[{"data":1,"prerenderedAt":828},["ShallowReactive",2],{"{\"cv\":1786118516038,\"version\":\"published\"}widgets\u002Fnavigation-bar":3,"{\"cv\":1786118516038,\"resolve_relations\":[\"ResourceFeatureCard.resource\"],\"version\":\"published\"}case-studies\u002Fsecuring-dynamic-containerized-environments":67},{"data":4,"headers":45},{"story":5,"cv":42,"rels":43,"links":44},{"name":6,"created_at":7,"published_at":8,"updated_at":9,"id":10,"uuid":11,"content":12,"slug":32,"full_slug":33,"sort_by_date":22,"position":34,"tag_list":35,"is_startpage":15,"parent_id":36,"meta_data":22,"group_id":37,"first_published_at":38,"release_id":22,"lang":39,"path":40,"alternates":41,"default_full_slug":22,"translated_slugs":22},"Navigation Bar","2026-08-05T05:55:49.585Z","2026-08-07T15:41:09.255Z","2026-08-07T15:41:09.269Z",205700094329908,"be34732b-2155-45e7-8ee2-86e1157a8cb4",{"_uid":13,"component":14,"showMarketingBanner":15,"marketingBannerContent":16},"e7a8d72d-8af8-452e-87b2-de4098162fb9","NavigationBar",false,{"type":17,"content":18},"doc",[19],{"type":20,"attrs":21,"content":23},"paragraph",{"textAlign":22},null,[24],{"text":25,"type":26,"marks":27},"See us at Black Hat booth #7505","text",[28],{"type":29,"attrs":30},"textStyle",{"color":31},"#000000","navigation-bar","widgets\u002Fnavigation-bar",0,[],205696803161001,"e116d2fb-7cac-4697-9dcb-91d9283aecc3","2026-08-05T06:19:33.200Z","default","\u002F",[],1786117269,[],[],{"age":46,"cache-control":47,"connection":48,"content-length":49,"content-type":50,"date":51,"etag":52,"referrer-policy":53,"sb-be-version":54,"server":55,"vary":56,"via":57,"x-amz-cf-id":58,"x-amz-cf-pop":59,"x-cache":60,"x-content-type-options":61,"x-frame-options":62,"x-permitted-cross-domain-policies":63,"x-request-id":64,"x-runtime":65,"x-xss-protection":66},"897","max-age=0, public, s-maxage=604800, stale-if-error=3600","keep-alive","986","application\u002Fjson; charset=utf-8","Fri, 07 Aug 2026 15:47:27 GMT","W\u002F\"2042216e83630aaa3237c7e1f294f956\"","strict-origin-when-cross-origin","5.935.0","nginx\u002F1.29.1","Origin","1.1 bcf3714653b91c162db4f8a673af0716.cloudfront.net (CloudFront)","ZeTh6D2IBpDTvE_4iyFmgL2OCX4omEB--bgRtc5iMESE9WExc4T0AA==","CMH68-P4","Hit from cloudfront","nosniff","SAMEORIGIN","none","230b9f43-81bf-43c7-8b53-0c93ba9a09f6","0.045602","0",{"data":68,"headers":817},{"story":69,"cv":42,"rels":700,"links":816},{"name":70,"created_at":71,"published_at":72,"updated_at":73,"id":74,"uuid":75,"content":76,"slug":693,"full_slug":694,"sort_by_date":22,"position":695,"tag_list":696,"is_startpage":15,"parent_id":697,"meta_data":22,"group_id":698,"first_published_at":72,"release_id":22,"lang":39,"path":22,"alternates":699,"default_full_slug":22,"translated_slugs":22},"Securing dynamic containerized environments","2026-07-23T17:17:13.586Z","2026-07-24T16:06:17.174Z","2026-07-24T16:06:17.192Z",201266927995590,"fb3400f1-470d-4f55-9092-3eae5df9f497",{"Tags":77,"_uid":78,"title":70,"content":79,"component":508,"seoOgImage":509,"previewImage":514,"previewTitle":516,"relatedContent":517,"seoDescription":681,"previewDescription":681,"shortOutcomeDescription":682},"container security, Kubernetes, cybersecurity","e0f10234-7a3c-4061-838a-bac232c782ad",{"type":17,"content":80},[81,94,102,113,121,165,173,182,190,200,208,216,225,233,265,273,282,290,299,307,316,325,333,342,350,359,367,376,385,393,401,409,418,426,434,442,451,459,472,482,490,498],{"type":82,"attrs":83,"content":85},"heading",{"level":84,"textAlign":22},2,[86],{"text":87,"type":26,"marks":88},"Unprecedented speed, scalability, and development velocity are brought about by this evolution, but it also opens up new attack vectors and reveals serious security flaws that conventional network and perimeter-based controls cannot fix.",[89,92],{"type":29,"attrs":90},{"color":91},"#003B5C",{"type":93},"bold",{"type":20,"attrs":95,"content":96},{"textAlign":22},[97],{"text":98,"type":26,"marks":99},"Businesses must deal with the distinct and quickly changing security challenges posed by containerized, ephemeral, and distributed microservice workloads as they embrace the agility of cloud-native infrastructures. Xiid Terniion is a radically novel method designed specifically to protect these contemporary settings at the rate at which they change.",[100],{"type":29,"attrs":101},{"color":91},{"type":82,"attrs":103,"content":105},{"level":104,"textAlign":22},3,[106],{"text":107,"type":26,"marks":108},"Industry Challenge: The Modern Container Security Gap",[109,112],{"type":29,"attrs":110},{"color":111},"#F68D2E",{"type":93},{"type":20,"attrs":114,"content":115},{"textAlign":22},[116],{"text":117,"type":26,"marks":118},"Across sectors—whether finance, healthcare, manufacturing, or technology—operational environments are marked by:",[119],{"type":29,"attrs":120},{"color":91},{"type":122,"content":123},"bullet_list",[124,135,145,155],{"type":125,"content":126},"list_item",[127],{"type":20,"attrs":128,"content":129},{"textAlign":22},[130],{"text":131,"type":26,"marks":132},"Ephemeral Workloads: 70% of containers live less than 5 minutes, with attack windows often completing within 10 minutes",[133],{"type":29,"attrs":134},{"color":91},{"type":125,"content":136},[137],{"type":20,"attrs":138,"content":139},{"textAlign":22},[140],{"text":141,"type":26,"marks":142},"Constant Change & Scaling: Continuous deployments and updates introduce new workloads at breakneck speed, while auto-scaling sees containers rapidly spin up and down to meet demand.",[143],{"type":29,"attrs":144},{"color":91},{"type":125,"content":146},[147],{"type":20,"attrs":148,"content":149},{"textAlign":22},[150],{"text":151,"type":26,"marks":152},"IP Address Volatility: Containers are regularly restarted or moved, causing frequent IP changes that render static network policies and firewalls ineffective.",[153],{"type":29,"attrs":154},{"color":91},{"type":125,"content":156},[157],{"type":20,"attrs":158,"content":159},{"textAlign":22},[160],{"text":161,"type":26,"marks":162},"Orchestration & API Exposure: Control planes, such as Kubernetes APIs and registries, form high-value targets with elevated privileges and lateral movement risks.",[163],{"type":29,"attrs":164},{"color":91},{"type":20,"attrs":166,"content":167},{"textAlign":22},[168],{"text":169,"type":26,"marks":170},"These realities challenge established notions of perimeter defense, making it clear that legacy firewalls, static rules, and complex overlays (like service meshes) fail to keep pace with true container-driven operations. Container security must be as dynamic and granular as the environments it protects.",[171],{"type":29,"attrs":172},{"color":91},{"type":82,"attrs":174,"content":175},{"level":104,"textAlign":22},[176],{"text":177,"type":26,"marks":178},"The Xiid Solution: True Zero Trust Container Security with Terniion",[179,181],{"type":29,"attrs":180},{"color":111},{"type":93},{"type":20,"attrs":183,"content":184},{"textAlign":22},[185],{"text":186,"type":26,"marks":187},"Xiid Terniion was engineered to directly address these pervasive industry issues through several core innovations:",[188],{"type":29,"attrs":189},{"color":91},{"type":82,"attrs":191,"content":193},{"level":192,"textAlign":22},4,[194],{"text":195,"type":26,"marks":196},"Process-to-Process, Outbound-Only Security",[197,199],{"type":29,"attrs":198},{"color":91},{"type":93},{"type":20,"attrs":201,"content":202},{"textAlign":22},[203],{"text":204,"type":26,"marks":205},"By establishing process-level tunnels—instead of relying on IPs or hostnames—Terniion ensures every containerized process maintains an immutable, isolated, and identifable security boundary, regardless of how underlying infrastructure or IP addresses change.",[206],{"type":29,"attrs":207},{"color":91},{"type":20,"attrs":209,"content":210},{"textAlign":22},[211],{"text":212,"type":26,"marks":213},"All connections are outbound-only and triple-encrypted with multiple layers of end-to-end encryption, meaning containers and hosts never expose inbound ports or data to middlemen or attackers. This outbound architecture eliminates exposed attack surfaces and significantly reduces the risk of lateral movement within the cloud or data center.",[214],{"type":29,"attrs":215},{"color":91},{"type":82,"attrs":217,"content":218},{"level":192,"textAlign":22},[219],{"text":220,"type":26,"marks":221},"Quantum-Secure Triple Encryption",[222,224],{"type":29,"attrs":223},{"color":91},{"type":93},{"type":20,"attrs":226,"content":227},{"textAlign":22},[228],{"text":229,"type":26,"marks":230},"Terniion augments defense-in-depth with three distinct layers of encryption:",[231],{"type":29,"attrs":232},{"color":91},{"type":122,"content":234},[235,245,255],{"type":125,"content":236},[237],{"type":20,"attrs":238,"content":239},{"textAlign":22},[240],{"text":241,"type":26,"marks":242},"TLS 1.3 for outer-layer transport security",[243],{"type":29,"attrs":244},{"color":91},{"type":125,"content":246},[247],{"type":20,"attrs":248,"content":249},{"textAlign":22},[250],{"text":251,"type":26,"marks":252},"Kyber KEM and Dilithium digital signatures for post-quantum resilience",[253],{"type":29,"attrs":254},{"color":91},{"type":125,"content":256},[257],{"type":20,"attrs":258,"content":259},{"textAlign":22},[260],{"text":261,"type":26,"marks":262},"AES-256-GCM AEAD as the inner core",[263],{"type":29,"attrs":264},{"color":91},{"type":20,"attrs":266,"content":267},{"textAlign":22},[268],{"text":269,"type":26,"marks":270},"This allows organizations to future-proof sensitive data and operations even as quantum computing threats evolve.",[271],{"type":29,"attrs":272},{"color":91},{"type":82,"attrs":274,"content":275},{"level":192,"textAlign":22},[276],{"text":277,"type":26,"marks":278},"Automated, Profile-Driven Security with Profles",[279,281],{"type":29,"attrs":280},{"color":91},{"type":93},{"type":20,"attrs":283,"content":284},{"textAlign":22},[285],{"text":286,"type":26,"marks":287},"SealedTunnel Profiles make it possible to deploy fully-networked, pre-configured, and securely isolated containers with no manual intervention. Standardized, template-based mappings and bindings ensure that security is consistent and immediate for new workloads, allowing seamless horizontal scaling without security bottlenecks or manual interventions.",[288],{"type":29,"attrs":289},{"color":91},{"type":82,"attrs":291,"content":292},{"level":192,"textAlign":22},[293],{"text":294,"type":26,"marks":295},"Multi-Cloud, Multi-Pattern Support",[296,298],{"type":29,"attrs":297},{"color":91},{"type":93},{"type":20,"attrs":300,"content":301},{"textAlign":22},[302],{"text":303,"type":26,"marks":304},"With Kubernetes integration (including sidecar, daemonset, and gateway models), enterprises benefit from cloud-agnostic security that works seamlessly across AWS, Azure, Google Cloud, on-premises, and edge deployments.",[305],{"type":29,"attrs":306},{"color":91},{"type":82,"attrs":308,"content":309},{"level":192,"textAlign":22},[310],{"text":311,"type":26,"marks":312},"Use Cases Across the Modern Enterprise",[313,315],{"type":29,"attrs":314},{"color":91},{"type":93},{"type":20,"attrs":317,"content":318},{"textAlign":22},[319],{"text":320,"type":26,"marks":321},"Agile Microservices",[322,324],{"type":29,"attrs":323},{"color":91},{"type":93},{"type":20,"attrs":326,"content":327},{"textAlign":22},[328],{"text":329,"type":26,"marks":330},"Organizations supporting microservice architectures benefit from SealedTunnel’s process-to-process tunneling and microsegmentation, allowing secure horizontal scaling without IP or firewall reconfiguration delays and resilient, secure inter-service communication.",[331],{"type":29,"attrs":332},{"color":91},{"type":20,"attrs":334,"content":335},{"textAlign":22},[336],{"text":337,"type":26,"marks":338},"CI\u002FCD and Software Supply Chain Security",[339,341],{"type":29,"attrs":340},{"color":91},{"type":93},{"type":20,"attrs":343,"content":344},{"textAlign":22},[345],{"text":346,"type":26,"marks":347},"As CI\u002FCD pipelines become attack vectors, SealedTunnel delivers complete network isolation for build runners and code repositories. Outbound-only connections and zero required public IP exposure neutralize zero-day attacks and emerging threats.",[348],{"type":29,"attrs":349},{"color":91},{"type":20,"attrs":351,"content":352},{"textAlign":22},[353],{"text":354,"type":26,"marks":355},"Machine Learning, AI, IoT, and Edge Workloads",[356,358],{"type":29,"attrs":357},{"color":91},{"type":93},{"type":20,"attrs":360,"content":361},{"textAlign":22},[362],{"text":363,"type":26,"marks":364},"From large model delivery to constrained edge devices, SealedTunnel ensures all data transfers are triple-encrypted, resilient to unreliable networks, and securely isolated regardless of the underlying compute platform.",[365],{"type":29,"attrs":366},{"color":91},{"type":82,"attrs":368,"content":369},{"level":104,"textAlign":22},[370],{"text":371,"type":26,"marks":372},"Business Impact and ROI",[373,375],{"type":29,"attrs":374},{"color":111},{"type":93},{"type":82,"attrs":377,"content":378},{"level":192,"textAlign":22},[379],{"text":380,"type":26,"marks":381},"Security Risk Reduction",[382,384],{"type":29,"attrs":383},{"color":91},{"type":93},{"type":20,"attrs":386,"content":387},{"textAlign":22},[388],{"text":389,"type":26,"marks":390},"• Drastically reduced attack surface: No open inbound ports and immutable process boundaries.",[391],{"type":29,"attrs":392},{"color":91},{"type":20,"attrs":394,"content":395},{"textAlign":22},[396],{"text":397,"type":26,"marks":398},"• Breach containment: Lateral movement is prevented at the process level—not just at the endpoint.",[399],{"type":29,"attrs":400},{"color":91},{"type":20,"attrs":402,"content":403},{"textAlign":22},[404],{"text":405,"type":26,"marks":406},"• Compliance readiness: Automated, robust encryption and access controls facilitate PCI DSS, HIPAA, and SOC 2 alignment.",[407],{"type":29,"attrs":408},{"color":91},{"type":82,"attrs":410,"content":411},{"level":192,"textAlign":22},[412],{"text":413,"type":26,"marks":414},"Operational Effciency and Cost Optimization",[415,417],{"type":29,"attrs":416},{"color":91},{"type":93},{"type":20,"attrs":419,"content":420},{"textAlign":22},[421],{"text":422,"type":26,"marks":423},"• Streamlined deployment: Automated profile-driven configuration enables rapid environment provisioning and continuous deployment.",[424],{"type":29,"attrs":425},{"color":91},{"type":20,"attrs":427,"content":428},{"textAlign":22},[429],{"text":430,"type":26,"marks":431},"• Elastic scalability: Security scales seamlessly with application loads, without creating network configuration-related chokepoints or delays.",[432],{"type":29,"attrs":433},{"color":91},{"type":20,"attrs":435,"content":436},{"textAlign":22},[437],{"text":438,"type":26,"marks":439},"• Toolchain consolidation: SealedTunnel replaces multiple legacy tools, reducing licensing and management overhead.",[440],{"type":29,"attrs":441},{"color":91},{"type":82,"attrs":443,"content":444},{"level":104,"textAlign":22},[445],{"text":446,"type":26,"marks":447},"Proven Reliability",[448,450],{"type":29,"attrs":449},{"color":111},{"type":93},{"type":20,"attrs":452,"content":453},{"textAlign":22},[454],{"text":455,"type":26,"marks":456},"Xiid’s platform is field-tested in hostile environments, penetration tested by the U.S. Air Force Research Laboratory, and has been granted an unconditional Authority to Operate by the U.S. Department of Defense, proving real-world resilience for critical and sensitive workloads.",[457],{"type":29,"attrs":458},{"color":91},{"type":20,"attrs":460,"content":461},{"textAlign":22},[462],{"text":463,"type":26,"marks":464},"Comparative Assessment",[465,467,471],{"type":29,"attrs":466},{"color":91},{"type":468,"attrs":469},"anchor",{"id":470},"yui_3_17_2_1_1784827017577_497",{"type":93},{"type":20,"attrs":473,"content":474},{"textAlign":22},[475],{"type":476,"attrs":477},"image",{"id":478,"alt":479,"src":480,"title":479,"source":479,"copyright":479,"meta_data":481},201268827202504,"","https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F1292x771\u002Fa37ea88803\u002Fscreenshot_6-9-2025_153939_.jpeg",{},{"type":82,"attrs":483,"content":484},{"level":104,"textAlign":22},[485],{"text":486,"type":26,"marks":487},"Conclusion",[488],{"type":29,"attrs":489},{"color":111},{"type":20,"attrs":491,"content":492},{"textAlign":22},[493],{"text":494,"type":26,"marks":495},"Only the process-to-process, outbound-only Terniion can keep pace with the operational realities of modern dynamic containerized architectures. Xiid’s platform provides the automation, quantum resilience, and integration needed to make security a force multiplier for DevSecOps—not a drag.",[496],{"type":29,"attrs":497},{"color":91},{"type":20,"attrs":499,"content":500},{"textAlign":22},[501,506],{"text":502,"type":26,"marks":503},"Organizations investing today in quantum-secure, process-isolated networking are well-positioned to thrive as the demand for speed, regulatory compliance, and security grows—across cloud, edge, and the inevitable quantum-powered future.",[504],{"type":29,"attrs":505},{"color":91},{"text":507,"type":26}," ","CaseStudy",{"id":510,"alt":479,"name":479,"focus":479,"title":479,"source":479,"filename":511,"copyright":479,"fieldtype":512,"meta_data":513,"is_external_url":15},201325896601723,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F5292x3528\u002Fe014f32c26\u002Fgovernmental-hackers-exploiting-network-systems-high-tech-office.jpg","asset",{},{"id":510,"alt":479,"name":479,"focus":479,"title":479,"source":479,"filename":511,"copyright":479,"fieldtype":512,"meta_data":515,"is_external_url":15},{},"Securing dynamic containerized environments Use Case | Xiid",[518],{"_uid":519,"variant":520,"resource":521,"component":679,"background":680},"6b0de268-b527-4dee-848b-fd745e9d5380","oneThirdLeftPhoto",[522],{"name":523,"created_at":524,"published_at":525,"updated_at":526,"id":527,"uuid":528,"content":529,"slug":669,"full_slug":670,"sort_by_date":671,"position":672,"tag_list":673,"is_startpage":15,"parent_id":674,"meta_data":22,"group_id":675,"first_published_at":676,"release_id":22,"lang":39,"path":22,"alternates":677,"default_full_slug":22,"translated_slugs":22,"_stopResolving":678},"CI\u002FCD pipeline security: Human error is inevitable. Lateral movement isn't","2026-06-15T23:11:55.413Z","2026-07-27T21:04:49.739Z","2026-07-27T21:04:49.754Z",187906111156902,"d0949410-f184-41bd-88ee-b8a421a5f7ae",{"Tags":479,"_uid":530,"body":531,"title":532,"content":533,"component":634,"seoOgImage":635,"keyTakeaways":639,"previewImage":664,"previewTitle":532,"relatedContent":666,"seoDescription":667,"previewDescription":668},"69a52ed9-008b-4441-a3c4-57b32d15254b",[],"CI\u002FCD pipeline security: Human error is inevitable. Lateral movement isn't.",{"type":17,"content":534},[535,540,547,552,557,564,573,578,585,590,595,600,607,612,617,624,629],{"type":20,"attrs":536,"content":537},{"textAlign":22},[538],{"text":539,"type":26},"The incident report always reads “human error\": a misconfigured runner, a committed token, an overpermissioned service account attached to a build job that didn’t need it. These mistakes happen at every company, regardless of maturity level, so the question isn’t whether they’ll happen to your team. The question is how your architecture lets those errors compound.",{"type":82,"attrs":541,"content":542},{"level":84,"textAlign":22},[543],{"text":544,"type":26,"marks":545},"A Compromised Runner Is a Beachhead",[546],{"type":93},{"type":20,"attrs":548,"content":549},{"textAlign":22},[550],{"text":551,"type":26},"When attackers gain access to a CI\u002FCD pipeline runner through a leaked token, a poisoned dependency, or a misconfigured environment variable, they don’t stop there. They enumerate everything reachable from that position, including artifact stores, secrets managers, container registries, staging environments, and sometimes even production databases. They look for credentials baked into the source code, its comments, and the documentation markup. They probe the subnet for services the runner was never supposed to touch but can, because no one restricted the network paths when it was originally provisioned.",{"type":20,"attrs":553,"content":554},{"textAlign":22},[555],{"text":556,"type":26},"That’s the blast radius problem in software delivery pipelines. A typical GitLab runner sitting on a shared subnet can reach the artifact store, the secrets vault, adjacent runners, and internal APIs all in the same network breath. The misconfiguration is the entry point, but the open network is the damage multiplier.",{"type":82,"attrs":558,"content":559},{"level":84,"textAlign":22},[560],{"text":561,"type":26,"marks":562},"Why Least Privilege Alone Doesn’t Contain the Damage",[563],{"type":93},{"type":20,"attrs":565,"content":566},{"textAlign":22},[567,571],{"text":568,"type":26,"marks":569},"T",[570],{"type":93},{"text":572,"type":26},"he standard DevSecOps response to blast radius is least-privilege configuration: tighten IAM policies, scope tokens to the minimum needed permissions, and rotate secrets on a schedule. While these are necessary controls, none of them solve the lateral movement problem.",{"type":20,"attrs":574,"content":575},{"textAlign":22},[576],{"text":577,"type":26},"Least privilege governs what a process is authorized to do. However, it has no effect on what’s network-reachable to a compromised process. A misconfigured IAM role is one mistake, but the runner can still attempt connections to adjacent services, scan for open ports, and exploit trust relationships baked into the subnet’s routing table. Authorization policy and network reachability operate on different layers, and closing the gap at the authorization layer leaves the network layer wide open.",{"type":82,"attrs":579,"content":580},{"level":84,"textAlign":22},[581],{"text":582,"type":26,"marks":583},"Terniion Removes the Paths, Not Just the Permissions",[584],{"type":93},{"type":20,"attrs":586,"content":587},{"textAlign":22},[588],{"text":589,"type":26},"Terniion approaches CI\u002FCD pipeline security from a different premise: instead of configuring what’s allowed to reach what, make every pipeline component non-addressable by default and grant reachability only where it’s explicitly required.",{"type":20,"attrs":591,"content":592},{"textAlign":22},[593],{"text":594,"type":26},"Terniion deploys lightweight STLink agents alongside protected pipeline components. Each STLink establishes outbound-only, process-to-process connections with triple-layer, quantum-resistant encryption. No inbound ports open. No public IPs. No routable addresses exposed on the subnet. A runner authorized to pull artifacts from a specific store does exactly that and nothing else. The network path to the secrets vault, to adjacent runners, and to staging simply doesn’t exist from that runner’s position. Probing the subnet returns nothing because there’s nothing addressable to probe.",{"type":20,"attrs":596,"content":597},{"textAlign":22},[598],{"text":599,"type":26},"This is the distinction between restricting what a compromised process can do versus eliminating what it can reach. The first approach relies on the perimeter holding. The second doesn’t need that assumption.",{"type":82,"attrs":601,"content":602},{"level":84,"textAlign":22},[603],{"text":604,"type":26,"marks":605},"Blast Radius as a Design Parameter",[606],{"type":93},{"type":20,"attrs":608,"content":609},{"textAlign":22},[610],{"text":611,"type":26},"Because Terniion works at the process level rather than the network level, the blast radius shrinks to whatever a specific process was authorized to reach—and nothing else. A build runner connected to the artifact store has exactly that: one tunnel, one destination, one authorized process on each end. There is no tunnel to the secrets manager, no tunnel to staging, no tunnel to production, because SealedTunnel never establishes connections that weren't explicitly configured. An attacker who compromises that runner can't pivot to other systems because the paths to those systems were never created in the first place.",{"type":20,"attrs":613,"content":614},{"textAlign":22},[615],{"text":616,"type":26},"Layered with Aclave credential-less authentication, which removes stored usernames, passwords, and long-lived certificates from the pipeline entirely, the architecture eliminates both the movement path and the credential that a compromised runner could carry to another system.",{"type":82,"attrs":618,"content":619},{"level":84,"textAlign":22},[620],{"text":621,"type":26,"marks":622},"Error Prevention and Error Containment Are Different Problems ",[623],{"type":93},{"type":20,"attrs":625,"content":626},{"textAlign":22},[627],{"text":628,"type":26},"Most pipeline security investment goes into preventing mistakes. Examples of this are secret scanning, pre-commit hooks, tighter code review, or security training. All of it matters, but none of it is a substitute for an architecture that limits what a mistake can become.",{"type":20,"attrs":630,"content":631},{"textAlign":22},[632],{"text":633,"type":26},"When the inevitable misconfiguration happens, the architecture either gives attackers a subnet to pivot across or it doesn’t. Terniion’s process-to-process tunneling and Zone-enforced segmentation make pipeline components non-addressable to anything outside their authorized communication scope. Your engineers don’t become less human. The blast just has nowhere left to go.","BlogPost",{"id":636,"alt":479,"name":479,"focus":479,"title":479,"source":479,"filename":637,"copyright":479,"fieldtype":512,"meta_data":638,"is_external_url":15},201614295374915,"https:\u002F\u002Fa.storyblok.com\u002Ff\u002F292462593318313\u002F6912x3888\u002Fd3bebd6fa6\u002Fpc-screens-server-hub-office-desk-showing-programming-software-close-up.jpg",{},{"type":17,"content":640},[641],{"type":122,"content":642},[643,650,657],{"type":125,"content":644},[645],{"type":20,"attrs":646,"content":647},{"textAlign":22},[648],{"text":649,"type":26},"Human error in CI\u002FCD pipelines—misconfigured credentials, leaked secrets, improper access—is inevitable, but lateral movement from those errors doesn't have to be.",{"type":125,"content":651},[652],{"type":20,"attrs":653,"content":654},{"textAlign":22},[655],{"text":656,"type":26},"Outbound-only, process-to-process architecture contains the blast radius: a compromised credential or node can't pivot to other systems.",{"type":125,"content":658},[659],{"type":20,"attrs":660,"content":661},{"textAlign":22},[662],{"text":663,"type":26},"Traditional CI\u002FCD security tools focus on detecting threats after access is granted; Terniion removes the exposure before the process starts.",{"id":636,"alt":479,"name":479,"focus":479,"title":479,"source":479,"filename":637,"copyright":479,"fieldtype":512,"meta_data":665,"is_external_url":15},{},[],"When a CI\u002FCD runner gets compromised, the real damage comes from lateral movement — here's how Terniion's process-level isolation eliminates the pathways attackers need to pivot.","The incident report always reads \"human error\" - a misconfigured runner, a committed token, or an overpermissioned service account attached to a build job that didn't need it. ","cicd-pipeline-human-error-is-inevitable","blog\u002Fcicd-pipeline-human-error-is-inevitable","2026-04-15",50,[],193139877037850,"763d95bc-8eae-48f5-a95a-3b931b2fc331","2026-04-15T09:06:00.000Z",[],true,"ResourceFeatureCard","white","See how Xiid Terniion delivers quantum-secure, process-to-process protection for Kubernetes, CI\u002FCD, and multi-cloud containers—eliminating attack surfaces and streamlining security at scale.",{"type":17,"content":683},[684],{"type":20,"attrs":685,"content":686},{"textAlign":22},[687],{"text":688,"type":26,"marks":689},"Organizations in a variety of industries are switching from static legacy systems to dynamic, containerized architectures driven by CI\u002FCD pipelines and Kubernetes.",[690],{"type":29,"attrs":691},{"color":692},"#2CD5C4","securing-dynamic-containerized-environments","case-studies\u002Fsecuring-dynamic-containerized-environments",-10,[],188221605925663,"c1e17c84-7224-47c5-9d45-d675aec99328",[],[701],{"name":523,"created_at":524,"published_at":525,"updated_at":526,"id":527,"uuid":528,"content":702,"slug":669,"full_slug":670,"sort_by_date":671,"position":672,"tag_list":814,"is_startpage":15,"parent_id":674,"meta_data":22,"group_id":675,"first_published_at":676,"release_id":22,"lang":39,"path":22,"alternates":815,"default_full_slug":22,"translated_slugs":22},{"Tags":479,"_uid":530,"body":703,"title":532,"content":704,"component":634,"seoOgImage":787,"keyTakeaways":789,"previewImage":811,"previewTitle":532,"relatedContent":813,"seoDescription":667,"previewDescription":668},[],{"type":17,"content":705},[706,710,716,720,724,730,737,741,747,751,755,759,765,769,773,779,783],{"type":20,"attrs":707,"content":708},{"textAlign":22},[709],{"text":539,"type":26},{"type":82,"attrs":711,"content":712},{"level":84,"textAlign":22},[713],{"text":544,"type":26,"marks":714},[715],{"type":93},{"type":20,"attrs":717,"content":718},{"textAlign":22},[719],{"text":551,"type":26},{"type":20,"attrs":721,"content":722},{"textAlign":22},[723],{"text":556,"type":26},{"type":82,"attrs":725,"content":726},{"level":84,"textAlign":22},[727],{"text":561,"type":26,"marks":728},[729],{"type":93},{"type":20,"attrs":731,"content":732},{"textAlign":22},[733,736],{"text":568,"type":26,"marks":734},[735],{"type":93},{"text":572,"type":26},{"type":20,"attrs":738,"content":739},{"textAlign":22},[740],{"text":577,"type":26},{"type":82,"attrs":742,"content":743},{"level":84,"textAlign":22},[744],{"text":582,"type":26,"marks":745},[746],{"type":93},{"type":20,"attrs":748,"content":749},{"textAlign":22},[750],{"text":589,"type":26},{"type":20,"attrs":752,"content":753},{"textAlign":22},[754],{"text":594,"type":26},{"type":20,"attrs":756,"content":757},{"textAlign":22},[758],{"text":599,"type":26},{"type":82,"attrs":760,"content":761},{"level":84,"textAlign":22},[762],{"text":604,"type":26,"marks":763},[764],{"type":93},{"type":20,"attrs":766,"content":767},{"textAlign":22},[768],{"text":611,"type":26},{"type":20,"attrs":770,"content":771},{"textAlign":22},[772],{"text":616,"type":26},{"type":82,"attrs":774,"content":775},{"level":84,"textAlign":22},[776],{"text":621,"type":26,"marks":777},[778],{"type":93},{"type":20,"attrs":780,"content":781},{"textAlign":22},[782],{"text":628,"type":26},{"type":20,"attrs":784,"content":785},{"textAlign":22},[786],{"text":633,"type":26},{"id":636,"alt":479,"name":479,"focus":479,"title":479,"source":479,"filename":637,"copyright":479,"fieldtype":512,"meta_data":788,"is_external_url":15},{},{"type":17,"content":790},[791],{"type":122,"content":792},[793,799,805],{"type":125,"content":794},[795],{"type":20,"attrs":796,"content":797},{"textAlign":22},[798],{"text":649,"type":26},{"type":125,"content":800},[801],{"type":20,"attrs":802,"content":803},{"textAlign":22},[804],{"text":656,"type":26},{"type":125,"content":806},[807],{"type":20,"attrs":808,"content":809},{"textAlign":22},[810],{"text":663,"type":26},{"id":636,"alt":479,"name":479,"focus":479,"title":479,"source":479,"filename":637,"copyright":479,"fieldtype":512,"meta_data":812,"is_external_url":15},{},[],[],[],[],{"age":818,"cache-control":47,"connection":48,"content-encoding":819,"content-type":50,"date":820,"etag":821,"referrer-policy":53,"sb-be-version":54,"server":55,"transfer-encoding":822,"vary":823,"via":824,"x-amz-cf-id":825,"x-amz-cf-pop":59,"x-cache":60,"x-content-type-options":61,"x-frame-options":62,"x-permitted-cross-domain-policies":63,"x-request-id":826,"x-runtime":827,"x-xss-protection":66},"896","gzip","Fri, 07 Aug 2026 15:47:29 GMT","W\u002F\"282e4a3d966262977d9855f2d49a636d\"","chunked","Origin,Accept-Encoding","1.1 0eae140cb47e1df2572b33198dae08ca.cloudfront.net (CloudFront)","EptJxx8VIy_zo0aYZ0pNFMlZwc3YrRhlhdEudEsigUf1S-8YZ0gjlQ==","cf4f4e39-7775-4dcd-8157-40296c47613f","0.039990",1786118545542]