The most detailed free FDE + DevOps library: 140+ lessons, 70+ labs and 80 long-form articles, in English and Turkish. Start learning →

DevOps Foundations · Module 6: CI basics and artifact discipline · Lab

Fix Over-wide Pipeline Permissions and a Wrong Cache Key

50 min hands-on · Advanced

The L16 pipeline plus a dependency cache; no real cloud credentials, fixture tokens only, under /tmp/dlab-m06-03.

Two ways to do this lab: in your browser on Killercoda (free, no install), or on your own machine as a local guide. Killercoda runs one free scenario at a time: if you see a waiting queue, close other Killercoda tabs and wait a minute.

Objectives

  • Scope each job to the minimum permission its steps need
  • Repair a cache key so wrong-branch restores fail closed
  • Prove a denial: the narrowed job cannot reach what it no longer needs
  1. Step 1

    Map the excess

    List every job with granted versus minimum-needed scopes. Pick the worst over-wide grant (for example a deploy token used for status updates) and narrow it to the single API it needs.

  2. Step 2

    Repair the cache key

    Craft a cache key that restores another branch's dependencies, show the silent mix, then fix the key (lockfile hash plus branch partition with restore-keys ordered honestly) and show the wrong-branch restore failing closed.

  3. Step 3

    Prove the denial

    Add a step to the narrowed job that attempts the removed access and show it denied. Record the denial plus the successful green run with the repaired cache.

How to confirm it worked

  • Job-by-job scope map with one narrowing applied and recorded
  • Wrong-branch cache mix demonstrated, then repaired to fail closed
  • Denial of the removed access shown in the run record
  • Final green run recorded with the repaired cache key