>DevOps Interview KB

Advanced DevOps Interview Questions

194 questions

How would you harden a container to run with a read-only root filesystem, given that some part of the application still needs to write to disk somewhere?

AdvancedDocker7 min

Standard Docker volumes are tied to a single host — how would you give containers access to network-backed storage that survives even the host itself being replaced?

AdvancedDocker7 min

A Cloud Function times out mid-execution after partially completing a multi-step operation — what state does it leave behind, and how do you design around this?

AdvancedGCPCloud Functions7 min

After adding a Serverless VPC Access connector to a Cloud Function, cold starts got noticeably slower — why, and is this avoidable?

AdvancedGCPCloud Functions6 min

How would you audit an entire GCP organization to find every principal holding Owner or Editor at the project level, before a security review?

AdvancedGCP7 min

A GCP service account key was accidentally committed to a public repository — walk through your incident response, GCP-specific steps included.

AdvancedGCP8 min

How would you design a CI/CD pipeline's GCP authentication using service account impersonation instead of a downloaded key, and why is that safer?

AdvancedGCP7 min

A bucket scan flags a bucket as publicly readable, but Public Access Prevention shows as enabled — how is that possible, and how do you investigate it?

AdvancedGCPCloud Storage7 min

A signed URL was accidentally shared publicly — can you revoke it before it expires, and how would you design around this risk?

AdvancedGCPCloud Storage7 min

Object versioning was enabled for safety, but a lifecycle rule deleting noncurrent versions caused the same data loss versioning was meant to prevent — how?

AdvancedGCPCloud Storage7 min

A secret was committed several commits ago and has since been rotated, but it's still sitting in the repository's Git history. How do you actually remove it, not just delete it in a new commit?

AdvancedGit7 min

Design a migration from long-lived AWS access keys stored as GitHub Actions secrets to OIDC-based short-lived credentials, for an organization with 40 repositories deploying to production.

AdvancedGitHub ActionsAWSOIDC12 min

How would you scope an OIDC trust policy differently for a GitHub Actions workflow that runs on pull requests versus one that only runs on main?

AdvancedGitHub ActionsAWS8 min

Why is it specifically dangerous to use self-hosted GitHub Actions runners on a public repository, in a way that doesn't apply to a private repository?

AdvancedGitHub Actions7 min

A team wants to auto-merge every Dependabot PR that passes CI, to reduce the toil of manually reviewing hundreds of dependency bumps. What's the actual risk, and how would you design this safely?

AdvancedGitHubDevSecOps8 min

You have a monorepo where a single commit might touch 1 service or 15. How would you use GitLab's dynamic child pipelines so you only run CI for the services that actually changed?

AdvancedGitLab CI/CD8 min

A compliance requirement mandates that every commit merged into a regulated project be cryptographically signed and traceable to a verified author. How would you enforce this in GitLab?

AdvancedGitLab CI/CD7 min

How does Argo CD's ignoreDifferences configuration interact with its automated self-healing (selfHeal) feature?

AdvancedArgo CDKubernetes6 min

A mutating webhook injects configuration into your resources. When should that injected config actually be tracked in Git instead of ignored via ignoreDifferences?

AdvancedArgo CDKubernetes7 min

GitOps means Git is the source of truth for everything deployed, but you obviously can't commit plaintext secrets to Git. How do you actually reconcile this?

AdvancedGitOpsSecurity8 min

How does Helm's --atomic flag change the stuck-release failure mode, and what window of risk does it not actually cover?

AdvancedHelm6 min

How would you share common templates (labels, resource boilerplate) across many microservice charts without copy-pasting them into every chart?

AdvancedHelm7 min

A Helm pre-upgrade hook Job doesn't run before the Deployment update it's supposed to precede — why, and how do you fix the ordering?

AdvancedHelm7 min

A helm rollback succeeds but the application still behaves like the newer version — why might rollback not fully revert the deployed state?

AdvancedHelm7 min