MicrosoftDocs/azure-monitor-docs/articles/chaos-studio

Last 20 commits touching this section.

923e10c

Apply Authoring Assistant suggestion

eb85da6

Chaos Studio Workspaces: add Key Vault, VM Hibernate, VM Maintenance Reboot templates and custom Scenario Actions Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

56449d6

Frame Chaos Studio Experiments (classic) as replaced by Workspaces and add migration guide (#5498) * Frame Chaos Studio Experiments (classic) as replaced by Workspaces and add migration guide - Reword the classic servicing include to 'being replaced by Workspaces' and link a new migration guide; move it directly under the H1 in all 49 classic articles. - Add chaos-studio-migrate-from-classic.md: identify model, concept map, experiment-to-Scenario map, capabilities not yet in Workspaces, steps, cleanup. - Add the guide to TOC (Workspaces and classic sections) and landing page; replace the 'Use Experiments (classic) when GA is required' landing link. - Recast the comparison, overview, and Workspaces overview articles as a transition. - Add 'which model am I using' sections to both troubleshooting articles. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Readability pass on Classic-to-Workspaces migration content Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Use 'after' for time sequence Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address PR validation: TOC section size, table header Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix broken stress-ng reference links Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Fix Resource Graph query: experiments are in the resources table Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Address adversarial review findings Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Keep classic banner direct; tighten migration guide wording Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

a2e2f0d

BULK: Retire Azure Monitor Platform subservice (#5424) * Retire Azure Monitor Platform subservice * Fix migrated article links

cd1cc85

Improve Chaos Studio Workspaces technical SEO (#5324) Apply the approved incremental documentation and navigation updates on authoritative MicrosoftDocs main, excluding previously merged Workspaces changes. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

e794ea5

Clarify Chaos Studio Workspaces documentation (#5285) * Clarify Chaos Studio Workspaces documentation Make Workspaces the current-model entry point, distinguish Experiments (classic), repair AKS and reference routing, and keep migration guidance limited to verified model-selection facts. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Correct Chaos Studio model guidance Label Workspaces preview status on the landing page, retain general availability as a classic selection criterion, and align agent and identity descriptions with current model behavior. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Align classic navigation terminology Use Experiments (classic) consistently in navigation and keep the shared legacy notice accurate for both experiment and agent workflow articles. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1fce7819-da5e-49b7-ab61-f178e80f0bf6 * Address Learn authoring feedback Apply grounded grammar and clarity improvements, preserve product-term capitalization, and remove an unsupported full-support claim for Experiments (classic). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1fce7819-da5e-49b7-ab61-f178e80f0bf6 --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: 1fce7819-da5e-49b7-ab61-f178e80f0bf6

988cd73

Rewrite AKS zone-down sample-app tutorial for async signals and hard placement (#5240) * Rewrite AKS zone-down sample-app tutorial for async signals and hard placement - Replace the fixed "~5 minute" Kubernetes reschedule claim with observable, monitor-driven guidance; downtime duration is no longer asserted as a fact. - Add explicit Cloud Shell bootstrap (az account set, az aks get-credentials, kubelogin convert-kubeconfig) before the first kubectl call. - Pin the front end to a single zone as an explicit, labeled demo anti-pattern instead of relying on the scheduler's default placement, so run 1's failure is deterministic instead of easy to miss. - Add a browser-based monitor (monitor.py) as the primary demo surface, showing storefront HTTP status, target-node readiness, pod placement, and a transition history; Metrics and kubectl become supporting signals. - Call out that the storefront HTTP signal and node NotReady status update asynchronously, and that the HTTP signal is primary. - Set the Compute Zone Down scenario duration to 5 minutes for this demo, with a note that other scenario types need their own duration guidance. - Replace the ScheduleAnyway topology spread constraint (previously described as guaranteeing per-zone placement, which it doesn't) with a DoNotSchedule hard constraint, plus an explicit verify-fix.sh check that every zone has a Ready store-front replica before run 2. - Add a troubleshooting section for when run 1's impact isn't visible. - Reframe run 2's outcome as sustained availability through the outage, not zero dropped requests, noting brief load-balancer convergence is still possible. Mirrors the final contract from the companion microsoft/chaos-studio samples/aks-zone-down-demo update. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Strengthen monitor error visibility and run-2 wording - Monitor: call out that a failed kubectl/API poll surfaces as an explicit error state per signal, instead of hanging on a "checking" placeholder. - Verification: clarify that verify-fix.sh retries transient kubectl/API/ JSON failures until its own timeout before failing, rather than exiting on the first transient error. - Run 2: reframe explicitly as sustained availability with a possible brief Azure Load Balancer convergence blip, not an unbroken "stays green throughout" state. Interim update while the companion microsoft/chaos-studio sample branch finishes its correction pass; not final until the revised contract lands. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Reconcile zone-pin, monitor, and verify steps with the immutable f9573c9 sample - Derive PIN_ZONE dynamically from the pod's actual node/zone label (kubectl get pods -> node -> zone label), instead of asking the reader to pick a bare zone number. - Move the deliberate-anti-pattern annotation to the Deployment's top-level metadata.annotations (matches deploy.sh); use the exact annotation key chaos-demo.aks-zone-down-demo/deliberate-anti-pattern. - Add the rollout restart/status wait and a self-check that the pod landed back in $PIN_ZONE, mirroring deploy.sh's own safety check. - Pin the monitor.py / verify-fix.sh download URLs to the immutable commit f9573c943694e88cf3aacbca38debe84fa91a62c instead of a 404ing main branch link; note the move to a tagged ref once merged. - Pass $PIN_ZONE verbatim (full zone label) to monitor.py --target-zone instead of a hardcoded eastus2- prefix. - Tighten the monitor error-state wording to match the real red banner behavior, and the verify-fix.sh wording to match its rollout-wait + per-zone Ready check. - Point the scenario zone-number entry and troubleshooting steps at $PIN_ZONE instead of an ad hoc 'the zone you pinned' reference. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Remove unsupported fixed recovery-time claim in run 2 wording Replace 'recovery within a few seconds' with environment-dependent wording: a brief Azure Load Balancer convergence blip is possible with no fixed time bound, and the monitor's transition history is what distinguishes a transient blip from a sustained outage. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> * Apply Learn Authoring Assistant style suggestions Accepts 10 of 11 flagged suggestions: splits four semicolon-joined independent clauses into separate sentences, replaces 'may' with 'might' per style guide, removes a dangling 'below' reference, adds a noun after the demonstrative 'these', and replaces a dash-joined clause with a full sentence introducing a cross-reference. Rejects the suggestion to drop the trailing colon on 'Remove the zone pin you added earlier:' (line 256) because it would break the established colon-before-code-block pattern used by every other numbered step in this article that introduces a fenced code block (for example, the 'Create a resource group and the cluster:' and 'Deploy the application:' steps). Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

33c0413

Remove unsupported VM Hibernate scenario Remove VM Hibernate from the Chaos Studio Workspaces scenario catalog because the action is unavailable in both the portal and API. Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

2fb8815

Merge upstream main into Terraform docs update Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

048ea74

Clarify Terraform support for Chaos workspaces Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

1feb8a6

Separate Chaos Studio Classic docs and document the AKS Chaos Mesh admin-credential limitation (#5123) * Separate Chaos Studio Classic docs and document the AKS Chaos Mesh admin-credential limitation * Address PR review: bullets for non-sequential list, include metadata, remove dead link

f1c3f1f

Add agent network connectivity troubleshooting to workspaces and scenarios article (#4967) * Add agent network connectivity troubleshooting section Documents the network configurations that block the Chaos agent from reaching Chaos Studio (private subnet/outbound access, NSG, firewall/UDR, proxy, DNS, IMDS) with fixes and diagnostics, plus a pointer from the Scenario-run-fails section. Rebased onto current main. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Link agent-based Scenario requirements to the connectivity troubleshooting section * Clarify recognition step with verified error string and Scenario run failure banner * Lowercase 'scenarios' per Learn style guide (capitalize_proper_nouns) * Add Portal/Azure CLI tabs to the subnet outbound-access and NSG fixes * Fix list-effective-nsg JMESPath fields and match link-text casing per review --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

b4e847b

Merge pull request #5080 from nikhilkaul1234/permission-flow-reconciliation Reconcile Workspace permission-flow docs with the shipped experience

c9127f4

Apply style suggestions

570da42

Reconcile Workspace permission-flow docs with the shipped experience Engineering confirmed the only automatic RBAC fixing for Workspaces is the Reader banner on the Workspace and the Fix Permissions option on the Scenario configuration page (fixResourcePermissions via REST). Remove the create-time Automatic role assignment step from the quickstart, document the three assignment paths on the permissions page, retitle the service-group known issue, and align the overview, comparison, limitations, and classic security pages. Link the least-privilege custom-roles article from the permissions page.

6213bf5

Apply engineering review feedback to the sample-app tutorial Changes that were pushed to the sample-app-tutorial branch after #5073 merged: document the confirmed permission flow (Reader banner on the workspace, Fix Permissions on the scenario configuration page when validation reports missing RBAC, least-privilege custom roles linked as the alternative), pin the sample manifest to the 2.2.0 release, and make the fix step deterministic with a zone topology spread constraint.

cf5edf0

Add least-privilege custom roles how-to for Chaos Studio Workspaces (#5076) Adds guidance for customers who opt out of fixResourcePermissions and build least-privilege custom roles from scenario validation output. Adds a TOC entry under the Workspaces section. Rebased onto latest main to resolve TOC.yml merge conflict; applies accepted style suggestions.

0379b0a

Add sample-app zone resilience tutorial for Chaos Studio Workspaces (#5073) * Add sample-app zone resilience tutorial for Workspaces Adds an end-to-end tutorial that deploys the AKS store demo sample app to a zone-redundant cluster and runs the Compute Zone Down scenario from a workspace, with TOC entry and cross-links from the workspace quickstart and the AKS guidance page. * Apply style suggestions * Rework tutorial into a break-fix-prove arc Run the zone-down scenario first against the app's default single-replica front end so the storefront visibly fails, then scale it out and rerun to validate the fix. Adds a monitoring-signals section and a report-comparison section. * Apply style suggestions

d466fc8

Chaos Studio: remove How-to guides and agent sections from the hub page (#5030) * Remove How-to guides and Chaos Studio agent sections from the hub page * Label classic agent docs and redirect workspace users to agent-based scenarios * Add Linux distribution support for agent-based Scenarios * Restore Physical Memory Pressure and agent requirements lost in merge

d48569e

Document confirmed agent-based scenario support: restore Physical Memory Pressure, add requirements, update private networking