⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] CI/CD Then copy app code (changes every commit) Production Scenario [L2]

Q: Developers are committing secrets (API keys) to your Git repository. How do you prevent this?

Pre-commit prevention (stop it before it lands in Git):

#CI/CD #Then copy app code (changes every commit) #L2 #DevOps #Automation #Pipelines
🎙️ Candidate Opening & Architectural Context
""In our delivery pipeline supporting multiple engineering squads, pipeline reliability was paramount. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Initial Diagnostics & Root Cause Analysis

Pre-commit prevention (stop it before it lands in Git):

  • Pre-commit hooks — use tools like detect-secrets, gitleaks, or truffleHog in a pre-commit hook. The commit fails if secrets are detected.
  • Lefthook or Husky — manage git hooks across the team.
  • Add a secret scanning step in CI: gitleaks detect --source=. — fails the pipeline if secrets found.
  • GitLab has built-in secret detection. GitHub has secret scanning (free for public repos, enterprise for private).
2️⃣

Remediation & Permanent Safeguards

CI pipeline detection (catch it early in the pipeline): Post-commit response: Best approach: pre-commit hooks + CI step + developer education.

  • If a secret was committed and pushed, immediately rotate the credential (treat as compromised).
  • Remove from git history with git filter-repo (not git filter-branch — too slow).
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Pre-commit hooks — use tools like detect-secrets, gitleaks, or truffleHog in a pre-commit hook. The commit fails if secrets are de."
⚡ 60-Second Elevator Pitch Talking Points
  • Pre-commit hooks — use tools like detect-secrets, gitleaks, or truffleHog in a pre-commit hook. T...
  • Lefthook or Husky — manage git hooks across the team.
  • Add a secret scanning step in CI: gitleaks detect --source=. — fails the pipeline if secrets found.
Advertisement
Want more CI/CD scenarios?
Explore our complete collection of scenario-based CI/CD interview runbooks.
Browse All CI/CD Questions →

📚 Related Production Scenarios in CI/CD