問題文
A build pipeline must deploy applications and read the deployment status through the platform APIs without any person signing in, and the security team wants the permissions of that access to be narrow and revocable. Which arrangement fits?
選択肢
- Create a service account in the identity provider, grant it only the deployment permissions it needs, and let the pipeline sign in with a password.
- Register a connected app that acts for a user, grant it only the deployment permissions it needs, and let it obtain a token with the user credentials.
- Register a connected app that acts on its own behalf, grant it only the deployment permissions it needs, and let it obtain a token with its own credentials.
- Create an access token in the account settings, grant it only the deployment permissions it needs, and let the pipeline call the APIs with it.