A kill switch is a single, governed control that disables an automated behavior everywhere at once. In pipeline security, it is the emergency brake for injected scanning: when a scanner outage or bad configuration starts failing every build in the organization, the kill switch stops the bleeding in one audited action instead of a hundred panicked YAML edits.

Properties of a real kill switch

  • One switch, effective estate-wide, without uninstalling anything.
  • Authorized through a control plane — not whoever edits an extension setting fastest.
  • Audited: who flipped it, when, and when it was restored.
  • Layered: per-pipeline disable beneath it, so the global switch stays reserved for true emergencies.

Why it enables stricter enforcement

Counterintuitively, a good kill switch makes organizations enforce more, not less: teams accept blocking policies far more readily when the recovery path from a false alarm is minutes and governed, rather than heroic and improvised.

RELATED CONCEPTS