⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Platform Engineering & IDP Interview Questions Scenario 15 of 50 in Platform Engineering & IDP
Staff Platform Engineer Platform Engineering Internal Developer Platforms & Catalogs Backstage Security
🎯 Target Role / Context: Staff Platform Engineer Interview · IDP Security Architecture

Q: After rolling out Backstage with Okta OIDC authentication, developers complain that their sessions randomly expire while drafting templates, causing lost work. Additionally, junior developers can trigger production database deletion templates. How do you resolve OIDC token refresh and configure Backstage RBAC?

Diagnosing token refresh failures in Spotify Backstage and implementing fine-grained RBAC policies across engineering squads.

#Platform Engineering #Backstage #Okta #OIDC #RBAC #Security #IDP
🎙️ Candidate Opening & Architectural Context
"Session dropouts in Backstage stem from misconfigured refresh token lifecycles and missing session stores. Granular access control requires implementing Backstage's new Permission Framework (`@backstage/plugin-permission-backend`) backed by Okta group claims."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Configure Persistent Session Storage & Offline Refresh Tokens

Configure Okta to grant `offline_access` scope and configure Backstage backend PostgreSQL session storage so token refreshes occur transparently in the background.

# app-config.yaml
auth:
  providers:
    okta:
      development:
        clientId: ${OKTA_CLIENT_ID}
        clientSecret: ${OKTA_CLIENT_SECRET}
        audience: ${OKTA_AUDIENCE}
        additionalScopes: ['offline_access', 'groups']
2

Implement Custom Permission Policy for Scaffolder Templates

Implement a `PermissionPolicy` class in `packages/backend/src/plugins/permission.ts` inspecting the user's Okta groups to restrict sensitive templates.

class CustomPolicy implements PermissionPolicy {
  async handle(request: PolicyQuery, user?: BackstageIdentityResponse): Promise<PolicyDecision> {
    if (isTemplateAction(request)) {
      const isProdDbTemplate = request.attributes?.templateId === 'delete-prod-db';
      const isStaffOrLead = user?.identity.ownershipEntityRefs.includes('group:default/tech-leads');
      if (isProdDbTemplate && !isStaffOrLead) return { result: AuthorizeResult.DENY };
    }
    return { result: AuthorizeResult.ALLOW };
  }
}
Advertisement
3

Auto-Draft State Recovery in Scaffolder UI

Enable local storage draft persistence in the Backstage frontend so that form progress is never lost even if network connectivity blips.

Pro Tip: Security Principle: Map authorization to company Okta groups directly; never manage static user lists inside YAML config files.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Secure Backstage by configuring Okta offline_access refresh tokens, persisting sessions in PostgreSQL, and enforcing policy-as-code via the Backstage Permission Framework."
⚡ 60-Second Elevator Pitch Talking Points
  • Include offline_access in Okta scopes to allow silent background token refreshes.
  • Implement Backstage Permission Framework to gate sensitive infrastructure scaffolding templates by team.
  • Store session states in backend PostgreSQL to prevent session loss on container restarts.
Advertisement
Want more Platform Engineering & IDP scenarios?
Explore our complete collection of scenario-based Platform Engineering & IDP interview runbooks.
Browse All Platform Engineering & IDP Questions →