Abstract
As cloud-native CI/CD pipelines automate software delivery at scale, identity-centric security has become a critical concern. This paper reports a systematic literature review of 59 peer-reviewed studies that examine authentication and authorisation (AuthN/AuthZ) in CI/CD workflows. We synthesise key vulnerability classes, including token theft, privilege escalation, session hijacking, supply-chain abuse, and misaligned microservice identities. We then introduce a CI/CD-specific vulnerability taxonomy and systematically map established mechanisms such as OAuth 2.0, Kerberos, SAML, mTLS, RBAC/ABAC, XACML, API gateways, and MFA to the attack vectors they mitigate across the pipeline. Finally, we analyse emerging trends, including Zero-Trust Architecture, decentralised identity, service-mesh-based access control, and cryptographically anchored identity models that use blockchain and self-sovereign identity. The review exposes persistent gaps in configuration, observability, and runtime enforcement, as well as organisational barriers to adopting stronger identity controls. Our findings provide a structured foundation for designing trustworthy, identity-centric DevSecOps practices and highlight concrete research directions for securing access in cloud-native CI/CD environments.
Author supplied keywords
Cite
CITATION STYLE
Saleh, S. M., Madhavji, N. H., & Steinbacher, J. (2026). Systematic Review of Identity-Centric Security in Cloud-Native CI/CD Pipelines. In CCIOT 2025 - Proceedings of 2025 10th International Conference on Cloud Computing and Internet of Things (pp. 23–32). Association for Computing Machinery, Inc. https://doi.org/10.1145/3785520.3785525
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.