https://www.mdu.se/

mdu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Applying zero trust principles to self-hosted build agents in cloud environments
Mälardalen University, Faculty of Engineering and Health Sciences, Department of Computer Science & Engineering.
2026 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

Unlike platform-hosted build agents, self-hosted CI/CD build agents are managed by the organization that uses them. Self-hosted CI/CD build agents give organizations control over the build environment, but they also create security risks because they can connect source code, workflow execution, administrative access, credentials, and cloud resources. This thesis investigates how Zero Trust principles can reduce threats to self-hosted build agents in cloud environments. The study uses a before-and-after comparative case study in a controlled GitHub Actions and Microsoft Azure environment. A baseline self-hosted runner setup was analyzed through threat modeling using STRIDE, and the identified weaknesses were used to design an improved environment based on Zero Trust principles, including stronger verification, more restricted access, and measures that limit the effect of compromise. The evaluation compared the baseline and improved conditions using repeated attack scenarios and exposure scoring across attack feasibility, access level, and affected assets or evidence. The results show that the baseline runner was exposed to host compromise, credential reuse, persistent workflow state, broad Azure permissions, and limited visibility. The improved setup reduced exposure in all evaluated scenarios through controls such as removing direct public administrative exposure, strengthening identity-based access, reducing residual runner state, replacing reusable cloud secrets with federated authentication, narrowing cloud permissions, and improving centralized logging. The thesis shows that Zero Trust principles can provide a practical structure for reducing the attack surface and limiting the impact of compromise in self-hosted CI/CD environments.

Place, publisher, year, edition, pages
2026. , p. 47
Keywords [en]
Zero Trust, Self-Hosted Build Agents, Security
National Category
Computer Sciences Security, Privacy and Cryptography
Identifiers
URN: urn:nbn:se:mdh:diva-77412OAI: oai:DiVA.org:mdh-77412DiVA, id: diva2:2068947
Supervisors
Examiners
Available from: 2026-06-22 Created: 2026-06-09 Last updated: 2026-06-22Bibliographically approved

Open Access in DiVA

Applying zero trust to build agents(2990 kB)48 downloads
File information
File name FULLTEXT01.pdfFile size 2990 kBChecksum SHA-512
1906d43eae729454200df479f65bafef35e40af79909c10a5feebfb7cc4dcc911c3d31f39b310a8393291dd004f0f9616d92036bb423d9d9003820870a87c44a
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Al Rifai, Hashem
By organisation
Department of Computer Science & Engineering
Computer SciencesSecurity, Privacy and Cryptography

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 92 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf