Cloud operations runbooks

Incident and cost-spike procedures: NAT, egress, Kubernetes spend, IAM lockout, failover, DNS, certificates and quotas.

  • Runbook

    Autoscaling Failure Runbook for AWS, Azure, Google Cloud and Alibaba Cloud

    Separate a policy that never fired from quota, regional capacity, launch failure, failed health checks and scale-in protection before you raise max size.

  • Runbook

    Cloud quota exhaustion

    Identify the quota that blocked a create or scale call, then request an increase or change the design without guessing the limit.

  • Runbook

    Cross-region traffic cost increase

    Separate inter-AZ, inter-region and internet egress on the bill, then find the copy or failover path that grew.

  • Runbook

    DNS routing failure

    Diagnose hosted-zone, resolver and health-check failures on Route 53, Azure DNS, Cloud DNS and Alibaba Cloud DNS.

  • Runbook

    Expired certificate

    Replace an expired TLS certificate on ACM, Azure Key Vault / Application Gateway, Certificate Manager and Alibaba SSL Certificates without dropping the old listener first.

  • Runbook

    IAM access lockout

    Regain administrative access without deleting the last admin, and use documented break-glass paths on each provider.

  • Runbook

    Kubernetes cluster cost increase

    Separate control-plane fees from node, volume, load-balancer and egress cost when a cluster bill jumps.

  • Runbook

    NAT gateway cost increase

    Find why NAT or Cloud NAT spend rose by separating hourly gateway charges from bytes processed.

  • Runbook

    Region failover

    Execute documented DNS or anycast failover, and separate that from ad-hoc region moves that are not in the DR plan.

  • Runbook

    Unexpected cloud cost spike

    Isolate a cloud spend spike by account, service and usage type before you delete or resize anything.