Skip to content

docs: clarify Front Door regional resiliency and fire-drill gates - #37

Open
Hou (SciencePotato) wants to merge 8 commits into
mainfrom
houchichan-microsoft-front-door-resiliency-guide
Open

Hou (SciencePotato) wants to merge 8 commits into
mainfrom
houchichan-microsoft-front-door-resiliency-guide

Conversation

@SciencePotato

@SciencePotato Hou (SciencePotato) commented Oct 7, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Clarify responsibility for the Microsoft-configured regional-resiliency baseline and customer operation; customers replacing the topology own their alternate design.

  • Describe independent two-region Function/storage/Key Vault/identity stacks sharing the public endpoint, caller trust and encryption-key identity.

  • Require EACH region to sustain the combined peak workload: at least twice its normal traffic in a balanced two-region baseline, plus planned headroom. Require measured latency/error/capacity evidence and quota/provider/dependency validation; autoscale settings alone are not proof.

  • Add a bounded nonproduction fire-drill runbook covering approvals, automatic health-based rerouting, sustained survivor load, unconditional restoration, conservative failback, reverse-direction repetition and sanitized evidence.

  • Distinguish evaluation-only throughput from full live-send capacity. Require production-representative provider-approved non-delivering credential/provider testing, or separately authorized delivery validation, for the capacity gate.

  • Preserve existing measured failover results and limitations. An app-stop simulation is not a full regional-outage test, and no zero-downtime, safe-retry or production-capacity claim is introduced.

  • Add a practical proposed-test checklist covering what to test, safe execution, agreed acceptance criteria and evidence, including both failover directions, survivor capacity, dependency refresh, access rejection, failback and interrupted-controller recovery. Separate these proposed tests from historical results and exclude real-SAS flows because evaluation can trigger native fallback.

Scope

Documentation only: docs/FRONTDOOR.md. Independent branch based on main, separate from infrastructure PR #34 and observability PRs #35 and #36. No Azure deployment, outage, scaling, policy or monitoring operation was performed.

Validation

  • Reviewed against the requested baseline, capacity and fire-drill requirements and the JavaScript evaluation early-return behavior.
  • All 15 local links/heading anchors and git diff whitespace checks passed.
  • Observed failure totals, timings and limitations are preserved; the results prose uses neutral HTTP-error wording.
  • Published head: e2faa04e808403393c486131f6948dd4798b7d1c.
  • Runtime tests not run: documentation-only change with no documentation test job configured.

Hou Chi Chan and others added 8 commits October 7, 2026 16:01
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7c454360-a88e-447c-9158-ba68d9ba6ede
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7c454360-a88e-447c-9158-ba68d9ba6ede
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7c454360-a88e-447c-9158-ba68d9ba6ede
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7c454360-a88e-447c-9158-ba68d9ba6ede
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7c454360-a88e-447c-9158-ba68d9ba6ede
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 7c454360-a88e-447c-9158-ba68d9ba6ede
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant