An auditor asks what share of PersistentVolumeClaims carry the retention label and you have a 100%-pass admission dashboard — what do you report?
answer
- Two numbers, two different denominators
- Requests since a date, not objects today
- Pass rates drift up by selection
- Coverage needs an inventory count
- Report the gap with an owner and date
basics
~20 sReport the count from an inventory of stored PVCs, not the dashboard. A 100% pass rate describes admission requests since the rule was enabled; the auditor asked about the population of objects that exist, which only enumerating them answers.
solid answer
~50 sThe two numbers have different denominators. The dashboard's denominator is PVC write requests since enforcement began; the auditor's is every PVC in the estate today. Handing over the first as an answer to the second is a misstatement, and it is the kind that costs you credibility on every other control you claim. So I would report three things: the control is enforced for creates and updates from a stated date, here is the measured share of stored PVCs carrying the label from an actual inventory, and here is the remediation plan for the gap with an owner and a date. I would also flag that a pass rate drifts toward 100% by construction, because authors learn what the gate accepts and stop submitting anything else — so it measures request hygiene, not the estate.
go deeper
Know that an enforcement pass rate counts requests the gate was asked about, and that the objects sitting in a cluster from before the rule are not in that count at all.
Be able to name the denominator of any compliance number you quote, and to explain why measuring stored objects is a different exercise from reading a gate's telemetry.
Show that you would measure the estate, report the real figure and the gap together, and attach an owner and a date rather than defending the flattering number.
Own the reporting standard: enforcement date and population coverage stated as separate claims, exceptions with expiries, and a culture where an unflattering measured number is preferred to a green metric nobody can define.
## Two populations wearing the same percentage sign A gate's telemetry answers: *of the requests I was asked about, how many passed?* The auditor is asking: *of the objects that exist, how many satisfy the control?* Those questions share a unit and nothing else. The request population excludes, by construction: - every object created **before** enforcement began — the legacy pocket, which for long-lived resources like claims and namespaces may be most of the estate; - every object the rule's scope does not match — a different resource, a subresource, an operation not in the list; - every object living somewhere the gate is not installed — another cluster, another account, an environment stood up by a team you do not know about. So the pass rate is an upper bound on nothing. It can read 100% while a majority of stored objects violate the control. ## The selection effect There is a second reason to distrust the number as a coverage claim. Enforcement changes behaviour: once a rule denies unlabelled claims, authors add the label to their templates, and the denials stop arriving. A mature gate therefore trends toward a 100% pass rate **whatever the estate looks like**, because the denominator is the traffic of people who have already learned the rule. A rising pass rate is evidence the rule is understood; it is not evidence the population is compliant. ## What to report instead A defensible coverage statement has four parts: 1. **The population.** "All PersistentVolumeClaims in the three production clusters as of 12 May" — say what was counted and where, because scope is the first thing a sharp auditor probes. 2. **The measurement method.** Enumerated stored objects and evaluated them with the same rule logic the gate uses. Not "the gate says so". 3. **The number, including the gap.** "1,842 of 2,242 carry the label; 400 predate enforcement." 4. **What happens next.** Owner, remediation approach, date, and any exceptions with expiry. Alongside it, state the control's operation separately: enforced for creates and updates since a stated date. Enforcement date and population coverage are two different assertions, and conflating them is the whole trap. ## Why volunteering the gap is the strong move The instinct is to present the flattering number and hope the question does not get sharper. It always does — an auditor who samples five random PVCs and finds two unlabelled has learned something worse than a 82% figure: that your reporting cannot be relied on. Every other control you assert now needs independent testing. Volunteering an unflattering measurement with a credible plan costs one uncomfortable conversation; being caught reporting request telemetry as population coverage costs the benefit of the doubt everywhere. ## The judgment call underneath Once the real number is on the table you owe a decision about the 400, and it is a genuine tradeoff rather than a technicality: - **Remediate now.** Write the label onto the stored objects. Cheap for a label, much less cheap when conformance requires recreating objects — and for storage-backed workloads, touching live objects carries its own risk. - **Let churn close it.** Free, but for resources that are rarely rewritten it may never converge, and "eventually" is not a date an auditor accepts. - **Register a time-boxed exception.** Honest, visible, and it puts the residual risk in front of whoever owns it — but an exception with no expiry is just the gap with paperwork. Usually the answer is a mix: remediate what is safe to touch in bulk, except the rest with owners and expiries, and hold the gate so the population cannot grow. What you should not do is pick the option that makes the dashboard look right. ## What interviewers listen for They want to hear you separate *the control operates* from *the population complies*, name the denominator problem out loud, and reach for a measurement of stored objects rather than a metric that happens to be at hand. A candidate who says "we show them the dashboard, it is green" has failed the question in one sentence.
- The auditor accepts the dashboard without pushing. Do you correct them?Yes. An audit finding is cheaper than a misstatement discovered later, and once you know the number is being read as something it is not, staying quiet is a choice. I would put the correct measurement in the record with the remediation plan attached, so the file shows the gap was known, sized and owned rather than obscured.
- How do you decide between mass-remediating the 400 and letting normal churn close the gap?By churn rate and blast radius. For a resource rewritten on every deploy, churn genuinely converges within a release cycle and the cheapest action is to wait and measure. For claims and other long-lived objects, churn never comes, so you remediate deliberately — in batches, off-peak, with a rollback — or you accept the risk in writing with an expiry. The deciding question is whether you can name a date.
- What would you change so this question is easier to answer next quarter?Measure the estate on a schedule rather than when asked, from an inventory of stored objects, and publish coverage next to enforcement rather than instead of it. Then the number is a trend a team can act on, the legacy pocket is visible from day one of any new rule, and nobody is tempted to reach for the gate's pass rate because a better number already exists.
saying these in an interview costs you the question
- Presents the admission pass rate as estate compliance
- Cannot state the denominator of the metric being reported
- Assumes a rising pass rate means the estate is improving
- Reports coverage without naming the population and date measured
- Offers an exception with no owner and no expiry