Azure Chaos Studio Workspace Runbook: Safely Simulate Outages and Prove Recovery

3

Azure Chaos Studio Workspace Runbook: Safely Simulate Outages and Prove Recovery

Focus keyphrase: Azure Chaos Studio Workspace runbook

If your incident drill currently means “someone says let’s test failover” and everyone goes quiet, this runbook is for you. We’ll set up an Azure Chaos Studio Workspace, run a controlled Scenario in preproduction, and verify recovery with evidence you can reuse for ops reviews and audits.

What this runbook covers

  • Workspace scope and identity setup
  • Scenario configuration and permission validation
  • Execution checks, report review, and rollback hygiene

Chaos Studio Workspace architecture overview
Numbered flow from admin to workspace creation, managed identity permissions, scenario execution on scoped resources, and scenario report review.

1) Azure admin
Portal + RBAC

2) Chaos Studio Workspace
Scope: RG / Subscription

3) Managed identity
Least-privilege roles

4) Scenario targets in scope

Virtual Machines
Compute Zone Down

NSG / VNet
DNS Outage

Databases
Failover scenarios

5) Scenario report + monitoring
Status, duration, target resources

Diagram 1 (architecture): Keep blast radius under control by combining Workspace scope boundaries with least-privilege managed identity assignments before any Scenario run.

Prerequisites

Requirement Minimum Why it matters
Azure access Contributor on Workspace resource group Create and configure the Chaos Studio Workspace
Role assignment rights Owner or User Access Administrator on target scope Grant managed identity access for Scenario actions
Subscription setup Microsoft.Chaos resource provider registered Required to deploy Chaos Studio resources
Target resources Preproduction resources in one scoped boundary Run controlled outage simulations safely
Monitoring Azure Monitor + Log Analytics enabled Validate recovery, not just fault execution

Variables

Placeholder Description Example
<SUBSCRIPTION_ID> Azure subscription containing the workspace and test resources 00000000-1111-2222-3333-444444444444
<RESOURCE_GROUP> Resource group for Chaos Studio workspace rg-chaos-preprod
<WORKSPACE_NAME> Chaos Studio workspace name chaos-preprod-westus2
<SCOPE_RESOURCE_ID> Scoped resource ID (subscription or resource group) /subscriptions/.../resourceGroups/rg-app-preprod
<SCENARIO_NAME> Scenario to run Compute Zone Down

Step-by-step runbook

1) Create the Workspace and set scope

Portal path: Azure portal → Chaos Studio → Workspaces → Create

  1. Set Subscription, Resource Group, Workspace name, and region.
  2. On Scope, choose Subscription, Resource group, or Service group for discovery boundary.
  3. On Identity, select system-assigned or user-assigned managed identity.

Expected result: Workspace is created and starts discovering in-scope resources.

How to verify: Workspace opens successfully and resource inventory begins populating under Scenarios.

2) Grant required roles to the Workspace identity

Portal path: Chaos Studio Workspace → Access banner / Scenario configuration → Fix permissions

Assign only required roles for the planned Scenario actions. Example role mappings from Microsoft Learn include VM Contributor for VM shutdown actions and Network Contributor for NSG-based network outage actions.

# Optional: confirm provider registration
az provider register --namespace Microsoft.Chaos --subscription <SUBSCRIPTION_ID>

# Optional: verify registration state
az provider show --namespace Microsoft.Chaos --subscription <SUBSCRIPTION_ID> --query registrationState -o tsv

Expected result: Validation no longer reports missing permissions for selected scenario actions.

How to verify: Scenario configuration page shows permission checks passing.

3) Configure and run a Scenario in preproduction

Portal path: Chaos Studio Workspace → Scenarios → <SCENARIO_NAME> → Save configuration → Run

  1. Choose a Scenario (for example, Compute Zone Down or DNS Outage).
  2. Set required parameters (for example zone filters) and optionally exclude sensitive resources.
  3. Run the Scenario and monitor action state.

Expected result: Run completes with action-level status and duration captured in a Scenario report.

How to verify: Workspace → Reports shows run status, targeted resources, action timeline, and execution flow.

Chaos Studio scenario flow
Five-step sequence: choose scenario, validate permissions, run scenario, review action status, and validate application recovery evidence.

1) Select
Scenario

2) Validate
Permissions

3) Run
Scenario

4) Review
Action status

5) Confirm
Recovery

Checks to complete before you call this a successful drill
• Scenario status = Succeeded (or expected partial outcomes documented)
• Expected resources were actually targeted (not silently skipped)
• App metrics/logs show recovery within target RTO

Diagram 2 (flow): A Scenario run is complete only after execution data and application recovery evidence both check out.

Verification checklist

  • Workspace scope includes exactly intended preproduction resources.
  • Managed identity has required roles and no broad unnecessary roles.
  • Scenario run has a report with action statuses, durations, and targeted resources.
  • Skipped actions were reviewed and understood.
  • Application telemetry confirms recovery behavior after injected faults.

Rollback and recovery steps

  1. Cancel any active Scenario run from the Scenario run view if outcomes are outside expected blast radius.
  2. Validate temporary disruption actions are removed (for example NSG deny rules from outage simulation).
  3. If a service remains degraded, run standard workload rollback (deployment rollback, failover reversal, or traffic failback) per app runbook.
  4. Capture Scenario report and monitoring evidence for postmortem.

Common errors and fixes

Symptom Likely cause Fix
Scenario validation fails with missing permission Workspace identity lacks required RBAC role Use Fix Permissions or assign least-privilege custom role manually
Run succeeds but expected resource not affected Resource outside scope or excluded by filter Review Workspace scope and Scenario filters, then rerun in preprod
Too many skipped actions Scenario template targets resources not present in scope Confirm intended target types exist; adjust Scenario choice
Report looks clean but app still failed Fault execution succeeded, app resiliency did not Correlate report with Azure Monitor metrics/logs and update app recovery controls

Topic selection and exclusion evidence: output/spmonkey-azure-chaos-studio-workspace-runbook-2026-10-09-topic-selection.json

Sources


Discover more from SharePoint Monkey

Subscribe to get the latest posts sent to your email.