<p class=\"wp-block-paragraph\">SBOM lists what\u2019s inside your artifact; SLSA provenance proves how and where it was built. Use both: generate SBOM for transparency and apply signed provenance to prevent tampering. Gate deployments on verified signatures and provenance checks.<\/p>\n\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section\t\thelp class=\"sc_fs_faq sc_card    \"\n\t\t\t\t>\n\t\t\t\t<h3 id=\"which-logs-should-i-collect-from-ci-cd-servers\">Which logs should I collect from CI\/CD servers?<\/h3>\t\t\t\t<div>\n\t\t\t\t\t\t<div class=\"sc_fs_faq__content\">\n\t\t\t\t\n\n<p class=\"wp-block-paragraph\">Collect auth logs, sudo and auditd events, runner and orchestrator logs, package manager logs, container runtime logs, registry access logs, and VCS audit logs. Keep at least 30\u201390 days hot, longer in cold storage for investigations and compliance.<\/p>\n\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section\t\thelp class=\"sc_fs_faq sc_card    \"\n\t\t\t\t>\n\t\t\t\t<h3 id=\"how-can-i-reduce-the-blast-radius-of-a-compromised-pipeline\">How can I reduce the blast radius of a compromised pipeline?<\/h3>\t\t\t\t<div>\n\t\t\t\t\t\t<div class=\"sc_fs_faq__content\">\n\t\t\t\t\n\n<p class=\"wp-block-paragraph\">Use isolated, ephemeral runners; restrict egress; store no long-lived secrets; scope IAM to per-repo needs; enforce non-privileged containers; and separate build, staging, and production credentials. Sign and verify artifacts so tampering can\u2019t silently reach production.<\/p>\n\n\t\t\t<\/div>\n\t\t<\/div>\n\t\t<\/section>\n\t\t\n<script type=\"application\/ld+json\">\n\t{\n\t\t\"@context\": \"https:\/\/schema.org\",\n\t\t\"@type\": \"FAQPage\",\n\t\t\"mainEntity\": [\n\t\t\t\t\t{\n\t\t\t\t\"@type\": \"Question\",\n\t\t\t\t\"name\": \"What are the best tools to monitor CI\/CD on Linux?\",\n\t\t\t\t\"acceptedAnswer\": {\n\t\t\t\t\t\"@type\": \"Answer\",\n\t\t\t\t\t\"text\": \"<p>Use Prometheus + Grafana for metrics, Wazuh\/Elastic or Splunk for logs and SIEM, Falco or eBPF sensors for runtime detection, and the platform\u2019s exporters (Jenkins, GitLab Runner, Kubernetes). Centralize logs from runners, registries, and VCS and correlate with pipeline events.<\/p>\"\n\t\t\t\t\t\t\t\t\t}\n\t\t\t}\n\t\t\t,\t\t\t\t{\n\t\t\t\t\"@type\": \"Question\",\n\t\t\t\t\"name\": \"How do I secure a self-hosted GitHub Actions runner?\",\n\t\t\t\t\"acceptedAnswer\": {\n\t\t\t\t\t\"@type\": \"Answer\",\n\t\t\t\t\t\"text\": \"<p>Run ephemeral runners, restrict allowed actions, pin to commit SHAs, and use OIDC with minimal IAM. Sandbox jobs in non-privileged containers or VMs, segment networks, and forward all system and runner logs to SIEM. Disable long-lived credentials and shared workspaces.<\/p>\"\n\t\t\t\t\t\t\t\t\t}\n\t\t\t}\n\t\t\t,\t\t\t\t{\n\t\t\t\t\"@type\": \"Question\",\n\t\t\t\t\"name\": \"Is SBOM enough, or do I need SLSA provenance too?\",\n\t\t\t\t\"acceptedAnswer\": {\n\t\t\t\t\t\"@type\": \"Answer\",\n\t\t\t\t\t\"text\": \"<p>SBOM lists what\u2019s inside your artifact; SLSA provenance proves how and where it was built. Use both: generate SBOM for transparency and apply signed provenance to prevent tampering. Gate deployments on verified signatures and provenance checks.<\/p>\"\n\t\t\t\t\t\t\t\t\t}\n\t\t\t}\n\t\t\t,\t\t\t\t{\n\t\t\t\t\"@type\": \"Question\",\n\t\t\t\t\"name\": \"Which logs should I collect from CI\/CD servers?\",\n\t\t\t\t\"acceptedAnswer\": {\n\t\t\t\t\t\"@type\": \"Answer\",\n\t\t\t\t\t\"text\": \"<p>Collect auth logs, sudo and auditd events, runner and orchestrator logs, package manager logs, container runtime logs, registry access logs, and VCS audit logs. Keep at least 30\u201390 days hot, longer in cold storage for investigations and compliance.<\/p>\"\n\t\t\t\t\t\t\t\t\t}\n\t\t\t}\n\t\t\t,\t\t\t\t{\n\t\t\t\t\"@type\": \"Question\",\n\t\t\t\t\"name\": \"How can I reduce the blast radius of a compromised pipeline?\",\n\t\t\t\t\"acceptedAnswer\": {\n\t\t\t\t\t\"@type\": \"Answer\",\n\t\t\t\t\t\"text\": \"<p>Use isolated, ephemeral runners; restrict egress; store no long-lived secrets; scope IAM to per-repo needs; enforce non-privileged containers; and separate build, staging, and production credentials. Sign and verify artifacts so tampering can\u2019t silently reach production.<\/p>\"\n\t\t\t\t\t\t\t\t\t}\n\t\t\t}\n\t\t\t\t\t\t]\n\t}\n<\/script>\n","protected":false},"excerpt":{"rendered":"<p>To monitor and secure CI\/CD on a Linux server, combine host hardening (SSH, firewall, MAC policies), rigorous pipeline controls (scanning, [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":14496,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"iawp_total_views":25,"footnotes":""},"categories":[350,2267],"tags":[],"class_list":["post-14361","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-knowledgebase","category-kb-devops"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/14361","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/comments?post=14361"}],"version-history":[{"count":1,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/14361\/revisions"}],"predecessor-version":[{"id":23359,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/posts\/14361\/revisions\/23359"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media\/14496"}],"wp:attachment":[{"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/media?parent=14361"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/categories?post=14361"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.youstable.com\/blog\/wp-json\/wp\/v2\/tags?post=14361"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}