Skip to content

fix(azure): check VM size availability at plan time - #136

Merged
rishabkumar7 merged 2 commits into
mainfrom
fix/azure-deploy-resilience
Oct 1, 2026
Merged

rishabkumar7 merged 2 commits into
mainfrom
fix/azure-deploy-resilience

Conversation

@rishabkumar7

Copy link
Copy Markdown
Collaborator

Closes #99

Changes

azure/main.tf

TROUBLESHOOTING.md

  • SkuNotAvailable section now explains the plan-time messages, lists x64 sizes that work, and warns about Arm64 sizes.
  • New sections: Azure for Students errors (allowed-region policy, credits used up) and Resource group already exists.

azure/README.md

  • The Student note now points to the in-repo section instead of the external Spot-instance guide. That guide recommends Standard_DC1s_v2, which is no longer listed in eastus, eastus2, westus2, or centralus.

Testing

terraform fmt -check and terraform validate pass (azurerm 5.x, azapi 2.13.0).

Plan-level (non-Student subscription):

Case Result
Defaults (Standard_B1s, East US) Plans normally
az_region="East US 2" Plans normally (display name converts to eastus2)
Standard_D1 (NotAvailableForSubscription on this subscription) Stops: "not available for your subscription"
Standard_B2pts_v2 Stops: "is Arm64, but the lab uses an x64 Ubuntu image"
Standard_Nope Stops: "not offered in East US"

Full deploy (release mode, Standard_B1s, East US):

  • Apply succeeded; setup.done present.
  • Password SSH as ctf_user works, including with public-key auth disabled on the client.
  • CTF test suite against the deployed lab: 28 passed, 0 failed.
  • The apt lock race didn't occur on this boot, so the lock-wait path wasn't exercised.
  • Lab destroyed afterwards.

Notes

  • Not tested on a real Azure for Students subscription. The restriction check was exercised with Standard_D1, which carries the same NotAvailableForSubscription restriction type.
  • The plan now needs read access to Microsoft.Compute/skus and adds a few seconds for the lookup.

- Add the azapi provider to look up the requested VM size in the
  Microsoft.Compute/skus API, which azurerm has no data source for.
- Fail at plan time with a clear message when the size is not offered
  in the region, is restricted for the subscription
  (NotAvailableForSubscription, common on Azure for Students), or is
  Arm64 (the lab uses an x64 Ubuntu image).
- Raise the bootstrap dpkg lock timeout from 120s to 300s to match the
  AWS and GCP bootstraps.
- Document the plan-time messages, x64 size options, Azure for Students
  region policy and credit errors, and the "resource group already
  exists" error in TROUBLESHOOTING.md.
- Replace the README's external Spot-instance workaround link with the
  in-repo Azure for Students section.

Refs #99

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Missing SKU architecture metadata is mishandled, and several troubleshooting commands may inspect or delete resources in the wrong subscription.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
What changed in this PR

Adds Azure VM SKU preflight validation and improves deployment troubleshooting.

Changes:

  • Queries SKU availability and architecture using AzAPI.
  • Extends apt lock timeouts.
  • Expands Azure troubleshooting guidance.
File Description
azure/​main.tf Adds SKU checks and timeout updates.
azure/​README.md Links Azure Students guidance.
TROUBLESHOOTING.md Documents Azure deployment failures.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread azure/main.tf Outdated
Comment thread TROUBLESHOOTING.md

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The implementation and documentation are consistent, validated, and have no unresolved issues.

Review effort: Balanced
Findings: None

Resolved since last review (2)

@rishabkumar7
rishabkumar7 merged commit b8042f1 into main Oct 1, 2026
4 checks passed
@rishabkumar7
rishabkumar7 deleted the fix/azure-deploy-resilience branch October 1, 2026 20:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Research Terraform resilience for Azure: region, VM size, and subscription restrictions

2 participants