A half-day workshop on deploying and using Azure SRE Agent in production. This workshop is designed for IT/Ops, SRE, and platform engineering teams who want to see how Azure SRE Agent can be deployed, connected to production signals, and used to investigate and remediate incidents.
- IT Pros
- SREs / platform engineers
- cloud operations teams
- Azure architects responsible for operating production workloads
- Teach it - give the agent context, goals, and guardrails
- Connect it - wire the agent to observability, incident, and code systems
- Let it work - run a realistic incident and review outcomes
The lab uses Azure-Samples/app-service-dotnet-agent-tutorial as the target workload: a small .NET 9 minimal-API app hosted on Azure App Service with a deployment slot, Application Insights, and a controllable HTTP 500 fault (INJECT_ERROR=1). See docs/sample-app.md for the full integration story.
Prerequisites: az, git, pwsh 7+, and the .NET 9 SDK on PATH.
Important: regional quota. The workshop deploys an App Service Linux Standard (S1) plan, which requires a non-zero per-region instance quota. On many internal, sponsored, MPN, and CSP subscriptions,
eastusandeastus2are capped at 0 instances for this SKU and the deploy will fail at preflight withSubscriptionIsOverQuotaForSku. The interactive script therefore offers a curated picker with three regions known to have quota on typical workshop subscriptions:canadacentral,westus3, andswedencentral. If you must use a different region, request an App Service Standard Linux instance quota increase first (Portal: Subscription, Usage + quotas, App Service, region, Request increase).
pwsh ./scripts/deploy-demo-env.ps1That single command provisions the infrastructure, clones the sample, builds it, deploys both slots, and runs smoke tests. The interactive scripts/deploy-demo-env.ps1 script:
- Checks
az,git, and the .NET 9 SDK are installed. - Reuses your existing
azsession, or runsaz loginonly if needed. - Prompts for the subscription, resource group, and region (with
scripts/env.confvalues as defaults) and persists your choices. - Validates the region supports Linux App Service S1.
- Runs
az deployment group validateas a preflight so quota / SKU / region issues surface immediately, and on a quota failure offers to re-pick the region and re-validate. - Deploys
infra/main.bicep(App Service plan, web app,stagingslot, Log Analytics, Application Insights, Http5xx alert). - Clones the sample app into
./sample-app/(gitignored) viascripts/clone-sample-app.ps1. - Builds with
dotnet publish -c Releaseand deploys to both the production and staging slots withaz webapp deploy --slot(with built-in cold-start retry for first deploys on a fresh plan). - Runs
scripts/smoke-test.ps1against both slots and writes the deployment outputs back intoscripts/env.conffor the other workshop scripts to consume.
End state: a healthy production slot, a faulty staging slot, Application Insights wired up, and an Http5xx alert ready for Azure SRE Agent to investigate during Module 6. Full parameter reference and unattended/CI usage in PS-SETUP.md.
If you prefer azd, the same infra and sample are wired up via azure.yaml. The azd flow has two known sharp edges on slot-enabled App Service apps (init-time project validation and a slot-deploy hang), so the PowerShell path above is recommended. See AZD-SETUP.md for the full steps and workarounds.
SREinProd/
├── README.md
├── CODE_OF_CONDUCT.md
├── LICENSE
├── SECURITY.md
├── CONTRIBUTING.md
├── azure.yaml # azd definition (points to ./sample-app)
├── AZD-SETUP.md
├── PS-SETUP.md
├── TROUBLESHOOTING.md
├── docs/
│ ├── architecture.md
│ ├── facilitator-guide.md
│ ├── delivery-plan.md
│ ├── demo-runbook.md
│ └── sample-app.md # integration story for the .NET sample
├── Learning/ # concepts, discussions, and reference material
│ ├── README.md
│ ├── 1-Foundation.md
│ ├── 2-Deploy-Agent.md
│ ├── 3-Connectors.md
│ ├── 4-Connect-Observability.md
│ ├── 5-Response-Plans-and-Guardrails.md
│ └── 6-Incident-Drill.md
├── Workshop/
│ ├── ReadMe.md # streamlined hands-on path
│ ├── 1-Foundation.md
│ ├── 2-Deploy-Agent.md
│ ├── 3-Connectors.md
│ ├── 4-Connect-Observability.md
│ ├── 5-Response-Plans-and-Guardrails.md
│ └── 6-Incident-Drill.md
├── infra/
│ ├── README.md
│ ├── main.bicep # App Service + slot + AI + LA + Http5xx alert
│ └── main.parameters.json
├── scripts/
│ ├── env.template # copy to env.conf (gitignored) and fill in
│ ├── clone-sample-app.ps1 # idempotent clone of the upstream sample
│ ├── deploy-demo-env.ps1 # end-to-end environment build
│ ├── deploy-to-slot.ps1 # build + zip + deploy helper
│ ├── demo-warmup.ps1 # baseline traffic + fault injection
│ ├── demo-rollback.ps1 # restore env between runs
│ └── smoke-test.ps1
└── sample-app/ # cloned on demand; gitignored
The published workshop contains six completed modules:
- Foundation
- Deploy the Agent
- Connectors
- Connect Observability
- Response Plans and Guardrails
- Incident Drill
Use Workshop/ReadMe.md for the streamlined hands-on path. Each exercise retains only the actions, required context, safety notes, troubleshooting, and validation needed to complete the lab.
Use the Learning companion for deeper concepts, discussion prompts, reference tables, screenshot inventories, and maintainer guidance. The unfinished exercises are not included in the published workshop.
- The sample application is licensed MIT by Microsoft
Azure-Samples. This repo ships only the infra/scripts/docs needed to integrate it. - Tenant-specific values (subscription, region, regional quotas) belong in
scripts/env.conf, which is gitignored.