1. Pipeline Secrets advanced

    Between 31 January and 1 April 2021 an altered Codecov Bash Uploader script exfiltrated the environment variables of every CI job that ran it, and was discovered by a customer comparing the script's checksum against the published one. What is the underlying architectural failure, and which changes remove the class rather than the instance?

    3 min answer codecovci-secretssupply-chainoidc
  2. Pipeline Secrets advanced

    How should secrets be handled in a delivery pipeline, and what is the strongest available approach?

    2 min answer secretsworkload-identityscopingexfiltration
  3. Policy as Code advanced

    A platform team's policy-as-code library has 240 rules. 190 are warn-only because teams objected to blocking. Pipeline output runs to 300 lines and nobody reads it. Two recent incidents were caused by conditions that rules 14 and 87 had been warning about for months. Review this. What would you remove, what would you change, and what would you keep?

    3 min answer policy-as-codegovernancealert-fatigueadmission-control
  4. Policy as Code advanced

    An admission policy requires that every image have a vulnerability scan with no critical findings, and the admission controller calls the scanner's API at admission time to check. The control works. What has the team bought, what are they paying, and when does the bill arrive?

    3 min answer policy-as-codeadmission-controlattestationcoupling
  5. Policy as Code intermediate

    An enterprise wants automated policy enforcement. Where should policies be evaluated, and what makes the approach fail?

    1 min answer policy-as-codeenforcementfeedbackexceptions
  6. Policy as Code advanced Multiple choice

    Your admission-time policy engine becomes unavailable during a deployment window. Should admission fail open - allow the change - or fail closed - block it?

    3 min answer policy-as-codeadmission-controlavailabilityfail-safe
  7. Progressive Delivery advanced

    A canary deployment looks healthy on average latency while a small percentage of users experience severe failures. Which signals should gate the rollout?

    2 min answer progressive-deliverycanarysegmentationbusiness-metrics
  8. Progressive Delivery advanced

    A payments platform wants progressive delivery. What must the rollout observe, and which changes cannot be rolled out progressively at all?

    2 min answer razorpaycanaryrollouthalt
  9. Progressive Delivery advanced

    What should automated rollout gates measure, and how do you prevent both false confidence and false failures?

    2 min answer canarygatessegmentationstatistics
  10. Progressive Delivery advanced

    Your canary analysis compares the canary's error rate against current production. Results are noisy and unreliable. What is methodologically wrong?

    2 min answer netflixcanarystatisticsmethod
  11. Progressive Delivery intermediate

    Your codebase has 340 feature flags. Nobody knows which are live. A recent incident was caused by an untested flag combination. How do you get out of this?

    2 min answer feature-flagstechnical-debtcomplexity
  12. Progressive Delivery advanced

    Your service handles 40 requests per minute. Product wants canary releases with automated analysis. What do you tell them?

    2 min answer canarystatisticsdeployment