Q: You are asked to implement a CI check that enforces conventional commit message format (`feat:`, `fix:`, `chore:`, etc.) across all repositories. How do you enforce this both locally and in the CI pipeline?
Local enforcement (pre-commit):
#CI/CD #๐ Supply Chain Security & Advanced CI/CD #L2 #DevOps #Automation #Pipelines
๐๏ธ Candidate Opening & Architectural Context
""In our delivery pipeline supporting multiple engineering squads, pipeline reliability was paramount. The interviewer is testing: Commit linting, pre-commit hooks, CI policy enforcement.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
๐ ๏ธ Production Runbook & Step-by-Step Resolution
1๏ธโฃ
Production Solution & Architecture
Local enforcement (pre-commit): Add commitlint to the repo with husky: A commit with message "updated stuff" is now rejected locally with a clear error message. CI enforcement (catch bypasses): Developers can bypass pre-commit hooks with git commit --no-verify. Add a CI job: This validates every commit in the PR diff. The PR cannot merge until all commits comply. Combine with branch protection to make this check required.
npm install --save-dev @commitlint/cli @commitlint/config-conventional husky
npx husky add .husky/commit-msg 'npx --no -- commitlint --edit "$1"'
๐ก The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Local enforcement (pre-commit):."
โก 60-Second Elevator Pitch Talking Points
- Immediate Triage: Local enforcement (pre-commit):
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement