Cloud operations runbooks
Incident and cost-spike procedures: NAT, egress, Kubernetes spend, IAM lockout, failover, DNS, certificates and quotas.
- Runbook
Autoscaling Failure Runbook for AWS, Azure, Google Cloud and Alibaba Cloud
Separate a policy that never fired from quota, regional capacity, launch failure, failed health checks and scale-in protection before you raise max size.
- Runbook
Cloud quota exhaustion
Identify the quota that blocked a create or scale call, then request an increase or change the design without guessing the limit.
- Runbook
Cross-region traffic cost increase
Separate inter-AZ, inter-region and internet egress on the bill, then find the copy or failover path that grew.
- Runbook
DNS routing failure
Diagnose hosted-zone, resolver and health-check failures on Route 53, Azure DNS, Cloud DNS and Alibaba Cloud DNS.
- Runbook
Expired certificate
Replace an expired TLS certificate on ACM, Azure Key Vault / Application Gateway, Certificate Manager and Alibaba SSL Certificates without dropping the old listener first.
- Runbook
IAM access lockout
Regain administrative access without deleting the last admin, and use documented break-glass paths on each provider.
- Runbook
Kubernetes cluster cost increase
Separate control-plane fees from node, volume, load-balancer and egress cost when a cluster bill jumps.
- Runbook
NAT gateway cost increase
Find why NAT or Cloud NAT spend rose by separating hourly gateway charges from bytes processed.
- Runbook
Region failover
Execute documented DNS or anycast failover, and separate that from ad-hoc region moves that are not in the DR plan.
- Runbook
Unexpected cloud cost spike
Isolate a cloud spend spike by account, service and usage type before you delete or resize anything.