Skip to content

Rework 29 Environment Validator TSGs with TSG Forge - #353

Draft
John Neemes (1008covingtonlane) wants to merge 7 commits into
Azure:mainfrom
1008covingtonlane:tsg-envval-batch-tier1
Draft

John Neemes (1008covingtonlane) wants to merge 7 commits into
Azure:mainfrom
1008covingtonlane:tsg-envval-batch-tier1

Conversation

@1008covingtonlane

@1008covingtonlane John Neemes (1008covingtonlane) commented Sep 17, 2026

Copy link
Copy Markdown
Collaborator

Summary

Reworks the 29 root-level TSG/EnvironmentValidator articles through a structured TSG quality workflow.

  • Adds consistent troubleshooting structure, safety gates, verification, escalation boundaries, and administrator-facing evidence.
  • Adds required publication metadata and publication layout.
  • Raises every final article to lint A, a 5/5 usability panel across 13 personas, and 8/8 administrator-surface coverage.
  • Records honest validation depth, including live loops, faithful proxy tests, and read-only validation where a destructive inject was not safe.
  • Incorporates independently adjudicated automated-review findings and removes internal project, lab, and source-system references from public content.

Scope

This PR covers the 29 articles at the root of TSG/EnvironmentValidator.
The Networking/ and SLB/ subdirectories are not part of this PR.

Validation

  • 29 of 29 final articles pass the publication contract with unique Article IDs.
  • All 237 PowerShell fences in the modified public articles parse successfully.
  • All 29 spec-bound static lints are Grade A.
  • 29 full original BEFORE cards and 29 refreshed AFTER cards were generated.
  • Eight bot-remediated articles received focused September 18, 2026 revalidation at their permitted fidelity.
  • Public-content scans found no internal project names, lab identifiers, internal URLs, or PII.
  • No retained reservation was released, and no deployed cluster member was mutated.

Evidence

The evidence comment links all 29 scrubbed BEFORE and AFTER cards and includes the per-TSG improvement table.

PG review routing

Primary product group: Environment Validator

Reviewer requested: erskinejohn (John Erskine), who has contributed directly to Environment Validator TSGs in this repository.

Apply the highest-leverage BEFORE-panel work items to six EnvironmentValidator
TSGs: System Drive Free Space, ASR Rule GP Conflict, SBE Installed Env Vars,
SBE Endpoint Connectivity, SBE Model/SKU, and SBE Version Supports OperationType.

The batch adds safer drain and evidence handling, correct result-field and
RSoP guidance, cross-node collection, ownership and escalation boundaries,
component-log and non-evident surface coverage, accurate SUCCESS-only semantics,
worked model/SKU examples, and release-safe version guidance.

Validation completed on six separate reserved masonenodes:

  - six live PASS loops, with cleanup/residue checks
  - six AFTER panels, all 13 personas at 5/5
  - six AFTER lint grades A
  - admin discoverability 18/48 -> 48/48
  - persona mean 3.40 -> 5.00
  - zero metric regressions

Full BEFORE/AFTER cards and structured deltas remain in the session campaign
artifacts under /Users/joneemes/Desktop/PR327/campaign-state/.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 2e86358a-9cca-442e-ab63-590b8ea3e4ec
Apply TSG Forge validation findings, safety gates, discoverability guidance, and verified remediation updates across the first two six-article chunks.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: d48285da-dafe-48c3-8590-c6dd9f438064
Apply TSG Forge findings, live validation evidence, safety gates, product-movement boundaries, and complete administrator guidance across the capacity-sized six-article wave.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: d48285da-dafe-48c3-8590-c6dd9f438064
Add PickleFactory-compliant metadata and layouts, preserve full diagnostics, and record Grade A validation for WMI, administrative privileges, SecureBootStatus, PhysicalDisk, WDAC, and AllResults.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: d48285da-dafe-48c3-8590-c6dd9f438064
Retrofit the first 18 EnvironmentValidator articles with authoritative YAML metadata, audience scoping, revision history, and template layouts while preserving validated command blocks and technical content.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: d48285da-dafe-48c3-8590-c6dd9f438064
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: d48285da-dafe-48c3-8590-c6dd9f438064
@1008covingtonlane

John Neemes (1008covingtonlane) commented Sep 17, 2026

Copy link
Copy Markdown
Collaborator Author

TSG quality evidence, refreshed September 18, 2026

The AFTER cards include a dated post-review addendum.

Additional non-inline review fix: the Hardware Secure Boot fallback now matches only the canonical and verified legacy result names and fails closed when neither result is returned. Public copies contain no internal project names, lab identifiers, local paths, internal URLs, email addresses, or non-documentation IP addresses.

TSG Forge improvement summary

NOTE: this grade did not include validating the TSG on a live cluster.

Validation-level key

  • L0: Static document checks and persona review only; no live cluster execution.
  • L1: Diagnostic commands were run read-only on a live cluster and returned the documented shape.
  • L2: The real detector or classifier was exercised with a safe reversible proxy or faithful data-source injection.
  • L3: The real failure mode and remediation were exercised on an isolated scratch object.
  • L4: Full live loop: baseline pass, genuine failure injection, detection, documented mitigation, revalidation pass, and cleanup.
TSG Overall grade Lint Validation depth Persona score Admin surfaces Problem shown in
Known-Issue-AllResults-property-error-during-Pre-Update-Health-Check B to A B to A static to L1 read-only 2/5 to 5/5 (+3) 2/8 to 8/8 (+6) PowerShell, Portal, Event logs, Component logs
Known-Issue-High-Disk-Space-usage-in-TEMP B to A B to A static to L1 read-only 1.4/5 to 5/5 (+3.6) 1/8 to 8/8 (+7) PowerShell, Event logs, WAC, WAC in portal, Component logs
Known-Issue-SAN-LUN-Visibility-Failure B to A B to A static to L1 read-only 2.1/5 to 5/5 (+2.9) 2/8 to 8/8 (+6) PowerShell, Portal, Event logs, Component logs
Known-Issue-Test-Cluster-Access-Denied-WMI-Error B to A B to A static to live loop 2.5/5 to 5/5 (+2.5) 2/8 to 8/8 (+6) PowerShell, Portal, Event logs, Component logs
Known-Issue-Test-Cluster-Administrative-Privileges-Failure B to A B to A static to L1 loop 2.6/5 to 5/5 (+2.4) n/a/8 to 8/8 PowerShell, Portal, Event logs, Component logs
Known-Issue-Test-WdacEnablement-Null-Reference B to A B to A static to L2 loop 2.7/5 to 5/5 (+2.3) 1/8 to 8/8 (+7) PowerShell, Portal, Event logs, Component logs
Known-Issue-This-module-requires-Az-Accounts-version-5-3-0 B to A B to A static to L4 loop 1.7/5 to 5/5 (+3.3) 1/8 to 8/8 (+7) PowerShell, Portal, Component logs
Known-Issue-WinRM-cannot-process-the-configuration-request B to A B to A static to L2 loop 1.5/5 to 5/5 (+3.5) 1/8 to 8/8 (+7) PowerShell, Portal, Event logs, Component logs
Troubleshooting-AzStackHci_ARBStack_ARBIsLocked B to A B to A static to L1 read-only 2.8/5 to 5/5 (+2.2) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-AzStackHci_Security_AsrRuleGPConflict B to A B to A static to L4 loop 2.8/5 to 5/5 (+2.2) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-AzStackHci_Security_SecureBootStatus B to A B to A static to L2 read-only 2.5/5 to 5/5 (+2.5) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-Connectivity-Test-Dns B to A B to A static to L2 loop 3.5/5 to 5/5 (+1.5) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-DNS-ActiveDirectory-DomainName-Resolution B to A B to A static to L4 loop 3.5/5 to 5/5 (+1.5) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-DNS-External-DNS-Resolution B to A B to A static to L4 loop 3.6/5 to 5/5 (+1.4) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-External-Connectivity-Failures-in-Environment-Checker B to A B to A L1 read-only to L2 loop 2.8/5 to 5/5 (+2.2) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-Hardware-Test-Secure-Boot B to A B to A static to L4 loop 3.5/5 to 5/5 (+1.5) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-Hardware-Test-Tpm-Version B to n/a B to A static to L1 read-only 3.6/5 to 5/5 (+1.4) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-MSI-Does-Not-Have-Access-To-Subscription B to A B to A static to L1 loop 1.5/5 to 5/5 (+3.5) 2/8 to 8/8 (+6) PowerShell, Portal, Event logs, Component logs
Troubleshooting-Module-Versions B to A B to A static to L1 read-only 1.3/5 to 5/5 (+3.7) 1/8 to 8/8 (+7) PowerShell, Component logs
Troubleshooting-SBEHealth-Test-Endpoint-Connectivity B to A B to A static to live loop 2.92/5 to 5/5 (+2.08) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Cluster logs, Failover Cluster Manager, WAC, WAC in portal, Component logs
Troubleshooting-SBEHealth-Test-Endpoint-Matches-ModelSKU B to A B to A static to live loop 3.5/5 to 5/5 (+1.5) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-SBEHealth-Test-Installed-SBE-Env-Vars B to A B to A static to L2 loop 3.6/5 to 5/5 (+1.4) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-SBEHealth-Test-SolutionExtensionModule B to A B to A static to live loop 3.2/5 to 5/5 (+1.8) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-SBEHealth-Test-Version-Supports-OperationType-Tests B to A B to A static to live loop 3.8/5 to 5/5 (+1.2) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-Software-IsNotPartofDomain B to A B to A static to live loop 3.1/5 to 5/5 (+1.9) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Failover Cluster Manager, WAC, WAC in portal, Component logs
Troubleshooting-Test-NetAdapter-API B to A B to A static to L2 loop 1.5/5 to 5/5 (+3.5) 1/8 to 8/8 (+7) PowerShell, Portal, Event logs, Component logs
Troubleshooting-Test-PhysicalDisk-API B to A B to A L1 read-only to L2 loop 1.8/5 to 5/5 (+3.2) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Component logs
Troubleshooting-Test-PowerShell-Module-Version B to A B to A static to L4 loop 2.1/5 to 5/5 (+2.9) 1/8 to 8/8 (+7) PowerShell, Portal, Event logs, Failover Cluster Manager, WAC, WAC in portal, Component logs
Troubleshooting-Test-SystemDrive-Free-Space B to A B to A static to live loop 3.6/5 to 5/5 (+1.4) 3/8 to 8/8 (+5) PowerShell, Portal, Event logs, Cluster logs, Component logs

Grade convention: BEFORE uses the measured document grade. AFTER uses the final overall technical grade. Validation depth is reported separately.

Campaign totals: 29 TSGs; every final article passes the publication contract, has lint A, has a 5/5 panel across all 13 personas, and addresses 8/8 admin surfaces.

The evidence attachments contain scrubbed full BEFORE and AFTER cards. Original internal lab evidence remains in the campaign workspace.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved critical and moderate findings remain in metadata, safety, authorization, and validation procedures.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Reworks 29 root-level Environment Validator TSGs into the TSG Forge publication format with standardized metadata, diagnostics, safety gates, evidence, remediation, and escalation guidance.

Changes:

  • Adds consistent article metadata, structure, and revision history.
  • Expands administrator-facing diagnostics, validation, and evidence procedures.
  • Adds safer remediation, rollback, ownership, and escalation boundaries.
File summaries
File Reviewed change and final review note
TSG/EnvironmentValidator/Troubleshooting-Test-SystemDrive-Free-Space.md Adds cleanup and evidence-preservation guidance. Critical: add the required schema marker; moderate: compare source and destination hashes before deletion.
TSG/EnvironmentValidator/Troubleshooting-Test-PowerShell-Module-Version.md Adds current-recipe module diagnosis and remediation.
TSG/EnvironmentValidator/Troubleshooting-Software-IsNotPartofDomain.md Adds domain-unjoin safety gates. Critical: require an approved credential or an owner-approved RID-500 enable/reset branch.
TSG/EnvironmentValidator/Troubleshooting-SBEHealth-Test-Version-Supports-OperationType-Tests.md Clarifies SBE version and coverage behavior.
TSG/EnvironmentValidator/Troubleshooting-SBEHealth-Test-SolutionExtensionModule.md Adds staged-package integrity troubleshooting.
TSG/EnvironmentValidator/Troubleshooting-SBEHealth-Test-Endpoint-Matches-ModelSKU.md Adds endpoint and hardware matching guidance.
TSG/EnvironmentValidator/Troubleshooting-MSI-Does-Not-Have-Access-To-Subscription.md Adds module and RBAC diagnosis. Critical: make role creation conditional on the corresponding missing-role result.
TSG/EnvironmentValidator/Troubleshooting-Hardware-Test-Tpm-Version.md Adds TPM and BitLocker safety procedures. Critical: verify recovery protectors for every protected volume before firmware changes.
TSG/EnvironmentValidator/Troubleshooting-Hardware-Test-Secure-Boot.md Adds Secure Boot and cluster-drain procedures. Moderate: match the documented underscore-delimited result name in fallback lookup.
TSG/EnvironmentValidator/Troubleshooting-AzStackHci_Security_AsrRuleGPConflict.md Adds RSoP and Group Policy remediation guidance.
TSG/EnvironmentValidator/Troubleshooting-AzStackHci_ARBStack_ARBIsLocked.md Adds lock detection and removal guidance. Moderate: verify resource, resource-group, and subscription scopes before declaring clear.
TSG/EnvironmentValidator/Known-Issue-WinRM-cannot-process-the-configuration-request.md Adds scoped TrustedHosts detection and rollback. Critical: fail closed on RSoP errors and preserve policy ownership.
TSG/EnvironmentValidator/Known-Issue-Test-WdacEnablement-Null-Reference.md Documents fixed WDAC validator behavior.
TSG/EnvironmentValidator/Known-Issue-Test-Cluster-Access-Denied-WMI-Error.md Adds DNS and WMI validation procedures. Moderate: account for UDP 53 or use Resolve-DnsName results rather than TCP 53 alone.
Review details

Suppressed comments (1)

TSG/EnvironmentValidator/Troubleshooting-Hardware-Test-Secure-Boot.md:157

  • The documented result name is AzStackHci_Hardware_Test_Secure_Boot, but this fallback searches for SecureBoot without the underscore. On a module that lacks -Include, it returns no result even when the full validator reports the check, so the article cannot verify or troubleshoot the failure. Match the actual underscore-delimited name (while retaining compatibility with alternate spellings).
    Where-Object Name -like '*Hardware*SecureBoot*'
  • Files reviewed: 29/29 changed files
  • Comments generated: 8
  • Review effort level: Lite (auto)

Note

Copilot is running an experiment and ran this review at Lite.


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread TSG/EnvironmentValidator/Troubleshooting-Hardware-Test-Tpm-Version.md Outdated
Comment thread TSG/EnvironmentValidator/Troubleshooting-Software-IsNotPartofDomain.md Outdated
Comment thread TSG/EnvironmentValidator/Known-Issue-Test-Cluster-Access-Denied-WMI-Error.md Outdated
Comment thread TSG/EnvironmentValidator/Troubleshooting-AzStackHci_ARBStack_ARBIsLocked.md Outdated
Comment thread TSG/EnvironmentValidator/Troubleshooting-Test-SystemDrive-Free-Space.md Outdated
Harden the eight bot-identified procedures, add focused safety corrections found during revalidation, and remove internal project and lab references from public articles.\n\nCo-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>\nCopilot-Session: d48285da-dafe-48c3-8590-c6dd9f438064
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants