Courseiva

EX294 Practice Question: Create content collections and execution environments

An execution environment fails to build because `pip install` fails when installing a Python package from a private repository that requires authentication. The build works when run locally by the developer. Which approach should be taken to securely provide credentials during the `ansible-builder build` process?

⚠ Common exam trap

Candidates often assume credentials must be placed directly in the execution environment definition file or the generated Containerfile, overlooking the secure, build-time injection mechanisms provided by BuildKit secrets and environment variables.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a `pip.conf` file that uses environment variables or BuildKit secrets to inject credentials.

`ansible-builder` supports BuildKit secrets and environment variable injection via a `pip.conf` file, allowing credentials to be passed securely at build time without hardcoding them into the execution environment definition. This approach ensures that sensitive authentication tokens are not exposed in the `execution-environment.yml` or the generated `Containerfile`, and it mirrors the local developer workflow where environment variables or secret mounts are used.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the credentials in the Automation Hub token and reference it.

    Why it's wrong here

    Automation Hub tokens authenticate collection and image registry access, not pip against a private Python index, so pip still receives no credentials. It tempts because it is the standard secret mechanism in this toolchain, and would be correct when the failure involves pulling collections or base images rather than installing packages.

  • ✗

    Add the credentials directly to the `Containerfile` that `ansible-builder` generates.

    Why it's wrong here

    The Containerfile is regenerated by ansible-builder on each build, so hand-edited credentials are overwritten and also persist in image layers. It tempts because editing the generated file directly appears to fix the failing pip command, and would be acceptable only for a throwaway local build with no secret involved.

  • ✗

    Include the credentials in the `execution-environment.yml` under `dependencies: python:`.

    Why it's wrong here

    Credentials written into execution-environment.yml are committed to source control and baked into build context, exposing secrets to anyone with repository access. It tempts because that file already lists Python dependencies, so adding an index URL there feels natural, and it would suit a public repository needing no authentication.

  • ✓

    Create a `pip.conf` file that uses environment variables or BuildKit secrets to inject credentials.

    Why this is correct

    A pip.conf referencing environment variables or BuildKit secrets keeps credentials out of image layers and build context, satisfying the requirement to authenticate to the private repository securely during ansible-builder build without exposing secrets in the resulting image.

About these practice questions

One of 392 original EX294 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This EX294 practice question is part of Courseiva's free Red Hat certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the EX294 exam.