⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Platform Engineering & IDP Interview Questions Scenario 33 of 50 in Platform Engineering & IDP
Senior Platform Engineer Platform Engineering Control Planes & Crossplane Cloud Vending
🎯 Target Role / Context: Senior Platform Engineer Interview · Cloud Governance & Storage

Q: Developers create S3 buckets manually, often forgetting SSE-KMS encryption, omitting public access blocks, and leaving terabytes of unexpiring logs that inflate cloud bills. How do you build a Crossplane self-service bucket vending system that guarantees compliance by design?

Designing an enterprise Crossplane Composition vending AWS S3 buckets with mandatory KMS encryption, blocked public access, and automated lifecycle rules.

#Platform Engineering #Crossplane #AWS S3 #Security #FinOps #Self-Service
🎙️ Candidate Opening & Architectural Context
"Manual cloud storage provisioning guarantees security breaches and cost leaks. By creating a Crossplane `AppStorage` composite resource, the platform team enforces KMS encryption, 100% public access blocking, and automated intelligent-tiering lifecycle transitions at the composition layer."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Define Minimal XRD Developer Interface

Expose only developer-relevant fields: bucket purpose, retention days, and lifecycle tiering.

apiVersion: apiextensions.crossplane.io/v1
kind: CompositeResourceDefinition
metadata:
  name: xappstorages.platform.acme.com
spec:
  group: platform.acme.com
  names: { kind: XAppStorage, plural: xappstorages }
  claimNames: { kind: AppStorage, plural: appstorages }
  versions:
    - name: v1alpha1
      schema:
        openAPIV3Schema:
          type: object
          properties:
            spec:
              properties:
                lifecycleDays: { type: integer, default: 90 }
                enableVersioning: { type: boolean, default: true }
2

Enforce Mandatory Security and FinOps in Crossplane Composition

The Composition renders an AWS S3 Bucket, PublicAccessBlock, ServerSideEncryptionConfiguration, and LifecycleConfiguration automatically.

# Composition resource snippet
- name: s3-public-access-block
  base:
    apiVersion: s3.aws.upjet.crossplane.io/v1beta1
    kind: BucketPublicAccessBlock
    spec:
      forProvider:
        blockPublicAcls: true
        blockPublicPolicy: true
        ignorePublicAcls: true
        restrictPublicBuckets: true
Advertisement
3

Export Read/Write IAM Policy to Developer Namespace

Crossplane generates a scoped IAM policy granting read/write access to that specific bucket ARN only, exporting the policy ARN to a Kubernetes Secret in the developer's namespace.

Pro Tip: Compliance by Design: Developers cannot misconfigure security because the Composition does not expose options to disable encryption or public access blocks.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Use Crossplane compositions to vend S3 storage with mandatory KMS encryption, strict public access blocks, and automated lifecycle transitions enforced by default."
⚡ 60-Second Elevator Pitch Talking Points
  • Design Crossplane XRDs exposing minimal storage parameters while hiding cloud configuration complexity.
  • Hardcode PublicAccessBlock and ServerSideEncryptionConfiguration inside the central Composition.
  • Automatically vend scoped IAM policies granting developers access strictly to their own provisioned bucket.
Advertisement
Want more Platform Engineering & IDP scenarios?
Explore our complete collection of scenario-based Platform Engineering & IDP interview runbooks.
Browse All Platform Engineering & IDP Questions →