โšก ~/naveed Interview Prep
โšก Portfolio Home โœ๏ธ Engineering Blog Deep Dives ๐ŸŽฏ Interview Hub 998+ Scenarios โ˜ธ๏ธ Kubernetes Mastery Hub 24 Modules ๐ŸŽฎ DevOps Arcade & Quizzes Subnet Blitz โšก ๐Ÿ—บ๏ธ DevOps Roadmaps PDFs & Guides ๐Ÿค– Morpheus Analysis AI Quant โ†— ๐Ÿ› ๏ธ Developer Tools Utilities ๐Ÿงช Labs & Experiments ๐Ÿ“„ Interactive CV & Certs ๐Ÿ”— All Links & Socials โšก Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE [L2] CI/CD ๐Ÿ” Supply Chain Security & Advanced CI/CD Production Scenario [L2]

Q: Your team runs `terraform plan` inside a GitHub Actions workflow. You notice that the plan output printed in the CI logs exposes the full contents of a secret stored in AWS Secrets Manager (because a developer added `output "db_password" { value = data.aws_secretsmanager_secret_version.db.secret_string }`). How do you prevent secret exfiltration via plan output?

Three controls must work together:

#CI/CD #๐Ÿ” Supply Chain Security & Advanced CI/CD #L2 #DevOps #Automation #Pipelines
๐ŸŽ™๏ธ Candidate Opening & Architectural Context
""When developers encounter this build or release bottleneck, my first goal is unblocking velocity safely. The interviewer is testing: Terraform sensitive outputs, CI log masking, least-privilege planning.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

๐Ÿ› ๏ธ Production Runbook & Step-by-Step Resolution

1๏ธโƒฃ

Initial Diagnostics & Root Cause Analysis

Three controls must work together:

  • Mark outputs sensitive in Terraform: output "db_password" { value = "..." sensitive = true }. Terraform will redact its value in plan output with (sensitive value).
  • Use a read-only IAM role for plan jobs โ€” the plan role has permissions to *read* state but not secretsmanager:GetSecretValue. This means the plan step never even retrieves the plaintext secret.
  • Scrub logs in CI: GitHub Actions allows adding secrets to the masked list dynamically: echo "::add-mask::$SECRET_VALUE". Any occurrence of that string in subsequent log output is replaced with ***.
2๏ธโƒฃ

Remediation & Permanent Safeguards

๐Ÿ’ก The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Mark outputs sensitive in Terraform: output "db_password" { value = "..." sensitive = true }. Terraform will redact its value in p."
โšก 60-Second Elevator Pitch Talking Points
  • Mark outputs sensitive in Terraform: output "db_password" { value = "..." sensitive = true }. Ter...
  • Use a read-only IAM role for plan jobs โ€” the plan role has permissions to *read* state but not se...
  • Scrub logs in CI: GitHub Actions allows adding secrets to the masked list dynamically: echo "::ad...
Advertisement
Want more CI/CD scenarios?
Explore our complete collection of scenario-based CI/CD interview runbooks.
Browse All CI/CD Questions →

๐Ÿ“š Related Production Scenarios in CI/CD