Azure acceptance
The v1 Bicep and Kubernetes sources define the dedicated P0 environment. They do not prove deployment or runtime behavior. Deployment and practical smoke acceptance are tracked separately in #1812 and #1814.
Offline checks
Run these commands from the repository root:
npm run test:azure
az bicep build --file infra\bicep\main.bicep --stdout
kubectl kustomize deploy\k8s\base
kubectl kustomize deploy\k8s\acceptance\foundation-probeThey validate source and local rendering only; they do not contact Azure or prove a running service.
Deployment
Use the guarded exact-source command in the Azure operator guide. It binds the approved subscription, tenant, resource group, and source SHA/tree/input hash. A public API endpoint is required: apiServerAccessProfile.enablePrivateCluster must be false. A publicly resolvable FQDN on a private cluster does not satisfy this requirement.
The AKS API uses managed Entra authentication and Azure RBAC, with local accounts disabled. PostgreSQL, Key Vault, Blob, VNet/private endpoints, and Monitor retain their approved target and region placement.
Required P0 smoke checks
Use standard Azure CLI/SDK and kubectl observations for a short runtime check:
- Read the actual AKS properties and confirm public API, managed Entra, Azure RBAC, and disabled local accounts.
- Confirm normal workload rollout, service health, and deployed image/version.
- Exercise one real authorized Identity secret-redemption request and one denied request. Do not log credentials or returned secret values.
- Use one small generated fixture for exact-version Key Vault read, Blob round trip, and PostgreSQL behavior; confirm cleanup removes only data owned by that fixture.
- Confirm relevant telemetry where the service integration requires it.
Record only concise, sanitized results and identify the actual source/image versions. Preserve the external P0 data services and all resources outside the approved fixture. Do not treat unrun checks as passed.
Optional Foundation Probe evidence
The foundation-probe Job and verify-acceptance.mjs --collect-runtime-evidence remain available as supplemental evidence collection. The verifier observes the Job, pod, image, workload identity, native receipt, and correlated Azure Monitor records; it does not run the Identity broker grant-redemption smoke test. This extended collector is not an additional P0 shipping gate. Legacy tag-count, inherited NRMS policy-origin, provider-generated resource inventory, and historical receipt audits are not required acceptance steps.
See Testing for what source tests can and cannot prove.
