Practical knowledge. Stronger foundations.
YOUR PREPARATION TOOLKIT

Last-hour review

Six-part technical answer

Scope the impact. Model the path/state. Collect discriminating evidence. Choose a bounded action. Verify the customer outcome. Prevent the confirmed failure from recurring.

Puppet / Foreman

Facts → catalog → apply → report. Ordering is not the same as notification. Hiera precedence must be explainable. Execs need meaningful state guards. No-op is not a full proof of safety. Partial runs are not universal rollback. Sensitive is not encryption. Provisioned OS is not ready service. Never put lab DHCP on the live LAN. PUPPET-ARCHPUPPET-RELPUPPET-HIERAPUPPET-EXECPUPPET-SENSITIVEFOREMAN

Python / integration

Pure planner; validated complete input; coherent revision; scoped identity; deterministic diff; bounded concurrency; request timeout plus total deadline; stable operation ID; explicit unknown outcomes; per-target results; current-state verification. A timeout may follow a successful write. Queue delivery can repeat. Acknowledgment and completed work are different. Do not turn an exception into an empty successful inventory. PY-MOCKPY-ASYNCHTTP-SEMRABBIT-ACKNAUTOBOT-API

Linux

High load does not necessarily mean busy CPUs. Host spare RAM does not disprove a cgroup OOM. A root-shell success does not prove a systemd service works. Compare CPU/I/O/memory pressure, process state, service user, namespace, limits, and SELinux evidence. Fix the cause, not every possible limit. LINUX-MANLINUX-CGROUPLINUX-PSISYSTEMDRHEL-SELINUX

Network

Trace both directions and original/translated tuples. Link up ≠ LACP forwarding. BGP Established ≠ accepted route ≠ selected route ≠ FIB ≠ service. Local preference affects your outbound choice; inbound traffic depends on remote policy. Prevent route leaks with explicit intent and negative tests. ICMPv6 matters. Fast BFD can detect or amplify trouble. LINUX-BONDRFC-BGPRFC-BGP-OPSRFC-BFDRFC-ND

Stateful security / TLS

Config sync ≠ session sync. IKE SA ≠ working Child SA/data path. NAT-T commonly uses UDP 4500; native ESP is IP protocol 50. MTU overhead must be counted. Interception creates two TLS legs. Client pinning and mTLS do not vanish because a CA is trusted. TLS 1.3 ECDHE is not passively decrypted with only a certificate private key. Fail-open/closed is an owned policy decision. RFC-IKERFC-NATTRFC-TLSF5-SSLO

Performance / overlay

Measure packet rate, flow count, per-queue/per-core load, locality, drops, and p99, not only average Gbps. Buffers absorb bursts but can add latency. Offloads change host capture appearance. EVPN control plane and VXLAN data plane are separate. RD uniqueness is not RT import policy. For the stated ordinary IPv4 VXLAN example, 1,500 inner IP bytes require 1,550 outer IP bytes. LINUX-SCALINGWIRESHARK-OFFLOADRFC-EVPNRFC-VXLAN

Before you close

Ask what the first 90 days must accomplish, where the two teams' responsibilities meet, which versions are deployed, and how change correctness is verified. Acknowledge unfamiliar products precisely, then show transferable reasoning. Do not apologize for not knowing every preferred platform. Do not claim a lab as production.

Final self-test

Can you write the safe planner? Explain your real Puppet workflow? Trace provisioning failure? Diagnose a resource limit? Walk a failed request? Defend a BGP export policy? Draw TLS trust on both legs? State a rollback that survives management loss? Tell five truthful stories without a script?

References resolve in the interview source library.