Table of Contents
A Day in the Life of a Developer
TL;DR: This illustrated story follows a developer dealing with common CI/CD problems caused by secrets, including broken authentication, manual token rotation, unclear access, and deployment failures. It explains the risks of storing secrets in GitLab variables, configs, and environment variables, highlights real-world breaches and supporting research, and introduces short-lived, identity-based access as a more secure and reliable alternative.
Aembit Team
Product & Research
Published Aug 2025
Updated Sep 2026
50:1
Non-human to human identities
18
Agent threat classes mapped
0
Long-lived secrets required
No form · instant
Download the Infographics
Free PDF · no email required
- 1 pages
- 12 min read
Prefer the full report?
Table of Contents
This quick, illustrated story walks you through one developer’s real frustrations: flaky secrets, unclear access, broken auth, late-night rollbacks. If you’ve ever juggled API keys, rotated tokens manually, or been blamed for something infra-related that wasn’t your fault, this one hits close to home.
You’ll walk away with:
- A developer’s-eye view of why CI/CD breaks.
- Why storing secrets in GitLab variables, configs, or env vars can lead to pain.
- Research and stats that back up the story.
- Real-world breaches caused by secrets mismanagement in GitLab CI/CD.
- The alternative: short-lived, identity-based access that just works.
Download it, share it with your team – and maybe the next person who tells you to “just rotate the token and move on.”
Continue Exploring
Our learning center features all the latest resources to deepen your understanding of securing workload access, including how-to guides, videos, webinars, and more.