How do you secure a CI/CD pipeline?
Assesses fundamental understanding of CI/CD conventions, runtime behavior, and memory/performance considerations.
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
Treat the pipeline as production infrastructure with its own threat model.
- Secrets: never hardcode them. Use a secrets manager or OIDC federation so the pipeline gets short-lived credentials instead of static keys. Mask values in logs.
- Least privilege: pipeline roles should only deploy what they need. Separate build and deploy permissions.
- Supply chain: pin and verify third-party actions and base images, sign artefacts, and generate SBOMs. Scan dependencies and images for CVEs.
- Code review: protect main, require reviews, and prevent self-approval of pipeline changes.
- Isolation: run untrusted builds in ephemeral, network-restricted runners. Do not expose long-lived cloud credentials to fork pull requests.
- Audit: log who triggered what, and store pipeline logs immutably.
permissions:
id-token: write
contents: read
Rotate credentials, scan infrastructure code with policy-as-code, and verify provenance before deployment. Assume the pipeline is a high-value target.
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.