Service Discovery and Configuration Management Questions

Letting services find and configure each other at runtime: service registries, client-side versus server-side discovery, DNS-based discovery, dynamic configuration, feature flags, and secrets distribution. Covers how services stay wired together as instances come and go, how config changes propagate safely, and how to monitor and diagnose the outages that stale endpoints or bad config pushes cause. The connective plumbing of a microservices deployment.

EasyTechnical
44 practiced

Why should secrets not be stored in plain configuration files or version control? Describe a secure secrets management approach for containerized microservices, covering short-lived vs long-lived secrets, authentication to a secrets store, audit logging, and how to revoke or rotate secrets safely.

HardSystem Design
48 practiced

Design a secrets distribution architecture for containerized workloads that supports key rotation without requiring container restarts. Constraints: thousands of containers, least-privilege access, audit logs, node-level caching, and low-latency retrieval. Consider using Vault, sidecars, node agents, and Kubernetes secrets; explain trade-offs for each.

HardTechnical
55 practiced

Design a zero-downtime secret rotation process for thousands of running containers that avoids secret leakage and guarantees minimal exposure to old secrets. Explain how you would distribute new secrets, revoke old secrets, coordinate dependent services (databases, third-party APIs), and audit the rotation. Discuss use of short-lived tokens, TLS, key-version headers, and potential race conditions.

That is every published Service Discovery and Configuration Management question for Security Architect so far. Browse the other topics in this category, or practice this one interactively.