≈489 tokens on demand. Your agent reads this file only when SKILL.md points to it.
Azure Infra Validation Runbook
Deployment Constraint Branches
VpnGw1-5 non-AZ not allowed: switch to an AZ SKU such as VpnGw1AZ.
Public IPs must have zones configured: recreate Standard Public IPs with zones.
- VNet overlap: reassign spoke address spaces.
useRemoteGateways fails early: apply it only after the hub gateway is complete.
- MFA / tenant mismatch: switch tenant or re-login before deployment.
Phase Detail
- Feasibility: write the validation goal in one line, decide whether Azure-only is enough, minimize topology, and set cleanup expectations.
- Scope Fix: choose lab vs production, fix tenant/subscription, and define the target observation.
- Official Grounding: verify prerequisites, limits, SKUs, and gaps against Microsoft Learn.
- Preflight: run
az account show, check provider registration, region availability, SKU/zone/RBAC, and decide polling evidence.
- Baseline Build: create RG, hub/branch/spoke VNets, GatewaySubnet, and peering. Apply remote gateway after gateway readiness.
- Core Deployment: create Public IPs, VPN Gateway / Route Server / NVA, and monitor long-running resources.
- Connectivity: create VPN or peer connections and wait for
Connected.
- Baseline Capture: collect BGP peer status, learned routes, route table, prefix count, and observation start time.
- Change: apply one setting change, capture Accepted/Succeeded/correlation ID, and wait for reconfiguration.
- Compare: recapture routes/status, compare route count and summarization, and separate control-plane completion from route/metric impact.
- Cleanup or Persist: delete one-shot labs or record why they remain.
Ready Rules
- Do not continue before
Succeeded, READY, or Connected is observed.
- Prefer
scripts/watch-az-resource-state.ps1 or scripts/check-vpn-lab-status.ps1 when available.
- Do not claim no outage from Activity Log alone; use polling, route, health, or metrics evidence.