Table of Contents

Cookbooks

Aembit Server Workload Cookbooks Series | GitLab

TL;DR: A practical GitLab CI/CD security guide showing how to replace static API keys and stored secrets with short-lived OAuth 2.0 tokens. It focuses on using workload identity, least-privilege policies, and dynamic authentication so each GitLab pipeline job gets only the access it needs, for only as long as it needs it. In one sentence: It’s a hands-on recipe for making GitLab pipelines safer by eliminating long-lived credentials and using temporary, policy-controlled access instead.

Aembit Team

Product & Research

Published Aug 2025

Updated Sep 2026

50:1

Non-human to human identities

18

Agent threat classes mapped

0

Long-lived secrets required

Aembit's GitLab Cookbook cover
No form · instant

Download the Cookbook

Free PDF · no email required

Table of Contents

CI/CD pipelines form the backbone of modern software delivery — but their security often hinges on how well you manage secrets.

In GitLab, one of the most widely adopted CI/CD platforms in the enterprise, credentials like API keys and tokens are often stored as static variables, environment secrets, or even hardcoded values. These practices scale poorly, widen your attack surface, and have played a role in high-profile breaches.

This free cookbook — the second in our series — serves up the technical recipe for securing your GitLab CI/CD pipeline’s access to the GitLab REST API with short-lived OAuth 2.0 tokens.

Inside, you’ll find the ingredients to:

Continue Exploring

Our learning center features all the latest resources to deepen your understanding of securing workload access, including how-to guides, videos, webinars, and more.

Workload Identity Federation Resource

What is Workload Identity Federation?

A secret can grant access. It cannot prove which workload is presenting it. Trace how federation changes the equation at scale.
Aembit and CrowdStrike AIDR data sheet for AI agent identity, access control, and content inspection share image

Aembit + CrowdStrike AIDR for AI Agent Security

Aembit and CrowdStrike AIDR combine AI agent identity and MCP access controls with real-time content inspection and enforcement.
Auditing and Governance for Workload and AI Agent Identity

Auditing and Governance in Modern Identity

Aembit turns workload and AI agent access activity into detailed audit trails, policy insights, and operational visibility.