>DevOps Interview KB

Senior DevOps Interview Questions

516 questions across 39 categories

Deeper trade-off and design questions — why a specific approach was chosen, what breaks at scale, and how to reason about a system you didn't build.

How would you audit an existing large Ansible playbook to find all the places check mode's coverage is actually incomplete?

AdvancedAnsible7 min

Why does Ansible's --check mode skip most command/shell tasks by default, and what does that imply about how much you can actually trust --check --diff output?

IntermediateAnsible6 min

What's the risk of a task using check_mode: false to force it to always execute, even during a supposed dry run?

IntermediateAnsible6 min

How would you build confidence in a playbook's check-mode output when it has to use command/shell for something with no equivalent module?

AdvancedAnsible7 min

How would you convince a team to invest time in an idempotency retrofit when the playbook "already works"?

IntermediateAnsible6 min

An Ansible playbook reports "changed" on the same tasks every single run, even when nothing about the target host actually changed. Why, and how do you fix it?

IntermediateAnsible8 min

How would you retrofit idempotency checks into an existing large Ansible playbook full of command/shell tasks, without rewriting every task at once?

AdvancedAnsible8 min

What signals would tell you an Ansible shell task is safe to leave alone versus genuinely needs fixing?

IntermediateAnsible6 min

How would you verify a purpose-built module replacement produces the exact same end state as the shell command it replaced, in a repeatable way?

AdvancedAnsible7 min

How do Argo CD's resource hooks compare to Helm's pre-install/pre-upgrade hooks, given Argo CD can also deploy Helm charts directly?

AdvancedArgo CDHelm7 min

How would you distinguish 'the migration itself is broken' from 'this was a transient failure worth retrying,' in terms of alerting design?

AdvancedArgo CD7 min

How would you clean up old, hash-named Argo CD migration Jobs so they don't accumulate indefinitely in the cluster?

IntermediateArgo CDKubernetes6 min

What would go wrong if you used content-hash naming for an Argo CD Job that's meant to run on every sync instead?

IntermediateArgo CDKubernetes6 min

How do you control the order Argo CD applies resources within a single Application, e.g. making sure a database migration Job completes before the Deployment that depends on it rolls out?

AdvancedArgo CDKubernetes8 min

What would break if a Helm chart's hooks specifically relied on helm rollback semantics, and how would that manifest when deployed via Argo CD instead?

AdvancedArgo CDHelm7 min

How would you handle an Argo CD migration Job that should run on every sync versus one that should only run when the migration itself actually changed?

AdvancedArgo CDKubernetes7 min

Why might Argo CD's sync-wave model be considered more expressive than Helm's own hook-weight system for controlling ordering?

AdvancedArgo CDHelm6 min

If an Argo CD PreSync hook Job fails, does Argo CD retry it automatically? How would you make that retry behavior explicit instead of relying on defaults?

IntermediateArgo CDKubernetes6 min

What happens to a PreSync hook Job that succeeded on a previous sync, if the overall sync is retried after a later hook fails?

AdvancedArgo CDKubernetes6 min

How does Argo CD's syncPolicy.retry backoff configuration work, and how would you tune it for a slow-starting dependency?

IntermediateArgo CD6 min

How would you verify a Helm chart's hooks behave correctly under Argo CD before migrating a production chart from helm install to GitOps?

AdvancedArgo CDHelm7 min

How would you audit whether an ECS task role or Lambda execution role is actually scoped tightly, versus just copy-pasted from a broader existing role?

AdvancedAWS7 min

What CloudTrail-based alerting would you specifically set up for a narrowly-scoped static-key IAM user, and how would you tune it to avoid false positives?

AdvancedAWS7 min

How would you design the exception process for an SCP blocking IAM user creation, so legitimate cases aren't blocked indefinitely by bureaucracy?

AdvancedAWS7 min