Chapter 3 of 6 · Before you start

Regional failover rehearsal for a governed AI service

Operate at scale 3 hours in a non-production POC

Chapter 3 of 6

Confirm:

CheckConfirm
Regional pathsThe governed service has deployed primary and secondary paths.
AgentThe platform owner confirms the immutable agent version and Entra identity.
GatewayThe gateway owner confirms the API Management policy version and both endpoints.
TraceThe primary path reports the expected trace fields. (The governed-agent, APIM, MCP security, observability, and promotion controls establish these prerequisites.)
ChangeThe approved change record names the exact resource-group scope, both selectors, maintenance window, delivery owner, and restore owner.
ControlsThe approved PowerShell and Bash health and routing controls accept the documented parameters. The routing owner confirms that Preview, Failover, and Restore change only the named selector.
AccessThe rehearsal operator has time-bound access for the approved scope. A customer-managed runtime directory exists outside the repository.

Implementation files#

TypeFileConsumer
Runtimeartifacts/control-definition.jsonThe Session 13 preflight scripts and regional rehearsal operators
Runtimeartifacts/regional/region.parameters.jsonThe Session 13 preflight scripts and rehearsal wrappers
Recordartifacts/regional/failover-runbook.mdThe service continuity and routing operators

control-definition.json binds the approved scope to the customer controls. The health control writes temporary JSON outside the repository. The wrappers remove it after each check. A read-only deployment preview is unsupported because this session does not deploy infrastructure. The routing control provides the read-only selector preview.

Session 13

Regional failover rehearsal for a governed AI service slide deck