⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] CI/CD GitHub Actions Production Scenario [L2]

Q: How do you securely pass secrets to a GitHub Actions workflow without hardcoding them?

1. GitHub Secrets — go to repo Settings → Secrets → add secrets. Reference in workflow as ${{ secrets.MY_SECRET }}. Never printed in logs.

#CI/CD #GitHub Actions #L2 #DevOps #Automation #Pipelines
🎙️ Candidate Opening & Architectural Context
""In our delivery pipeline supporting multiple engineering squads, pipeline reliability was paramount. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Initial Diagnostics & Root Cause Analysis

No access keys stored. The IAM role trusts GitHub Actions via OIDC. Most secure approach.

  • GitHub Secrets — go to repo Settings → Secrets → add secrets. Reference in workflow as ${{ secrets.MY_SECRET }}. Never printed in logs.
  • GitHub Environment Secrets — scope secrets to specific environments (production, staging). Require environment protection rules (manual approval before accessing prod secrets).
  • OIDC with AWS/GCP — instead of storing cloud credentials as secrets, use GitHub's OIDC provider to get short-lived credentials:
2️⃣

Remediation & Permanent Safeguards

- uses: aws-actions/configure-aws-credentials@v2
  with:
    role-to-assume: arn:aws:iam::123456789:role/github-actions-role
    aws-region: us-east-1
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: GitHub Secrets — go to repo Settings → Secrets → add secrets. Reference in workflow as ${{ secrets.MY_SECRET }}. Never printed in ."
⚡ 60-Second Elevator Pitch Talking Points
  • GitHub Secrets — go to repo Settings → Secrets → add secrets. Reference in workflow as ${{ secret...
  • GitHub Environment Secrets — scope secrets to specific environments (production, staging). Requir...
  • OIDC with AWS/GCP — instead of storing cloud credentials as secrets, use GitHub's OIDC provider t...
Advertisement
Want more CI/CD scenarios?
Explore our complete collection of scenario-based CI/CD interview runbooks.
Browse All CI/CD Questions →

📚 Related Production Scenarios in CI/CD