Senior DevOps Interview Questions
516 questions across 39 categories
Deeper trade-off and design questions — why a specific approach was chosen, what breaks at scale, and how to reason about a system you didn't build.
How would the safe-migration approach for adding a NOT NULL column to a large table differ on MySQL versus PostgreSQL, given their different online-DDL capabilities?
AdvancedMysqlPostgresql8 min
How do you safely add a NOT NULL column to a large production table without locking it for the duration of a slow backfill?
AdvancedPostgresql9 min
Your database backups have been running successfully every night for two years, but nobody has ever actually restored one. Why is that a real risk, and how would you fix it?
IntermediateDatabases6 min
Under a traffic spike, your application starts throwing 'too many connections' errors from the database, even though the database itself isn't under heavy CPU or memory load. What's happening?
IntermediateDatabases7 min
A user updates their profile, immediately reloads the page, and sees their old data — but only sometimes. What's causing this, and how do you fix it?
AdvancedDatabases8 min
How would you design the actual mechanism that decides whether a given database query goes to the primary or a read replica, for an application that wasn't originally built with this split in mind?
AdvancedDatabases8 min
What's the actual trade-off between synchronous and asynchronous database replication, and how would you decide which to use for a payments system versus an analytics dashboard?
AdvancedDatabases7 min
Your company's microservices architecture has oddly chatty, tightly-coupled services that mirror exactly how your engineering org is divided into teams. Is that a coincidence?
IntermediateDevops6 min
A team's definition of 'done' for infrastructure changes is just 'terraform apply succeeded.' What's actually missing from that definition, and why does it matter?
IntermediateDevops6 min
A team is proud that their service hasn't had a major incident in 8 months, but when something does break, it takes hours to recover. Which reliability metric should they actually be optimizing for?
IntermediateDevops6 min
What's the actual difference between idempotency and "safe to re-run" — can a task be safely re-run without actually being idempotent?
IntermediateDevops6 min
How would you tell whether a company's "Platform Engineering" team is genuinely building self-service tooling, versus just being the old ops team under a new name?
IntermediatePlatform Engineering6 min
Joining a company with none of DevOps, SRE, or Platform Engineering formalized, which would you introduce first, and why?
IntermediateDevops7 min
What's the trade-off between running security scans as a separate CI job versus as a local pre-commit/pre-push hook?
IntermediateDevSecOps6 min
How would you measure whether engineers are actually acting on security scan findings, versus just dismissing them to unblock their PR?
IntermediateDevSecOps6 min
How would you handle a pre-existing backlog of medium-severity security findings that predates your new scanning rollout, without blocking every team's work on day one?
IntermediateDevSecOps7 min
How would you integrate SAST, dependency scanning, and secrets scanning into a CI/CD pipeline without making every single PR painfully slow?
IntermediateDevSecOps8 min
How would you design artifact signing into your CI/CD pipeline so a deployed container image or binary can be verified as genuinely coming from your build, not tampered with in transit?
AdvancedDevSecOps7 min
Your container scanner reports 200+ vulnerabilities in a base image you didn't choose and can't easily replace. How do you triage this into something actionable?
IntermediateDevSecOpsDocker7 min
What does 'build provenance' actually mean in a supply-chain security context, and how would you start implementing it (e.g. via SLSA) for an existing CI pipeline?
AdvancedDevSecOps8 min
Your build just pulled in a package from the public npm registry instead of your internal package with the same name, and it wasn't the version your team published. What's happening, and how do you respond?
AdvancedDevSecOps8 min
What's the actual trade-off between pinning exact dependency versions and allowing floating version ranges, from a supply-chain security perspective?
IntermediateDevSecOps6 min
A customer's procurement team now requires an SBOM for every release. How would you design SBOM generation into your build pipeline so it's actually useful, not just a compliance checkbox?
AdvancedDevSecOps8 min
A widely-used third-party GitHub Action your pipelines depend on was compromised via a stolen maintainer token. What's your actual exposure?
AdvancedDevSecOpsGitHub Actions8 min