Skip to content

Proof: Azure ACS Email hosted lifecycle and recipient delivery #152

Description

@yhay81

Tracks the hosted proof required before treating the Azure Communication Services Email transport and Azure deployment pack as production-ready.

Source implementation: #151
Portfolio program: #132
Exact accepted transport commit: 0289e2f9343018e92bcc469a9dfc696e5ad23823

Safety gate

  • Obtain explicit authorization for an isolated Azure test subscription/account and cost ceiling.
  • Do not use a shared production subscription or existing production resources.
  • Record subscription class, region, exact image digest, deployed commit, runtime/dependency versions, and resource inventory without publishing secrets or addresses.
  • Define rollback and cleanup before provisioning.

Infrastructure proof

  • Deploy the reviewed Azure Container Apps pack after it is merged and pin the immutable image digest.
  • Use PostgreSQL Flexible Server 18, private Blob Storage, Key Vault, managed identities, and least-privilege RBAC.
  • Provision or link ACS Email Communication Services with a custom verified domain; capture Domain, SPF, DKIM, and DKIM2 verification status.
  • Record current ACS quota/limit results and any approved custom-domain quota increase.
  • Configure Event Grid with an independent secret and exact ACS resource-topic restriction.
  • Run migrations before API/worker rollout and verify health/readiness.

Delivery and event proof

  • Send a controlled multi-recipient message and observe terminal recipient-level delivery reports correlated to the exact provider message ID.
  • Demonstrate duplicate delivery and out-of-order Event Grid events converge without duplicate terminal effects.
  • Demonstrate single-recipient engagement attribution and multi-recipient engagement retention as unattributed because ACS engagement events omit recipient identity.
  • Exercise bounce/failure/suppression behavior with controlled non-sensitive targets.
  • Confirm retry classification does not duplicate sends after an unknown LRO outcome.
  • Attach sanitized run IDs, timestamps, digests, status summaries, and CodeQL/CI links; never attach message content, recipient addresses, credentials, or raw secrets.

Teardown

  • Execute rollback/cleanup with retention disabled for the proof.
  • Verify zero unintended residual Container Apps, jobs, Event Grid subscriptions, databases, storage objects, identities, role assignments, or DNS changes.
  • Record final cost and residue audit.

This issue does not authorize billable Azure provisioning. The deployment pack remains experimental until this checklist is completed with evidence.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    parkedPreserved outside the active roadmap until demand or sponsorship justifies resumption

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions