The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Foundations · Module 4: Git and team workflow · Lab

Detect a Fictional Secret and Respond in Order

50 min hands-on · Advanced

Local Git scratch repo; a planted FICTIONAL secret sample (clearly labeled EXAMPLE, invalid format, never a real credential).

Two ways to do this lab: in your browser on Killercoda (free, no install), or on your own machine as a local guide. Killercoda runs one free scenario at a time: if you see a waiting queue, close other Killercoda tabs and wait a minute.

Objectives

  • Detect a secret-shaped string in history with a scan
  • Assess impact: where it appears, who could have seen it
  • Write the correct response order without touching real systems
  1. Step 1

    Plant and detect

    Commit a file containing EXAMPLE_API_KEY=fictional-sample-0000 (labeled fictional in the file itself). Then find it with git log -S and git grep across history, as if you did not know where it was.

  2. Step 2

    Assess the blast radius

    List every commit containing the sample, every branch and tag reaching it, and whether the scratch remote received it. Write the impact as three short lines: what, where, who could have seen it.

  3. Step 3

    Write the response order

    Write the ordered response for a REAL leak of this shape: revoke first (with the service owner), then remove from history, then rotate dependents, then verify, then postmortem. Explain why revoke precedes removal.

How to confirm it worked

  • The sample is found via history search, quoted with its commit
  • Impact lists commits, refs and remote exposure precisely
  • Response order starts with revoke, with the reason stated
  • The sample is plainly fictional and no real credential appears anywhere