Chapter 3 of 6
Confirm:
| Check | Confirm |
|---|---|
| Regional paths | The governed service has deployed primary and secondary paths. |
| Agent | The platform owner confirms the immutable agent version and Entra identity. |
| Gateway | The gateway owner confirms the API Management policy version and both endpoints. |
| Trace | The primary path reports the expected trace fields. (The governed-agent, APIM, MCP security, observability, and promotion controls establish these prerequisites.) |
| Change | The approved change record names the exact resource-group scope, both selectors, maintenance window, delivery owner, and restore owner. |
| Controls | The approved PowerShell and Bash health and routing controls accept the documented parameters. The routing owner confirms that Preview, Failover, and Restore change only the named selector. |
| Access | The rehearsal operator has time-bound access for the approved scope. A customer-managed runtime directory exists outside the repository. |
Implementation files#
| Type | File | Consumer |
|---|---|---|
| Runtime | artifacts/control-definition.json | The Session 13 preflight scripts and regional rehearsal operators |
| Runtime | artifacts/regional/region.parameters.json | The Session 13 preflight scripts and rehearsal wrappers |
| Record | artifacts/regional/failover-runbook.md | The service continuity and routing operators |
control-definition.json binds the approved scope to the customer controls. The health control writes temporary JSON outside the repository. The wrappers remove it after each check. A read-only deployment preview is unsupported because this session does not deploy infrastructure. The routing control provides the read-only selector preview.