How should secrets such as warehouse keys be handled in training CI?
PICTURE THIS: DATA SPLIT
Fit on train, tune on val, report on test once.
Simple meaning
Inject them from a secret manager at runtime, never commit them, and scope IAM to read-only training tables.
WHY — CI/CD for ML instead of guessing?
Why interviewers care about CI/CD for ML:
separate people who only read docs from people who shipped.
and tied to MLOps work.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens step by step?
Before you speak the answer, walk the interviewer through these steps:
- 1Inject them from a
secret manager at runtime, never commit them, and scope IAM to read-only training tables.
- 2Containers should run as
non-root with short-lived credentials.
- 3Logs must be scrubbed
so connection strings never hit the tracker.
- 4Give an example
One tiny concrete case you can say aloud.
- 5Common mistake
What juniors usually get wrong.
- 6Close
When you pick this over the alternative.
EXAMPLE — See it in action
Here's a short line you can speak, broken into clear beats:
Note: Adapt this scaffold to your own project — keep it under 60–90 seconds.
Key takeaway
Inject them from a secret manager at runtime, never commit them, and scope IAM to read-only training tables. Containers should run as non-root with short-lived credentials.