Senior DevOps Interview Questions
516 questions across 39 categories
Deeper trade-off and design questions — why a specific approach was chosen, what breaks at scale, and how to reason about a system you didn't build.
How would you grant a contractor temporary access to a GCP project that automatically expires, without manually revoking it later?
IntermediateGCP6 min
A service account in Project A needs to read from a Cloud Storage bucket in Project B — how does IAM actually handle this cross-project access?
IntermediateGCP6 min
A GCP service account key was accidentally committed to a public repository — walk through your incident response, GCP-specific steps included.
AdvancedGCP8 min
How would you design least-privilege IAM for a Cloud Function that reads from Pub/Sub and writes to a specific Cloud Storage bucket?
IntermediateGCP6 min
A project has correct IAM roles, but you still need to guarantee no VM ever gets a public IP — is that an IAM problem, or something else?
IntermediateGCP6 min
How would you design a CI/CD pipeline's GCP authentication using service account impersonation instead of a downloaded key, and why is that safer?
AdvancedGCP7 min
A GKE workload needs to call a GCP API — should it use Workload Identity or a mounted service account key file, and why?
IntermediateGCPGKE7 min
A browser-based app can list bucket contents but fails to upload directly to Cloud Storage with a CORS error — how do you fix the bucket's CORS configuration?
IntermediateGCPCloud Storage6 min
How would you choose between a dual-region and a multi-region Cloud Storage bucket for a workload needing regional resilience?
IntermediateGCPCloud Storage6 min
How would you design Cloud Storage lifecycle rules to automatically reduce cost as objects age, without risking premature deletion of data still in use?
IntermediateGCPCloud Storage7 min
A bucket scan flags a bucket as publicly readable, but Public Access Prevention shows as enabled — how is that possible, and how do you investigate it?
AdvancedGCPCloud Storage7 min
A signed URL was accidentally shared publicly — can you revoke it before it expires, and how would you design around this risk?
AdvancedGCPCloud Storage7 min
Why does Google recommend uniform bucket-level access over fine-grained ACLs, and what actually breaks when you enable it on an existing bucket?
IntermediateGCPCloud Storage6 min
Object versioning was enabled for safety, but a lifecycle rule deleting noncurrent versions caused the same data loss versioning was meant to prevent — how?
AdvancedGCPCloud Storage7 min
A teammate's work was lost after a force-push overwrote their commits on a shared branch. How would you recover it?
IntermediateGit7 min
A bug was introduced somewhere in the last 200 commits, but nobody knows exactly which one, and the bug doesn't reproduce reliably enough to eyeball the diffs. How would you find the exact commit using git bisect?
IntermediateGit6 min
A critical bug fix landed on main, and you need to get it onto a release branch that's several weeks behind. Should you cherry-pick the fix, or rebase the release branch onto main?
IntermediateGit6 min
A feature branch has 15 messy commits ('wip', 'fix typo', 'actually fix it') before it's ready for review. How would you use interactive rebase to clean this up into a coherent history?
IntermediateGit6 min
A repository has grown to several gigabytes because it stores large binary assets (design files, ML model weights) directly, making every clone painfully slow. How would you fix this?
IntermediateGit7 min
A teammate resolved a merge conflict by keeping 'their' version of every conflicting hunk without actually reading the other side's changes. Why is that dangerous, and how should conflicts actually be resolved?
IntermediateGit6 min
A secret was committed several commits ago and has since been rotated, but it's still sitting in the repository's Git history. How do you actually remove it, not just delete it in a new commit?
AdvancedGit7 min
After migrating to OIDC, how would you detect and alert on someone reintroducing a long-lived AWS access key as a GitHub secret?
IntermediateGitHub ActionsAWS7 min
Design a migration from long-lived AWS access keys stored as GitHub Actions secrets to OIDC-based short-lived credentials, for an organization with 40 repositories deploying to production.
AdvancedGitHub ActionsAWSOIDC12 min
How would you scope an OIDC trust policy differently for a GitHub Actions workflow that runs on pull requests versus one that only runs on main?
AdvancedGitHub ActionsAWS8 min