Q: How do you prevent bad configs from reaching production in a CI/CD pipeline?
Multi-stage CI/CD defense-in-depth framework for configuration management: schema validation, Helm linting and templating, strict Kubeconform checks, OPA/Conftest policy-as-code, and server-side dry runs.
#CI/CD #Kubernetes #Policy as Code #Helm #Kubeconform #OPA #Conftest
🎙️ Candidate Opening & Architectural Context
"I use layered controls across every stage of the pipeline: schema validation, linting, render checks, policy-as-code, environment-specific tests, and progressive delivery. For Kubernetes and Helm configs, I run helm lint, helm template, kubeconform with strict schemas, Conftest or Kyverno policy checks, secret scanning, and dry-run apply against a test API server before deployment."
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Static Linting, Template Rendering & Schema Validation
Catch syntax, type mismatches, and deprecated Kubernetes schema errors early in pull requests:
# Helm validation and rendering
helm lint charts/api
helm template api charts/api -f values-prod.yaml > rendered.yaml
# Kubernetes schema validation
kubeconform -strict -summary rendered.yaml
kubectl apply --dry-run=server -f rendered.yaml
- Helm Lint & Template: Run
helm lintto detect chart errors andhelm templateagainst environment values to produce concrete manifests. - Kubeconform Strict Schema Checking: Validate rendered YAML against official Kubernetes OpenAPI schemas with
-strictto reject undocumented fields. - Server-Side Dry Run: Execute
kubectl apply --dry-run=serveragainst an ephemeral or staging cluster to validate mutating webhooks and CRDs.
2️⃣
Policy-as-Code (OPA/Conftest) & Secret Scanning
Enforce organization security standards and prevent misconfigurations automatically:
# Policy checks with OPA Conftest
conftest test rendered.yaml --policy policy/
# Secret scanning and YAML linting
yamllint .
gitleaks detect --source .
- OPA / Conftest Guardrails: Block configs that violate security baselines (e.g., privileged containers, missing resource limits, insecure Ingress TLS, root user).
- Secret Leak Prevention: Run Gitleaks or Trufflehog in pre-commit and CI to ensure API keys and passwords never enter git.
- Environment Promotion Gates: Mandate PR reviews, protected branches, and successful deployment to staging before promoting to production.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Layer static linting (helm lint, kubeconform), policy-as-code (Conftest/OPA), secret scanning (Gitleaks), and server-side dry runs in CI so invalid configurations fail before touching production clusters."
⚡ 60-Second Elevator Pitch Talking Points
- Implement static verification in CI: helm lint, helm template, and kubeconform -strict against Kubernetes schemas.
- Enforce organizational security policies using OPA Conftest and scan for accidental secrets with Gitleaks.
- Validate against real Kubernetes admission webhooks with kubectl apply --dry-run=server in preview environments.
Advertisement