Free sample question
How would you design a multistage CI/CD pipeline with gates between build, test, scan, package, and deploy?
Senior · Pipeline Architecture · Delivery · Chapter 1: Pipeline Architecture & Optimization, question 1 of 6 · from Modern CI/CD & GitOps: Pipelines, Argo CD & Progressive Delivery
What the interviewer is really testing
whether you can sequence stages for fast feedback and safety at once, and decide which gates block a release versus which only warn, instead of bolting every check onto one giant job.
The 30-second answer
I'd split the pipeline into ordered stages with explicit gates between them: build once, run unit tests and linting in parallel, then security and dependency scans, then package an immutable signed artifact, then promote it across environments. The build artifact is created exactly once and carried forward by digest, never rebuilt per environment. Gates that block include failing tests and high-severity vulnerabilities; gates that warn feed dashboards. On GitHub Actions I'd use upload-artifact v4, OIDC for keyless cloud auth, and cosign to sign the image so deploy verifies provenance.
Follow-ups the interviewer will probe
- How do you keep the pipeline fast as it grows?
- Parallelize independent jobs inside each stage, cache dependencies and use a remote build cache, and run only affected tests on changed paths. Fail fast: order cheap high-signal checks first so a broken commit dies in seconds, not after a thirty-minute integration run.
- How does the artifact prove it is the one you tested?
- Build once and reference by content digest, not by tag. Sign with cosign keyless via OIDC, generate an SBOM with Syft, and attach SLSA build provenance. At deploy, a policy gate verifies the signature and provenance, so an unsigned or rebuilt image cannot advance.
- Where does GitOps fit into this pipeline?
- CI ends at a signed artifact and a commit to a config repo. Argo CD or Flux, both CNCF graduated, then reconcile the cluster to that desired state. The deploy gate becomes a pull request plus sync wave, and progressive delivery (Argo Rollouts or Flagger) handles canary promotion with metric analysis.
Recall hook
“Build once, gate often, promote by digest.”
stage checks cheapest-first, block only on test and severity failures, and ship the exact signed artifact you tested.
What the book adds to this question
In the ebook every question runs three pages. Between the 30-second answer and the follow-ups it adds a deep dive with a diagram, a decision framework, and a pitfalls-and-signals table. Modern CI/CD & GitOps: Pipelines, Argo CD & Progressive Delivery has 50 questions across 8 chapters and includes the free Interview-Day Playbook.
Want full three-page questions? Download the free 8-question PDF sample (from Cloud Interview Mastery).
Sample questions from the other books
- When would you recommend a hybrid or multi-cloud strategy, and when is it a mistake? · Cloud Interview Mastery: AWS, Azure & GCP
- How do you implement a canary deployment in Kubernetes, and how does traffic splitting actually work? · Container Orchestration Journey: Docker to Kubernetes
- How would you design Terraform state management across 200+ configurations with locking, isolation, and disaster recovery? · Infrastructure as Code Mastery: Terraform & OpenTofu
- Why standardize on OpenTelemetry, and when is the instrumentation cost worth it? · Senior DevOps & SRE Handbook: Observability, Reliability & Security