Q: You're building microservices and you want every service's Docker image to be uniquely and traceably tagged. What's your tagging strategy?
Never use latest in production — it makes rollback and debugging impossible.
#CI/CD #Docker in CI/CD #L3 #DevOps #Automation #Pipelines
🎙️ Candidate Opening & Architectural Context
""During a high-stakes release, we hit a similar deployment challenge and resolved it with automated safeguards. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Never use latest in production — it makes rollback and debugging impossible.
- Git commit SHA —
my-service:abc1234— fully unique, traceable.git rev-parse --short HEAD. - Semantic version + SHA —
my-service:1.4.2-abc1234— human readable + traceable. - Branch + SHA for non-main branches —
my-service:feature-login-abc1234for testing.
2️⃣
Remediation & Permanent Safeguards
Good strategies: Workflow: In Kubernetes, the deployment image tag is updated to the new SHA. ArgoCD/Flux detects the change and deploys. --- ## 🟣 Testing in CI
IMAGE_TAG=$CI_COMMIT_SHA # GitLab
# or
IMAGE_TAG=$GITHUB_SHA # GitHub Actions
docker build -t my-registry/my-service:$IMAGE_TAG .
docker push my-registry/my-service:$IMAGE_TAG
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Git commit SHA — my-service:abc1234 — fully unique, traceable. git rev-parse --short HEAD.."
⚡ 60-Second Elevator Pitch Talking Points
- Git commit SHA — my-service:abc1234 — fully unique, traceable. git rev-parse --short HEAD.
- Semantic version + SHA — my-service:1.4.2-abc1234 — human readable + traceable.
- Branch + SHA for non-main branches — my-service:feature-login-abc1234 for testing.
Advertisement