1. Multi-Region Rollout advanced

    You own the system that rolls changes out to thirty regions. During an incident the commander asks how fast you can get a fix everywhere. Walk me through your answer.

    3 min answer fastlymulti-regionrolloutincident-response
  2. Pipeline Architecture advanced

    A deployment platform's build queue is forty minutes deep after a popular framework release. Before adding capacity, what should be examined in the queue itself?

    2 min answer vercelrailwaybuildsqueueing
  3. Pipeline Architecture advanced

    How should a delivery pipeline be structured for a large monorepo where most changes affect a small part of the system?

    2 min answer pipelinemonoreposelectioncaching
  4. Pipeline Secrets advanced

    A team stores no credentials in its repository. The cloud role is assumed through OIDC federation, the registry token lives in a managed secret store, and the build never prints it. Over one weekend an attacker publishes a malicious version of the team's package, and the audit trail shows the push came from the team's own pipeline. Trace how, and name the structural fix.

    3 min answer pipeline-secretsfork-triggeroidcsupply-chain
  5. Pipeline Secrets advanced

    Between 31 January and 1 April 2021 an altered Codecov Bash Uploader script exfiltrated the environment variables of every CI job that ran it, and was discovered by a customer comparing the script's checksum against the published one. What is the underlying architectural failure, and which changes remove the class rather than the instance?

    3 min answer codecovci-secretssupply-chainoidc
  6. Pipeline Secrets advanced

    How should secrets be handled in a delivery pipeline, and what is the strongest available approach?

    2 min answer secretsworkload-identityscopingexfiltration
  7. Policy as Code advanced

    A platform team's policy-as-code library has 240 rules. 190 are warn-only because teams objected to blocking. Pipeline output runs to 300 lines and nobody reads it. Two recent incidents were caused by conditions that rules 14 and 87 had been warning about for months. Review this. What would you remove, what would you change, and what would you keep?

    3 min answer policy-as-codegovernancealert-fatigueadmission-control
  8. Policy as Code advanced

    An admission policy requires that every image have a vulnerability scan with no critical findings, and the admission controller calls the scanner's API at admission time to check. The control works. What has the team bought, what are they paying, and when does the bill arrive?

    3 min answer policy-as-codeadmission-controlattestationcoupling
  9. Policy as Code advanced Multiple choice

    Your admission-time policy engine becomes unavailable during a deployment window. Should admission fail open - allow the change - or fail closed - block it?

    3 min answer policy-as-codeadmission-controlavailabilityfail-safe
  10. Progressive Delivery advanced

    A canary deployment looks healthy on average latency while a small percentage of users experience severe failures. Which signals should gate the rollout?

    2 min answer progressive-deliverycanarysegmentationbusiness-metrics
  11. Progressive Delivery advanced

    A payments platform wants progressive delivery. What must the rollout observe, and which changes cannot be rolled out progressively at all?

    2 min answer razorpaycanaryrollouthalt
  12. Progressive Delivery advanced

    What should automated rollout gates measure, and how do you prevent both false confidence and false failures?

    2 min answer canarygatessegmentationstatistics