1 min lesson
Technical screen #1: scripting + identity fundamentals
Walk through the worked example in "Technical screen #1: scripting + identity fundamentals", then explain what it demonstrates.
Step 1 of 2
Sixty minutes that split in two: a live scripting problem and deep, configuration-level questions on identity. Both are graded as a senior engineer, which means trade-offs and failure modes, not textbook definitions.
A complete walkthrough of the Okta example must cover every Link header so pagination cannot drop users, idempotent PUTs so reruns cannot double-provision, backoff and retries for 429 rate limits, OKTA_TOKEN from the environment and timeouts plus raise_for_status() so API errors stop loudly. This is realistic IT automation, not an algorithm puzzle: expect API reconciliation, log parsing or safe provisioning.
import os, requests
BASE = "https://your-org.okta.com/api/v1"
HEADERS = {"Authorization": f"SSWS {os.environ['OKTA_TOKEN']}"}
def get_all_users():
"""Page through every active user, following Okta's Link header."""
users, url = [], f"{BASE}/users?filter=status eq \"ACTIVE\"&limit=200"
while url:
r = requests.get(url, headers=HEADERS, timeout=30)
r.raise_for_status()
users.extend(r.json())
url = r.links.get("next", {}).get("url") # pagination, not a magic page count
return users
def ensure_in_group(user_id, group_id):
"""Idempotent: PUT is safe to re-run; adding an existing member is a no-op."""
r = requests.put(f"{BASE}/groups/{group_id}/users/{user_id}",
headers=HEADERS, timeout=30)
r.raise_for_status()Narrate the choices as you go. Mention pagination so you don't silently drop users past page one, rate-limit handling for 429s, secrets pulled from the environment not hardcoded and the fact that re-running the script can't double-provision anyone.