Security Methods for Agentless Infrastructure Manage Ment via Continuous Delivery Pipelines
Keywords:
risk management, continuous control, supply chain security, software infrastructure as code, infrastructure managementAbstract
This article presents an analysis of security methods for agentless infrastructure management in the context of continuous delivery. The study is conducted as a structured analytical review and synthesis of academic publications focused on CI/CD security, software supply chain protection, infrastructure as code, policy management, and control automation. The main focus is placed on the relationship between delivery pipeline characteristics, risk distribution, threat detection mechanisms, and their impact on system resilience. Key sources of risk are examined, including code, configurations, dependencies, credentials, and the runtime environment, along with control parameters that determine the level of infrastructure security. It is established that risk in such systems is systemic in nature and emerges through transitions between stages rather than at isolated points. Existing approaches based on fragmented checks and static models are shown to lack continuity of control and to lose effectiveness in the absence of inter-stage connectivity. An original model is proposed, reflecting the transition from isolated protection mechanisms to a unified framework integrating telemetry, supply composition, behavioural data, and automated response. The article may be of interest to specialists in information security, DevSecOps, cloud technologies, and infrastructure management.
References
[1]. Anugula, P., Bhardwaj, A. K., Chhibber, N., Tewari, R., Khemka, S., & Ranjan, P. (2025). AutoGuard: A self-healing proactive security layer for DevSecOps pipelines using reinforcement learning. arXiv. https://doi.org/10.48550/arXiv.2512.04368
[2] Bedoya, M., Palacios, S., Díaz-López, D., et al. (2024). Enhancing DevSecOps practice with large language models and security chaos engineering. International Journal of Information Security, 23, 3765–3788. https://doi.org/10.1007/s10207-024-00909-w
[3] Dhandapani, S. (2025). Enhancing software supply chain security through STRIDE-based threat modelling of CI/CD pipelines. arXiv. https://doi.org/10.48550/arXiv.2506.06478
[4] Esposito, M., Robredo, M., Bakhtin, A., et al. (2026). Generative AI as an infrastructure copilot: Automating infrastructure-as-code across the DevSecOps lifecycle. Automated Software Engineering, 33, 58. https://doi.org/10.1007/s10515-026-00600-5
[5] Rajapakse, R. N., Zahedi, M., Babar, M. A., & Shen, H. (2022). Challenges and solutions when adopting DevSecOps: A systematic review. Information and Software Technology, 141, 106700. https://doi.org/10.1016/j.infsof.2021.106700
[6] Manolov, V., Gotseva, D., & Hinov, N. (2026). Analysis of GitHub Advanced Security: Security integration in GitHub and Azure DevOps. Future Internet, 18(2), 99. https://doi.org/10.3390/fi18020099
[7] Miñón, R., Diaz-de-Arcaya, J., Torre-Bastida, A. I., et al. (2025). ArtifactOps and ArtifactDL: A methodology and a language for conceptualizing and operationalising different types of pipelines. Journal of Cloud Computing, 14, 42. https://doi.org/10.1186/s13677-025-00761-w
[8] Mohammed, K. I., Shanmugam, B., & El-Den, J. (2025). Evolution of DevSecOps and its influence on application security: A systematic literature review. Technologies, 13(12), 548. https://doi.org/10.3390/technologies13120548
[9] Nascimento, B., Santos, R., Henriques, J., Bernardo, M. V., & Caldeira, F. (2024). Availability, scalability, and security in the migration from container-based to cloud-native applications. Computers, 13(8), 192. https://doi.org/10.3390/computers13080192
[10] Pahl, C., Sezen, Ö. C., & Hofer, F. (2026). Artificial intelligence for infrastructure-as-code—A systematic literature review. Electronics, 15(4), 755. https://doi.org/10.3390/electronics15040755
[11] Williams, L. et al. (2025). Research directions in software supply chain security. ACM Transactions on Software Engineering and Methodology. https://doi.org/10.1145/3714464
[12] Prates, L., & Pereira, R. (2025). DevSecOps practices and tools. International Journal of Information Security, 24, 11. https://doi.org/10.1007/s10207-024-00914-z
[13] Pan, Z. et al. (2024). Ambush from all sides: Understanding security threats in open-source software CI/CD pipelines. IEEE Transactions on Dependable and Secure Computing, 21(1), 403–418. https://ieeexplore.ieee.org/document/10061526
[14] Saleh, S. M., Madhavji, N., & Steinbacher, J. (2025). A systematic literature review on continuous integration and deployment (CI/CD) for secure cloud computing. arXiv. https://doi.org/10.48550/arXiv.2506.08055
[15] Zakharchenko, A. (2026). Integrating continuous compliance into DevSecOps pipelines: A data engineering perspective. Software, 5(1), 6. https://doi.org/10.3390/software501000
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Oleksandr Shevchenko

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.
Authors who submit papers with this journal agree to the following terms.