Staff / Principal Interview Questions
228 questions across 34 categories
Expert-level and system-design questions — the scope, trade-offs, and organizational reasoning expected at the most senior technical levels.
How would you manage Secrets across dev/staging/prod without committing plaintext to Git, while staying GitOps-declarative?
AdvancedKubernetes8 min
A Secret manifest with real credentials was committed to a public repo — how does remediation differ from a generic leaked-secret response?
AdvancedKubernetes7 min
A custom resource is stuck in Terminating status indefinitely after being deleted — what's a finalizer, and how does it cause this?
AdvancedKubernetes7 min
Custom resources are being created and updated, but the operator managing them appears to have silently stopped reconciling — how do you diagnose it?
AdvancedKubernetes8 min
For distributing a complex application, when would you package it as a Helm chart versus building a dedicated operator for it?
AdvancedKubernetesHelm7 min
How would you test a custom operator's reconcile logic without needing a full live cluster for every test run?
AdvancedKubernetes7 min
A CRD needs a breaking schema change, but existing custom resources and consumers depend on the old shape — how do you version a CRD safely?
ExpertKubernetes8 min
A team wants to automate a repetitive operational task with a custom Kubernetes operator — when is that actually the right tool versus overkill?
AdvancedKubernetes7 min
How would you troubleshoot connectivity that works within a node but fails between pods on different nodes?
AdvancedKubernetes8 min
A pod resolves a Service's DNS name intermittently but not consistently — how do you investigate CoreDNS itself?
AdvancedKubernetes8 min
How would you migrate a cluster from one CNI plugin to another without a full cluster rebuild — what's actually risky about it?
ExpertKubernetes8 min
What does a pod's ndots DNS setting default to, and how can it cause unexpectedly slow external DNS lookups?
AdvancedKubernetes7 min
A NetworkPolicy is applied but pods that should be blocked can still communicate — why might it not be enforced?
AdvancedKubernetes7 min
How would you debug a Service routing failure differently if you were using a service mesh like Istio instead of plain kube-proxy-based Services?
AdvancedKubernetesIstio7 min
A security team rejects a pod spec requesting privileged: true — what SecurityContext alternatives would you propose to meet the actual requirement?
AdvancedKubernetes7 min
How would you audit an entire cluster to find ServiceAccounts with effectively cluster-admin permissions before a security review?
AdvancedKubernetes7 min
A pod's ServiceAccount token was found in a public repo — what's your incident response, and how do you reduce blast radius for next time?
ExpertKubernetes8 min
How would you design least-privilege RBAC for a CI/CD pipeline that deploys to multiple namespaces, without granting cluster-admin?
AdvancedKubernetes8 min
A Pod Security Standard (restricted) rejects a legacy workload that needs to run as root — how do you handle this without disabling the standard cluster-wide?
AdvancedKubernetes7 min
How would you distinguish a genuine memory leak from a legitimately growing in-memory cache, using only Kubernetes-level metrics?
AdvancedKubernetesPrometheus8 min
Two pods that should never co-locate keep landing on the same node — what's wrong with the anti-affinity rule?
AdvancedKubernetes7 min
A critical pod gets preempted by a seemingly lower-priority pod during a resource crunch — how do you investigate and prevent it?
AdvancedKubernetes7 min
How would you dedicate a set of nodes exclusively to one team's workloads, while still letting that team's pods run elsewhere too?
AdvancedKubernetes7 min
How would you troubleshoot a pod stuck Pending even though kubectl describe pod shows no scheduling errors at all?
ExpertKubernetes8 min