Lesson 24 / 24

Revision: Cheat Sheet and Self-Check

Review the habits, commands and common interview questions from the whole course.

Cheat sheet

Never commit or paste secrets. Store them in a manager with a strong master password, Secret Key and MFA or passkeys. Share by vault and group with least privilege. Use them through op run or op inject. Scan before pushing. Rotate on schedule and on any leak, revoking before cleaning history.

Questions interviewers ask

Be ready to explain: why deleting a committed secret is not enough, how op run avoids writing secrets to disk, why passkeys resist phishing, what least privilege means for vaults, and the order of steps when a key leaks.

Quick check: A teammate asks for the staging API key in chat. What is the best reply?

  • Paste it, it is only staging
  • Add them to the staging vault with the right permission
  • Email it
  • Tell them to guess
Answer

Add them to the staging vault with the right permission — Granting vault access is auditable and revocable; a pasted key is neither.

Quick check: Which command runs an app with secrets injected only into its environment?

  • op signout
  • op vault list
  • git filter-repo
  • op run --env-file=.env.1p -- <command>
Answer

op run --env-file=.env.1p -- <command> — `op run` resolves references for that process without writing a plaintext file.

Quick check: What is the correct order after a key leaks publicly?

  • Clean history, then think about the key
  • Revoke or rotate, redeploy, check logs, then clean up
  • Delete the repo, then forget it
  • Wait one week
Answer

Revoke or rotate, redeploy, check logs, then clean up — Stopping misuse comes first; cleanup is secondary.