⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Platform Engineering & IDP Interview Questions Scenario 36 of 50 in Platform Engineering & IDP
Senior Platform Engineer Platform Engineering FinOps & Developer Work environments Platform FinOps
🎯 Target Role / Context: Senior Platform Engineer Interview · Platform FinOps Track

Q: Your multi-tenant Kubernetes cluster bill is $120,000/month, but finance cannot attribute costs to specific teams because pods share compute nodes and lack standard metadata. How do you implement OpenCost/Kubecost and enforce cost allocation via Golden Path templates?

Implementing automated Kubernetes resource cost tracking and chargeback/showback reports allocated across engineering business units.

#Platform Engineering #OpenCost #Kubecost #FinOps #Cost Allocation #Kubernetes
🎙️ Candidate Opening & Architectural Context
"In multi-tenant clusters, infrastructure bills cannot be parsed by raw AWS billing tags because worker nodes are shared by multiple teams. OpenCost/Kubecost allocates CPU, memory, and storage costs down to the container level by combining Kubernetes metrics with live cloud billing APIs."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Deploy OpenCost with Cloud Pricing API Integration

Deploy OpenCost in the management cluster configured with AWS Cost and Usage Report (CUR) or public on-demand/spot pricing APIs.

# Helm installation for OpenCost
helm install opencost opencost/opencost \
  --namespace opencost --create-namespace \
  --set opencost.exporter.defaultClusterId=prod-eks-01 \
  --set opencost.prometheus.internal.serviceName=prometheus-k8s
2

Standardize FinOps Labels in Golden Path Helm Base Chart

Enforce mandatory labels across all Deployment manifests: `app.kubernetes.io/owner`, `cost-center`, and `environment`.

# Base chart labels
metadata:
  labels:
    cost-center: {{ .Values.costCenter | quote }}
    team: {{ .Values.teamName | quote }}
    environment: {{ .Values.environment | quote }}
Advertisement
3

Enforce Label Validation via Kyverno Admission Webhook

Deploy a Kyverno policy that denies deployments in staging and production if the `team` or `cost-center` label is missing.

apiVersion: kyverno.io/v1
kind: ClusterPolicy
metadata:
  name: require-cost-labels
spec:
  validationFailureAction: Enforce
  rules:
    - name: check-team-label
      match: { resources: { kinds: ["Deployment", "StatefulSet"] } }
      validate:
        message: "Deployments must include a 'team' and 'cost-center' label for FinOps tracking."
        pattern:
          metadata:
            labels:
              team: "?*"
              cost-center: "?*"
4

Expose Monthly Showback Dashboards in Backstage

Expose OpenCost APIs directly in Backstage via the Kubecost plugin, allowing developers to see their team's live daily infrastructure spend.

Pro Tip: Behavioral FinOps: When engineering teams see their real daily dollar spend inside their developer portal, voluntary resource rightsizing increases by 30%.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Track multi-tenant cluster spend by deploying OpenCost, mandating team cost labels in Golden Path charts via Kyverno, and exposing live spend in Backstage."
⚡ 60-Second Elevator Pitch Talking Points
  • Deploy OpenCost to calculate per-pod CPU and memory spend against live cloud pricing data.
  • Mandate standardized team and cost-center labels in Golden Path templates enforced by Kyverno.
  • Provide developers with transparent showback dashboards inside Backstage to encourage voluntary rightsizing.
Advertisement
Want more Platform Engineering & IDP scenarios?
Explore our complete collection of scenario-based Platform Engineering & IDP interview runbooks.
Browse All Platform Engineering & IDP Questions →