โšก ~/naveed Interview Prep
โšก Portfolio Home โœ๏ธ Engineering Blog Deep Dives ๐ŸŽฏ Interview Hub 998+ Scenarios โ˜ธ๏ธ Kubernetes Mastery Hub 24 Modules ๐ŸŽฎ DevOps Arcade & Quizzes Subnet Blitz โšก ๐Ÿ—บ๏ธ DevOps Roadmaps PDFs & Guides ๐Ÿค– Morpheus Analysis AI Quant โ†— ๐Ÿ› ๏ธ Developer Tools Utilities ๐Ÿงช Labs & Experiments ๐Ÿ“„ Interactive CV & Certs ๐Ÿ”— All Links & Socials โšก Join The Dispatch (Weekly SRE Newsletter) →
Staff SRE / Principal Architect [L3] CI/CD ๐Ÿ” Supply Chain Security & Advanced CI/CD Staff SRE Scenario [L3]

Q: Your pipeline deploys to Kubernetes using `kubectl apply -f manifests/`. A colleague points out that no one validates the YAML before it hits the cluster โ€” a typo in a resource limit field goes undetected until the pod fails to schedule. How do you add static validation to the pipeline?

Add a dedicated manifest validation stage before any kubectl apply:

#CI/CD #๐Ÿ” Supply Chain Security & Advanced CI/CD #L3 #DevOps #Automation #Pipelines
๐ŸŽ™๏ธ Candidate Opening & Architectural Context
""During a high-stakes release, we hit a similar deployment challenge and resolved it with automated safeguards. The interviewer is testing: Kubernetes manifest validation, kubeconform, OPA/Conftest policy gates.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

๐Ÿ› ๏ธ Production Runbook & Step-by-Step Resolution

1๏ธโƒฃ

Initial Diagnostics & Root Cause Analysis

Add a dedicated manifest validation stage before any kubectl apply:

  • Schema validation with kubeconform:
  • Policy validation with conftest (OPA):
  • Dry-run against a real cluster: kubectl apply --dry-run=server -f manifests/ sends the manifest to the API server for server-side validation without creating any resources. This catches admission webhook rejections too.
2๏ธโƒฃ

Remediation & Permanent Safeguards

This validates every field against the official Kubernetes OpenAPI schema. A wrong resource.limits.memory: "512Mi" (note the wrong field path) fails immediately. Write Rego policies enforcing your standards: Run: conftest test manifests/. This catches policy violations the schema alone can't catch.

kubeconform -strict -kubernetes-version 1.30.0 manifests/
๐Ÿ’ก The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Schema validation with kubeconform:."
โšก 60-Second Elevator Pitch Talking Points
  • Schema validation with kubeconform:
  • Policy validation with conftest (OPA):
  • Dry-run against a real cluster: kubectl apply --dry-run=server -f manifests/ sends the manifest t...
Advertisement
Want more CI/CD scenarios?
Explore our complete collection of scenario-based CI/CD interview runbooks.
Browse All CI/CD Questions →

๐Ÿ“š Related Production Scenarios in CI/CD