Q: Developers are committing secrets (API keys) to your Git repository. How do you prevent this?
Pre-commit prevention (stop it before it lands in Git):
#CI/CD #Then copy app code (changes every commit) #L2 #DevOps #Automation #Pipelines
🎙️ Candidate Opening & Architectural Context
""In our delivery pipeline supporting multiple engineering squads, pipeline reliability was paramount. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Pre-commit prevention (stop it before it lands in Git):
- Pre-commit hooks — use tools like
detect-secrets,gitleaks, ortruffleHogin a pre-commit hook. The commit fails if secrets are detected. - Lefthook or Husky — manage git hooks across the team.
- Add a secret scanning step in CI:
gitleaks detect --source=.— fails the pipeline if secrets found. - GitLab has built-in secret detection. GitHub has secret scanning (free for public repos, enterprise for private).
2️⃣
Remediation & Permanent Safeguards
CI pipeline detection (catch it early in the pipeline): Post-commit response: Best approach: pre-commit hooks + CI step + developer education.
- If a secret was committed and pushed, immediately rotate the credential (treat as compromised).
- Remove from git history with
git filter-repo(notgit filter-branch— too slow).
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Pre-commit hooks — use tools like detect-secrets, gitleaks, or truffleHog in a pre-commit hook. The commit fails if secrets are de."
⚡ 60-Second Elevator Pitch Talking Points
- Pre-commit hooks — use tools like detect-secrets, gitleaks, or truffleHog in a pre-commit hook. T...
- Lefthook or Husky — manage git hooks across the team.
- Add a secret scanning step in CI: gitleaks detect --source=. — fails the pipeline if secrets found.
Advertisement