DevOps Foundations · Module 4: Git and team workflow · Lab
Detect a Fictional Secret and Respond in Order
50 min hands-on · Advanced
Local Git scratch repo; a planted FICTIONAL secret sample (clearly labeled EXAMPLE, invalid format, never a real credential).
Two ways to do this lab: in your browser on Killercoda (free, no install), or on your own machine as a local guide. Killercoda runs one free scenario at a time: if you see a waiting queue, close other Killercoda tabs and wait a minute.
Objectives
- Detect a secret-shaped string in history with a scan
- Assess impact: where it appears, who could have seen it
- Write the correct response order without touching real systems
Step 1
Plant and detect
Commit a file containing EXAMPLE_API_KEY=fictional-sample-0000 (labeled fictional in the file itself). Then find it with git log -S and git grep across history, as if you did not know where it was.
Step 2
Assess the blast radius
List every commit containing the sample, every branch and tag reaching it, and whether the scratch remote received it. Write the impact as three short lines: what, where, who could have seen it.
Step 3
Write the response order
Write the ordered response for a REAL leak of this shape: revoke first (with the service owner), then remove from history, then rotate dependents, then verify, then postmortem. Explain why revoke precedes removal.
How to confirm it worked
- The sample is found via history search, quoted with its commit
- Impact lists commits, refs and remote exposure precisely
- Response order starts with revoke, with the reason stated
- The sample is plainly fictional and no real credential appears anywhere