Part 13 · CI/CD, Git & Cloud
38 câu hỏi Git, CI/CD và Cloud
Trả lời theo graph/trust boundary/artifact identity/failure domain thay vì command hoặc service-name trivia.
Git
1. Blob/tree/commit/ref khác nhau?
Blob content, tree names/modes, commit root tree+parents, ref movable pointer tới object.
2. Staging area là gì?
Index là proposed next tree giữa working tree và repository, cho phép chọn hunks/files.
3. Rebase đổi commit ID vì sao?
Parent/metadata/tree chain đổi; commit hash gồm object content, nên replay tạo objects mới.
4. Merge vs rebase?
Merge giữ topology; rebase linearize nhưng rewrite. Chọn theo shared-history/collaboration policy.
5. Revert vs reset?
Revert tạo inverse commit an toàn shared; reset move ref và có thể index/tree destructive.
6. Reflog cứu gì?
Ref movements cục bộ để tìm commits lost sau reset/rebase trước expiry/GC.
7. Bisect cần điều kiện gì?
Known good/bad và deterministic test/classification; binary search commit graph candidate.
8. Trunk-based trade-off?
Giảm integration delay nhưng cần small changes, strong CI, flags và fast recovery.
9. Semantic conflict?
Text merge xanh nhưng changes assumptions/API/invariant không tương thích; cần tests/review.
10. Signed commit chứng minh gì?
Signature identity/integrity under key trust, không chứng minh review/build/runtime artifact.
CI/CD và supply chain
11. Build once/promote vì sao?
Đảm bảo artifact production chính là artifact đã test; config thay theo environment.
12. Cache khác artifact?
Cache optimization có thể bỏ/rebuild; artifact versioned deliverable được promote/audit.
13. Untrusted PR risk?
Code có thể exfiltrate secrets/tokens hoặc poison runner/cache; tách permissions/runners/events.
14. OIDC giảm risk thế nào?
Job token short-lived exchange cloud credentials; trust validates issuer/audience/repo/ref/environment.
15. id-token:write có cloud access?
Không trực tiếp; chỉ mint OIDC token, cloud trust/IAM quyết định permissions.
16. SBOM/provenance/signing?
Inventory, build origin/materials và identity/integrity; không cái nào tự bảo đảm bug-free.
17. Rolling/blue-green/canary?
Rolling efficient/mixed; blue-green quick switch/double capacity; canary limited blast/needs analysis.
18. Rollback sau data write mới?
Old binary may incompatible; use expand-contract, dual compatibility, forward fix/reconciliation.
19. GitOps trust boundary?
Repo write, controller identity, admission and artifact verification; pull model không xóa authorization risk.
20. IaC state nhạy cảm vì sao?
Maps resources/attributes và có thể chứa secrets; cần encrypted backend, locking, versioning, least access.
Terraform và administrative access
21. Terraform state dùng để làm gì và vì sao nhạy cảm?
State ánh xạ resource address sang provider object ID/attributes để tính diff và dependency. Nó có thể chứa secret/sensitive values, nên cần encrypted remote backend, locking, versioning, backup, audit và least access; không commit hoặc sửa JSON thủ công.
22. validate, plan và apply khác guarantee thế nào?
Validate kiểm tra syntax/internal consistency; plan đọc state/remote objects và dự đoán actions; apply gọi provider API và cập nhật state. Plan có thể stale, còn apply có thể partial failure do quota, permission, timeout hoặc eventual consistency.
23. count khác for_each?
count định danh instances bằng index nên chèn/xóa giữa list có thể đổi addresses hàng loạt. for_each dùng stable keys, phù hợp resources có business identity. Chọn theo identity semantics, không chỉ cú pháp ngắn.
24. Terraform import có làm resource được quản lý hoàn chỉnh?
Import chỉ bind remote object vào state/address; vẫn cần configuration khớp, review plan và xử lý dependencies. Nếu config sai, plan tiếp theo có thể update hoặc replace resource.
25. Apply thất bại giữa chừng xử lý thế nào?
Không apply lại mù. Xác định resources đã tạo/đổi, đọc state và provider, refresh/plan lại, sửa root cause rồi reconcile. Backend version/backup và audit quan trọng; -target chỉ dùng recovery có giới hạn.
26. Jump server/bastion là gì?
Là privileged administrative hop để operator truy cập private targets mà không expose SSH/RDP trên từng máy. Nó tập trung identity/audit nhưng trở thành high-value target, nên cần hardening, MFA, short-lived per-user access, HA và target-side least privilege.
27. Bastion khác VPN và NAT Gateway?
VPN/ZTNA tạo trusted access path/network identity; bastion là host/session hop cho admin protocol; NAT Gateway cung cấp outbound translation và không phải login host. Có thể dùng VPN/ZTNA trước bastion, nhưng chúng không thay nhau hoàn toàn.
28. Khi nào chọn managed session service thay bastion tự quản?
Khi muốn loại inbound SSH/RDP, tránh phân phối keys và có identity/session audit tích hợp. AWS Session Manager/Azure Bastion/ZTNA giảm host operations nhưng thêm control-plane dependency, IAM/config/cost constraints; vẫn cần break-glass và target authorization.
Cloud AWS/Azure
29. HA vs backup vs DR?
HA giảm downtime expected; backup point recovery; DR process/site strategy với RPO/RTO.
30. Private subnet tự secure?
Không; routes, public IP, SG/NSG, identity, endpoints và egress determine reachability.
31. NAT caveats?
Outbound sharing, port/capacity/HA and per-GB cost; not inbound protection alone.
32. Multi-AZ vs multi-region?
Multi-AZ simpler HA; multi-region adds routing, data conflict, failover/failback/cost for stronger RTO/latency/residency.
33. AWS SCP có grant permission?
Không; guardrail maximum. Identity/resource policy still must allow and explicit deny wins.
34. AWS ALB vs NLB?
ALB L7 HTTP routing/features; NLB L4 TCP/UDP/high performance/static IP use cases.
35. Azure resource group là gì?
Management/lifecycle/RBAC scope for resources, not network/security boundary by itself.
36. Azure Front Door vs App Gateway?
Front Door global edge/HTTP routing; Application Gateway regional L7/WAF inside Azure networking.
37. Managed identity giải quyết gì?
No stored credential lifecycle; still requires RBAC, token audience, network and workload trust.
38. Cost review tập trung đâu?
Rightsizing/utilization, commitment/spot, storage lifecycle, egress/NAT/logs, idle resources and SLO trade-offs.