Learn · Access control and auditability
Teams and authentication
Teams and pipeline permissions
Teams group users and carry permissions over pipelines. The useful discipline is to grant against a team rather than a person, so joining and leaving are the only two operations anyone performs.
Map Buildkite users to their source-control identities. Without that mapping, “who triggered this build” and “who wrote this commit” are two unrelated facts, and reconstructing an incident timeline means correlating them by hand.
Authentication at the organisation level
Enforce SSO or 2FA for access to the organisation. SSO is the stronger option, and not mainly because of password quality — because it makes deprovisioning somebody else’s problem, in a system that already does it.
When a contractor’s contract ends, their identity provider account is disabled as part of an existing process. If Buildkite access hangs off that, it ends too, without anyone remembering to do anything. That is a materially different guarantee from a checklist.
The audit log
The audit log records what happened in the organisation: token use, permission changes, configuration changes. Its value is entirely in the questions you can answer with it afterwards:
- Which agent token was used from an address we do not recognise?
- Who changed that pipeline’s settings, and when relative to the incident?
- When was this permission granted, and by whom?
Feeding it into a SIEM — via Amazon EventBridge, for instance — moves it from something you read after an incident to something that can alert during one.
Fork builds
A public pipeline that builds pull requests from forks is running code written by someone with no access to your organisation, on your agents, with whatever those agents can reach.
This is not hypothetical and it is not a niche configuration. If a pipeline is public, the decision about whether fork builds run — and if they do, on which queue, with which secrets available — is one of the more consequential configuration choices available to you.
This is where the queue boundary from the secrets unit earns its keep.
A security review asks you to demonstrate that a departed contractor can no longer trigger builds. Which control most directly answers that?
Sign in to answer and record your progress.