DevOps Infrastructure Terraform Terraform IaC Kubernetes Kubernetes SRE Observability Advanced High demand

Senior DevOps and Infrastructure Engineering Challenge

Hands-on Terraform code review and Kubernetes ingress/TLS repair, graded on what candidates actually produce.

About This Assessment

A 90-minute performance-based assessment for senior DevOps and infrastructure engineers. Candidates work in a live Linux environment with a running Kubernetes cluster and are graded on what they actually produce, not on recall. Two hands-on tasks (10 of 24 points): 1. Platform substrate review — A Terraform module provisioning a managed RDS instance and its security group is submitted as a pull request and fails review. The candidate repairs it: restrict administrative access to the trusted network, enforce encryption at rest, remove a hardcoded credential, close public accessibility, and apply required tagging. Graded from terraform plan output. 2. Ingress and TLS automation — A healthy web application is deployed but serves no traffic and never receives a certificate. The candidate diagnoses and repairs the ingress configuration and wires up automated certificate issuance so the service is reachable over HTTPS. Graded against live cluster state, however the fix is applied. Eight knowledge questions (14 points) cover Terraform state and plan workflows, AWS EKS managed node groups, RDS availability, SLO/SLI definition and error-budget practice, and OpenTelemetry collection and routing pipelines. Both hands-on tasks award partial credit per requirement met, so the score separates a candidate who fixed three of five findings from one who fixed all five.

Automated Grading

Task 1 (5 pts): one point per requirement met in the Terraform plan output — admin access restricted to the trusted CIDR, storage encryption enabled, hardcoded credential removed, publicly_accessible disabled, required tags applied. Task 2 (5 pts): one point per requirement verified against live cluster state — ingress routes to the service, ingress class correct, TLS section present, cert-manager issues a certificate, https://app.lab.local/ returns 200. Knowledge questions: 14 points across eight MCQs.

Environment

Gen2 (Kubernetes/KubeVirt) single node0, Ubuntu. Runs entirely inside node0 — no AWS account and no cloud egress at attempt time. Terraform pinned with a warmed offline provider cache (graded from terraform plan). Single-node k3s with ingress-nginx and cert-manager standing in for EKS. Provisioning asserts the Terraform module plans cleanly and that https://app.lab.local/ is NOT already serving 200. Content repo: github.com/TrueAbility/gen2-inflect-devops (variant-a).

Earn a Verified Certificate

Pass this assessment and receive an AbilityScreen Certified Professional credential — verifiable proof of your hands-on skills that you can share with employers.

  • Performance-verified — proves real skills demonstrated in a live environment, not a multiple-choice test
  • Employer-verifiable — each certificate has a unique ID that anyone can verify online
  • Career-ready — share directly to LinkedIn or include in your resume

Ready to prove your skills?

Purchase this assessment and get started today.

$99.00

You'll be redirected to Stripe for secure payment.