- Run
./scripts/validate.shfrom a clean clone. - Review the request tenant, target, action
plan_multi_tenant_cosmos_cmk_encryption, and approval evidence. - Confirm workload federation, least-privilege Azure roles, private DNS, quotas, retention, budgets, and regional support in a disposable environment.
- Compile and review
infra/main.bicep; keepdeployPlatform=falseuntil change approval.
Use a synthetic tenant and a dedicated resource group. Preserve the canonical plan and deployment correlation ID. Monitor adapter retries, denial rate, provider throttling, evidence delivery, latency, and cost. Never log tokens, request bodies containing personal data, or provider credentials.
The planner fails closed. On adapter failure, stop retries after a bounded attempt count, retain sanitized evidence, and alert the owner. Roll back the service-specific desired state using the approved pre-change snapshot; do not delete evidence under retention. Break-glass use requires two-person review and a retrospective.
Disable triggers, drain in-flight work, revoke federated role assignments, export required evidence, remove project resources only after retention and dependency checks, then verify no private endpoints, DNS records, identities, or cost-bearing resources remain.