Lesson 24 / 24
Revision: Cheat Sheet and Self-Check
Review the habits, commands and common interview questions from the whole course.
Cheat sheet
Never commit or paste secrets. Store them in a manager with a strong master password, Secret Key and MFA or passkeys. Share by vault and group with least privilege. Use them through op run or op inject. Scan before pushing. Rotate on schedule and on any leak, revoking before cleaning history.
Questions interviewers ask
Be ready to explain: why deleting a committed secret is not enough, how op run avoids writing secrets to disk, why passkeys resist phishing, what least privilege means for vaults, and the order of steps when a key leaks.
Quick check: A teammate asks for the staging API key in chat. What is the best reply?
- Paste it, it is only staging
- Add them to the staging vault with the right permission
- Email it
- Tell them to guess
Answer
Add them to the staging vault with the right permission — Granting vault access is auditable and revocable; a pasted key is neither.
Quick check: Which command runs an app with secrets injected only into its environment?
- op signout
- op vault list
- git filter-repo
- op run --env-file=.env.1p -- <command>
Answer
op run --env-file=.env.1p -- <command> — `op run` resolves references for that process without writing a plaintext file.
Quick check: What is the correct order after a key leaks publicly?
- Clean history, then think about the key
- Revoke or rotate, redeploy, check logs, then clean up
- Delete the repo, then forget it
- Wait one week
Answer
Revoke or rotate, redeploy, check logs, then clean up — Stopping misuse comes first; cleanup is secondary.