Chapter 1 of 6
Session scope#
What we will do#
Objective. Confirm that operators can move traffic to the secondary region and back before a real regional incident forces that move untested.
The team previews and moves one approved traffic selector to the secondary path, checks it against the regional contract, then restores and re-checks the primary path. The round trip must complete with a working secondary path and a working restored primary path.
Why it matters#
Problem. A failover path that has never been exercised often fails exactly when it's needed, during a real regional incident.
Solution. This rehearsal moves traffic to the secondary path and back under normal conditions, with delivery-owner approval before each move, so the team learns whether it actually works before an incident forces it.
Boundaries#
The selected service already has both regional paths deployed; infrastructure and API Management policy changes use the approved CI/CD workflow, outside this rehearsal. Foundry, API Management, and Azure Monitor stay authoritative for live service state; the repository holds the rehearsal contract, and the customer change system holds the approval and runtime outcome.
This session moves one approved selector through the customer routing control. It does not deploy infrastructure, change policy, update identity, or review the fleet inventory. Infrastructure and policy changes use the approved CI/CD workflow.
Session preparation
Who should join
- AI platform, service continuity, and API Management engineers
- Service and delivery owners
What you need
- The governed service has deployed primary and secondary paths.
- The platform owner confirms the immutable agent version and Entra identity.
- The gateway owner confirms the API Management policy version and both endpoints.
- The primary path reports the expected trace fields. (Sessions 04, 06, 08, 11, and 12.)
- The approved change record names the exact resource-group scope and both selectors. It also names the maintenance window, delivery owner, and restore owner.
- The approved PowerShell and Bash health controls accept the documented parameters.
- The approved PowerShell and Bash routing controls accept the documented parameters. The routing owner confirms that
Preview,Failover, andRestorechange only the named selector. - The rehearsal operator has time-bound access for the exact approved scope. The customer access process removes it after the rehearsal.
- An existing customer-managed runtime directory is available outside the repository for temporary health results.