Microsoft Certified: DevOps Engineer Expert flashcards
160 free flashcards. Tap a card to flip it.
Azure DevOps Scale Set Agents
Flip cardSelf-hosted build agents that are managed by an Azure Virtual Machine Scale Set, enabling automatic scaling (up and down) based on the demand from build and release pipelines.
- Provides dynamic agent capacity, optimizing costs and queue times.
- Allows for custom environments (OS, software, Docker).
- Integrated with Azure DevOps agent pools for seamless management.
Memory trick: Think of Scale Set Agents as a smart, elastic factory floor: it automatically adds or removes workers (agents) and tools (Docker) based on how many orders (builds) come in, so you're never overstaffed or understaffed.
Azure Artifacts Universal Packages
Flip cardA type of package in Azure Artifacts designed to store arbitrary files of any type and size, making it suitable for large binaries, installers, or machine learning models.
- Supports large files (up to 4 TB).
- Not language-specific (unlike NuGet, npm, Maven).
- Managed using Azure DevOps CLI or tasks like `UniversalPackages@0`.
Memory trick: Universal Packages hold everything, especially the big stuff.
Azure Repos Branch Policies
Flip cardRules enforced on specific branches in Azure Repos to maintain code quality, ensure collaboration, and control merges.
- Enforce pull request workflow.
- Require minimum reviewers and successful builds.
- Prevent direct pushes to protected branches.
Memory trick: Policies protect your main branch from bad merges.
NuGet Service Connection
Flip cardA type of service connection in Azure DevOps specifically designed to establish authenticated connections to NuGet package feeds (public or private).
- Simplifies authentication for NuGet tasks in pipelines.
- Supports Azure Artifacts feeds and external NuGet servers.
- Used for publishing and consuming NuGet packages.
Memory trick: Think of service connections as 'smart plugs': each is designed for a specific type of external system, like a NuGet plug for NuGet feeds.
Azure Artifacts Upstream Sources
Flip cardA feature in Azure Artifacts that allows a feed to act as a proxy for other package feeds, enabling consumption of packages from multiple sources (private and public) through a single endpoint.
- Simplifies client configuration by reducing the number of package sources.
- Can include other Azure Artifacts feeds, nuget.org, npmjs.com, etc.
- Packages from upstream sources are cached in the feed for faster access.
- Resolves packages in a defined order: feed's own packages, then upstream sources.
Memory trick: Upstream sources bring all packages down to one river.
TFVC to Git Migration (Full Fidelity)
Flip cardThe process of moving a Team Foundation Version Control (TFVC) repository to a Git repository while retaining all historical data, including branches, merges, and changesets.
- Preserves complete history for auditing and context.
- Often requires specialized tools like 'git-tfs'.
- More complex than basic code migration but offers significant benefits.
Memory trick: Think of 'git-tfs' as a time machine, preserving every branch and merge from TFVC's past.
CI Trigger Path Filters (Monorepo)
Flip cardA configuration within a Continuous Integration (CI) trigger in Azure DevOps pipelines that specifies which file paths, when changed, should cause the pipeline to run.
- Essential for optimizing builds in monorepos.
- Prevents unnecessary builds of unaffected components.
- Can include and exclude specific paths.
Memory trick: Imagine a monorepo as a giant tree. Path filters are like a smart gardener who only prunes (builds) the branches that have actually grown (changed code).
Azure DevOps Task Groups
Flip cardA feature in Azure DevOps that allows encapsulating a sequence of tasks into a single reusable unit, promoting consistency and reusability across pipelines.
- Encapsulates multiple tasks
- Reusable across build and release pipelines
- Promotes consistency and reduces duplication
Memory trick: Think of a task group as a pre-packaged lunchbox for your pipelines, always the same healthy meal.
Azure Pipelines Variable Groups with Key Vault
Flip cardA feature in Azure DevOps that allows you to store reusable sets of variables and securely link them to secrets stored in Azure Key Vault, making them accessible to pipelines at runtime.
- Centralized management of secrets and configuration values.
- Secrets are retrieved from Key Vault at runtime, not stored in Azure DevOps.
- Enhances security by leveraging Key Vault's access control and auditing.
- Variables can be shared across multiple pipelines.
Memory trick: Variable groups with Key Vault unlock secrets for pipelines.
Azure DevOps Build Service Identity
Flip cardA built-in service identity (Project Collection Build Service / Project Build Service) that Azure DevOps pipelines run under, automatically providing an OAuth token for secure interaction with other Azure DevOps services.
- Automatically generated for each project/organization.
- Used for pipeline authentication to internal Azure DevOps resources.
- Permissions can be managed like a regular user or group.
Memory trick: Think of the Build Service Identity as a loyal robot assistant for your pipeline: it has its own secure ID (OAuth token) to access internal resources without you needing to give it your personal keys.
Git Large File Storage (LFS)
Flip cardAn open-source extension for Git that replaces large files in your repository with text pointers, while the actual file contents are stored on a remote server.
- Prevents Git repository bloat and performance degradation.
- Allows versioning of large binary files alongside source code.
- Requires Git LFS client installation and configuration.
- Integrates seamlessly into existing Git workflows.
Memory trick: LFS handles large files, so Git stays nimble.
Self-Hosted Azure DevOps Agents
Flip cardBuild agents that you set up and manage on your own infrastructure (on-premises or cloud VMs), providing full control over the installed software and environment.
- Provides full control over installed software and dependencies.
- Required for specific hardware, custom tools, or outdated software not on Microsoft-hosted agents.
- Requires manual management of agent updates and maintenance.
Memory trick: Think of agents as workers: Microsoft-hosted are generalists, self-hosted are specialists with custom tools, and scale sets are a fleet of specialists.
git-svn Utility
Flip cardA Git command-line utility that provides a bidirectional gateway between a local Git repository and a remote Subversion repository, primarily used for migrating SVN history to Git.
- Performs full-fidelity migration from SVN to Git.
- Preserves commit history, author information, branches, and tags.
- Can be used for incremental synchronization.
- Requires knowledge of SVN repository structure (trunk, branches, tags).
Memory trick: git-svn converts ancient scrolls to modern trees.
Azure DevOps Service Connection
Flip cardA secure way to connect Azure DevOps pipelines to external and internal services (like Azure Artifacts, Azure subscriptions, GitHub) without exposing sensitive credentials directly in pipeline definitions.
- Stores credentials securely.
- Used for authentication to external systems.
- Different types exist for various services.
Memory trick: Connect services securely with a service connection.
Azure DevOps Pull Request Triggers & Branch Policies
Flip cardPull Request (PR) triggers in pipelines initiate builds when PRs are created or updated, while Branch Policies enforce conditions (e.g., successful build, reviewer approval) that must be met before a PR can be merged into a target branch.
- PR triggers ensure builds run for every PR change.
- Build validation policy prevents merging if the build fails.
- Minimum reviewers policy enforces code review before merge.
Memory trick: Think of PR policies as a gatekeeper for the main branch: the build must pass, and two guards must approve before the gate opens, all triggered by your request.
Azure DevOps Approvals and Checks
Flip cardMechanisms in Azure DevOps pipelines that require certain conditions (manual approval, external system validation, etc.) to be met before a stage or job can start executing on a protected resource or environment.
- Ensures compliance and quality gates.
- Can integrate with external systems via REST APIs.
- Applied to environments, service connections, agent pools, or variable groups.
Memory trick: To cross the gate, you need a checkmark and approval.
Git-TFS Utility
Flip cardA command-line tool that allows you to migrate a Team Foundation Version Control (TFVC) repository to Git, preserving the full commit history, branches, and merge relationships.
- Enables full-fidelity TFVC to Git migration.
- Handles complex branching and merging scenarios.
- Requires installation on a machine with TFVC client installed.
Memory trick: To bridge TFVC to Git, use the Git-TFS bridge.
Azure DevOps Path Filters
Flip cardA feature in Azure DevOps pipelines that restricts CI triggers to only run when changes are committed to specified file paths or directories.
- Used to optimize CI/CD in monorepos.
- Prevents unnecessary pipeline runs.
- Configured within the 'triggers' section of a YAML pipeline.
Memory trick: Only build the branches that *changed* in the tree.
Azure DevOps Multi-Repo Checkout
Flip cardA feature in Azure DevOps YAML pipelines that allows a single pipeline to check out code from multiple Git repositories (both Azure Repos and external) into the agent's workspace.
- Defined using `resources.repositories` in YAML.
- Supports different repository types (Git, GitHub, Bitbucket).
- Each repository is checked out into a specific directory.
Memory trick: Check out all the books from the library for your project.
Azure DevOps Service Hooks
Flip cardA mechanism in Azure DevOps to integrate with external services by sending notifications or payloads when specific events occur within Azure DevOps (e.g., code push, build completion, work item update).
- Configured at the project level.
- Supports various event types (code, build, work item, release).
- Can send data to webhooks, Azure Functions, or other integrated services.
- Enables automation and integration with third-party tools.
Memory trick: Service hooks connect events to external services, like a switchboard.
Azure Artifacts Upstream Sources (Resolution Order)
Flip cardUpstream sources in Azure Artifacts allow a single feed to serve packages from multiple sources, with a default resolution order of local feed content first, then configured upstream sources.
- Primary feed's packages are always resolved first.
- Upstream sources are queried in the order they are listed if the package isn't found locally.
- Caches packages from upstream sources for improved performance.
- Simplifies client NuGet.config by requiring only one feed URL.
Memory trick: Upstream sources prioritize local then flow to public.
Azure Pipelines Pre-deployment Approvals
Flip cardA feature in Azure DevOps release pipelines that pauses deployment to an environment and requires explicit approval from designated users or groups before proceeding.
- Configured per environment in a release pipeline.
- Supports multiple approvers and approval policies.
- Can integrate with Azure AD groups for approver management.
- Ensures human gatekeeping before critical deployments.
Memory trick: Pre-deployment approvals are the gatekeepers of production.
Azure DevOps Self-Hosted Agent Setup
Flip cardThe process of installing and configuring an Azure DevOps agent on a user-managed machine (on-premises or cloud VM) to run build and release jobs.
- Requires downloading agent software.
- Uses `config.cmd` or `config.sh` for configuration.
- Authenticates using a Personal Access Token (PAT).
- Communicates outbound over HTTPS to Azure DevOps.
Memory trick: Download, configure, and connect your bot to the cloud.
Azure Pipelines Multi-repo Checkout
Flip cardA feature in Azure Pipelines that enables a single pipeline to checkout code from multiple Git repositories (within the same or different organizations) into the build agent's workspace.
- Defined using `resources.repositories` in YAML.
- Supports Git repositories from Azure Repos, GitHub, or other Git sources.
- Each repository is checked out into a separate directory.
- Simplifies building applications with dependencies across multiple repositories.
Memory trick: Multiple repos, checkout them all at once.
Azure DevOps Variable Groups with Key Vault
Flip cardA feature in Azure DevOps that allows linking a variable group to an Azure Key Vault, enabling pipelines to securely access secrets stored in Key Vault at runtime.
- Secrets are never exposed in YAML or logs (when correctly handled).
- Provides centralized secret management.
- Requires appropriate permissions on Key Vault for the service connection.
Memory trick: Vault your variables for pipeline security.
SVN to Git Full Fidelity Migration
Flip cardThe process of migrating an SVN repository to Git while preserving the complete commit history, including branches, tags, and commit metadata.
- Tools like 'git-svn' are commonly used.
- Crucial for maintaining historical context and audit trails.
- Can be complex for very large or intricate SVN repositories.
Memory trick: To keep the full story, you need the right translator.
Azure DevOps Pipeline Templates
Flip cardReusable YAML files that define common pipeline structures, stages, jobs, or steps, allowing for parameterization and inclusion in multiple pipelines.
- Reduces YAML duplication and promotes consistency.
- Supports parameters for customization.
- Can be used for stages, jobs, steps, or even entire pipelines.
Memory trick: Think of pipeline templates as LEGO blocks for your builds: you design a block once, then use it everywhere, just changing a few colors (parameters).
Azure Pipelines Path Filters
Flip cardPath filters in Azure Pipelines YAML allow you to specify which file paths trigger a CI build, enabling selective pipeline execution based on code changes.
- Defined under the `trigger.paths` section.
- Use `include` to specify paths that trigger a build.
- Use `exclude` to specify paths that should not trigger a build.
- Wildcards like `**` (any sub-directory) and `*` (any character) are supported.
Memory trick: Path to success is to include all dependencies.
Azure Pipelines Task Groups
Flip cardA feature in Azure DevOps that allows you to combine a sequence of tasks into a single reusable task, which can then be used in multiple build or release pipelines.
- Encapsulates common build/release logic.
- Changes to a task group automatically update all pipelines using it.
- Reduces duplication and improves consistency.
- Can include input parameters for customization.
Memory trick: Task groups package steps for reuse and auto-update.
Kanban Agile Framework
Flip cardKanban is an agile framework focused on visualizing work, limiting work in progress (WIP), and maximizing efficiency of flow. It's highly adaptable to changing priorities and does not rely on time-boxed iterations, making it suitable for continuous delivery and rapid response environments.
- Visualizes workflow.
- Limits Work In Progress (WIP).
- No time-boxed iterations.
- Adapts to changing priorities.
Memory trick: Agile methods make work flexible.
Git Rebase Strategy
Flip cardGit rebase reapplies commits from one branch onto another, effectively rewriting commit history to create a linear progression without merge commits. It's used to keep feature branches up-to-date with the main branch and to maintain a clean, linear history on the main branch.
- Rewrites commit history.
- Creates a linear commit history.
- Avoids merge commits.
- Can be dangerous if used on shared branches.
Memory trick: Branch merges must be clean, like a clear path.
Feature Branching
Flip cardA branching strategy where all new development for a feature takes place in a dedicated branch, isolated from the main codebase.
- Promotes isolation of development efforts.
- Facilitates code review before merging.
- Reduces risk of regressions in the main branch.
Memory trick: Feature branches grow new ideas safely.
Kanban Framework
Flip cardAn agile framework that emphasizes visualizing work, limiting work in progress (WIP), and maximizing efficiency through a pull-based system.
- Visualizes work on a board with columns representing stages.
- Limits work-in-progress to reduce context switching and bottlenecks.
- Uses a pull system where team members take new work when they have capacity.
Memory trick: Kanban's 'K' is for 'Keep' work flowing, 'A' for 'Avoid' bottlenecks, 'N' for 'No' pushing, 'B' for 'Board' visualization, 'A' for 'As' capacity allows, 'N' for 'Now' pull.
Canary Release Strategy
Flip cardA Canary release strategy involves deploying a new version of an application or feature to a small, isolated group of users or servers (the 'canary') to test its stability and performance in a production environment before rolling it out to the entire user base. This minimizes risk.
- Gradual rollout to a subset of users.
- Monitors stability and gathers feedback.
- Minimizes risk of widespread issues.
- Often uses traffic routing or feature flags.
Memory trick: Releases can be a staged ascent.
Branch Policies for Main Branch Stability
Flip cardRules applied to a branch (e.g., `main`) to enforce quality gates, such as required reviews, automated checks, and preventing direct commits, ensuring its stability.
- Prevents direct commits to protected branches.
- Mandates minimum number of reviewers for PRs.
- Requires passing automated build/test pipelines.
- Can enforce static code analysis results.
Memory trick: Features branch, policies protect the main.
Advanced Release Strategies
Flip cardTechniques like Feature Flags and Canary Releases, often combined with Continuous Delivery, to enable controlled, low-risk, and incremental deployment of new features.
- Feature Flags: Toggle features on/off dynamically.
- Canary Releases: Gradual rollout to a small user subset.
- Blue/Green Deployments: Instant switch between old and new environments.
- Dark Launching: Deploy features hidden from users.
Memory trick: Flags fly, canaries sing, delivery is king.
Basic Pull Request Strategy
Flip cardA strategy where developers submit their changes for review and approval by other team members before they can be merged into a target branch.
- Enforces code review.
- Improves code quality and collaboration.
- Prevents direct commits to protected branches.
Memory trick: Pull requests pull in peer reviews.
Semantic Versioning (SemVer) Standard
Flip cardA formal specification that dictates how to assign and increment version numbers (MAJOR.MINOR.PATCH) to communicate the nature of changes and their impact on backward compatibility.
- Formalizes Major.Minor.Patch format rules.
- MAJOR for incompatible API changes.
- MINOR for backward-compatible new functionality.
- PATCH for backward-compatible bug fixes.
Memory trick: SemVer's rules make versions speak.
Immutable Artifact Versioning
Flip cardA versioning approach for deployable artifacts (e.g., Docker images) that incorporates unique identifiers like Git commit hashes and build numbers to ensure traceability and immutability.
- Each artifact version is unique and never changes.
- Directly links artifact to specific source code commit.
- Often includes build number for instance uniqueness.
- Crucial for reproducibility and debugging in production.
Memory trick: Commit hashes confirm each artifact's home.
Pipeline Resource Triggers
Flip cardPipeline resource triggers in CI/CD systems enable one pipeline to automatically start when another pipeline completes or publishes new artifacts. They are essential for managing complex dependencies across multiple repositories and services to ensure automated propagation of changes.
- Automate pipeline chaining.
- Crucial for microservice architectures.
- Ensures dependency-driven builds/releases.
- Can trigger on completion or artifact publication.
Memory trick: Dependencies trigger the chain reaction.
Blue/Green Deployment
Flip cardA release strategy that runs two identical production environments (Blue for current, Green for new) and switches traffic between them.
- Provides zero downtime during deployment.
- Enables instant rollback by switching traffic back to the previous environment.
- Requires double the infrastructure for production environments.
Memory trick: Blue/Green: 'B'etter for zero downtime, 'G'uarantees instant rollback.
Azure DevOps Delivery Plans
Flip cardAn Azure DevOps feature that provides a consolidated, multi-team view of work, enabling visualization of dependencies and progress across different backlogs on a timeline.
- Aggregates work from multiple teams/projects.
- Visualizes dependencies and milestones.
- Provides a timeline-based roadmap view.
- Supports program and portfolio management.
Memory trick: Delivery Plans deliver the big picture.
Azure DevOps Branch Policies
Flip cardAzure DevOps Branch Policies are rules applied to Git branches to enforce code quality, consistency, and compliance. They mandate conditions like code reviews, successful builds, and external service checks before pull requests can be merged, ensuring only high-quality code enters critical branches.
- Enforce quality and compliance.
- Applied to specific branches (e.g., `main`).
- Mandate PR conditions (reviewers, builds, scans).
- Crucial for maintaining code health.
Memory trick: Policies guard the code's integrity.
Squash and Merge Strategy
Flip cardA Git merge strategy that combines all commits from a source branch into a single new commit on the target branch, creating a clean, linear history.
- Simplifies Git history by reducing noise.
- Each merged PR becomes a single logical change.
- Facilitates easier reverts of entire features.
- Often used with pull requests to maintain a clean main branch.
Memory trick: Squash squashes commits clean.
DevOps Communication
Flip cardFostering frequent, transparent, and multi-directional communication across all teams (Dev, Ops, Business) to ensure alignment and rapid feedback.
- Emphasizes transparency and collaboration.
- Utilizes tools like shared dashboards and chat platforms.
- Includes regular meetings like stand-ups and retrospectives.
- Aims for continuous information flow.
Memory trick: DevOps talks daily, dashboards display all.
Scrum Framework
Flip cardScrum is an agile framework for developing, delivering, and sustaining complex products. It emphasizes empirical process control, self-organizing teams, and iterative, incremental delivery through time-boxed 'sprints' and defined roles and events.
- Time-boxed iterations (sprints).
- Defined roles (Product Owner, Scrum Master, Development Team).
- Prescribed events (Planning, Daily Scrum, Review, Retrospective).
- Focus on inspection and adaptation.
Memory trick: Agile is a way to build better.
Semantic Versioning (SemVer)
Flip cardA versioning scheme (MAJOR.MINOR.PATCH) that conveys meaning about the underlying changes in software releases.
- MAJOR version increment for incompatible API changes.
- MINOR version increment for adding backward-compatible functionality.
- PATCH version increment for backward-compatible bug fixes.
- Helps consumers understand the impact of upgrading.
Memory trick: SemVer: 'S'ignifies 'E'very 'M'ajor, 'M'inor, 'P'atch.
Kanban Board
Flip cardA Kanban board is an agile project management tool designed to visualize work, limit work in progress (WIP), and maximize efficiency (flow). It uses columns to represent stages of work and cards to represent individual tasks, promoting a pull-based system.
- Visualizes workflow.
- Limits Work In Progress (WIP).
- Promotes a pull-based system.
- Identifies bottlenecks.
Memory trick: Boards show work in motion.
Continuous Delivery (CD)
Flip cardA software engineering approach where code changes are automatically built, tested, and prepared for release, with a manual approval step before deployment to production.
- Code is always in a deployable state.
- Includes a manual gate for production deployment.
- Supports auditability and compliance.
- Enables frequent, reliable releases.
Memory trick: Delivery is ready, Deployment is done.
Feature Flags
Flip cardA technique that allows specific features to be turned on or off at runtime without deploying new code.
- Enable controlled rollout of features to specific user segments.
- Facilitate A/B testing and experimentation.
- Allow for 'dark launching' of features (deployed but hidden).
- Decouple deployment from release.
Memory trick: Feature Flags: 'F'ine-grained control, 'F'lexible rollout.
Work Item Linking Hierarchy
Flip cardWork item linking in Azure DevOps establishes relationships between work items for traceability, dependency management, and hierarchical organization. 'Child' links are used for breaking down larger work into smaller, manageable pieces.
- Establishes relationships between work items.
- Supports traceability and dependency tracking.
- Common types include Parent/Child, Related, Predecessor/Successor.
Memory trick: Links form a family tree for work.
DevOps Communication Platforms
Flip cardDevOps communication platforms, such as persistent chat with channels, are crucial for fostering transparency, real-time information sharing, and collaboration across development, operations, and QA teams. They help break down silos and ensure shared understanding.
- Real-time communication.
- Persistent and searchable history.
- Dedicated channels for topics/teams.
- Promotes transparency and shared understanding.
Memory trick: Chat bridges gaps between teams.
Git Flow Branching Strategy
Flip cardGit Flow is a branching model that defines strict roles for different branches: `master` (production-ready), `develop` (integration), `feature` (new features), `release` (preparing for release), and `hotfix` (urgent production fixes). It's suitable for projects requiring structured releases and support for multiple versions.
- Structured, multi-branch model.
- `master` branch always production-ready.
- Dedicated `develop` branch for integration.
- Separate `feature` branches for new work.
Memory trick: Branches define the flow of code.
Self-hosted Agent (Azure DevOps)
Flip cardAn agent that you set up and manage on your own infrastructure (on-premises or in cloud VMs) to run build and deployment jobs in Azure DevOps.
- Provides full control over dependencies, software, and network access.
- Required for deploying to on-premises environments or custom cloud setups.
- Reduces build/release times by pre-installing necessary tools.
Memory trick: If it's 'your house', you need a 'self-hosted' agent.
Azure App Service Slot Settings
Flip cardSlot settings (or 'sticky settings') in Azure App Service deployment slots are application settings or connection strings that are specifically tied to a slot and do not swap with the application content when a slot swap occurs. This ensures environment-specific configurations remain in their correct slots.
- Ensures environment-specific configurations persist across swaps.
- Prevents unintended configuration changes in production during deployment.
- Configured in the 'Configuration' section of an App Service slot.
Memory trick: Sticky settings stay put, even when slots swap.
Release Gates
Flip cardRelease gates in Azure DevOps automatically check for health and success criteria from external services before allowing a release to proceed to the next stage or environment.
- Can be configured for pre-deployment or post-deployment stages.
- Continuously monitor conditions and delay deployment until all conditions are met.
- Integrate with various services like Azure Monitor, Work Items, and custom APIs.
Memory trick: Gates guard the path, ensuring all checks pass.
Canary Deployment
Flip cardA deployment strategy where a new version of an application is released to a small subset of users or servers, monitored for health and performance, and then gradually rolled out to the rest of the infrastructure if successful.
- Minimizes risk by limiting exposure of new code.
- Allows for real-world testing with a small user group.
- Enables quick rollback if issues are detected.
Memory trick: A canary sings softly before the full chorus.
Azure Pipelines Self-Hosted Agent
Flip cardAn Azure Pipelines self-hosted agent is software that you install on your own infrastructure (e.g., on-premises VMs, physical servers) to run jobs from Azure Pipelines. It provides the compute capacity for your pipelines and enables deployments to environments not directly accessible by Microsoft-hosted agents.
- Connects securely outbound to Azure DevOps.
- Executes pipeline jobs and deployment tasks.
- Required for deploying to on-premises resources or specific network-restricted environments.
Memory trick: The agent is the messenger between cloud and home.
Azure Key Vault Integration (Azure DevOps)
Flip cardIntegrating Azure Key Vault with Azure DevOps allows pipelines to securely retrieve secrets, keys, and certificates stored in Key Vault, preventing sensitive information from being hardcoded or exposed in pipeline definitions.
- Uses Service Connections to authenticate with Key Vault.
- Secrets are exposed as pipeline variables at runtime.
- Enhances security, compliance, and secret management practices.
Memory trick: Key Vault unlocks secrets safely via service connections.
Service Mesh for Progressive Delivery
Flip cardA service mesh (e.g., Istio, Linkerd) is a dedicated infrastructure layer that handles service-to-service communication within a microservices architecture. It enables advanced traffic management features like intelligent routing, traffic shifting (e.g., for canary releases), fault injection, and observability, crucial for progressive delivery strategies in Kubernetes.
- Provides fine-grained control over traffic routing and distribution.
- Enables canary deployments and A/B testing with percentage-based traffic splits.
- Offers built-in observability, security, and resilience features.
Memory trick: The Service Mesh directs traffic with intelligence and grace.