Read blocked requests in KQL, qualify false positives and apply targeted rules with evidence.
Cloud · Infrastructure · Automation · AI
Operational knowledge for technical systems.
Naxaya turns architecture choices, failure modes, implementation patterns and runbook-level checks into practical technical notes for teams that need systems to stay explainable after deployment.
DNS, Private Endpoint, Application Gateway and validation matrices.
Automation guardrails, restore checks, identity troubleshooting and handover notes.
Symptom: A private AI agent can act but nobody can explain the action. First checks: List approved sources · Trace tool calls.
01
Architecture that can be operated
Design choices are written with their constraints, validation commands, failure modes and return paths.
02
Automation with guardrails
AWX, Ansible and scripts are treated as operational interfaces, not just convenient execution buttons.
03
Private AI with controls
Agent workflows stay grounded in approved sources, scoped identities, observable actions and human validation.
Focused series
Operational paths, grouped by problem.
Each series follows a concrete path from the initial symptom or design choice to validation, guardrails and production-ready runbooks.
Latest articles
Azure Storage: diagnose a private endpoint without opening the account
An operational runbook for Azure Storage private access failures by separating DNS, Private Endpoint, firewall, identity, logs and rollback evidence.
Read articleKQL snippet: isolate Azure Storage 403 on a private endpoint
A short query to separate identity, firewall, public endpoint and wrong subresource when private Azure Storage access is denied.
Read articleAzure App Service: diagnose a private endpoint before redeploying
Build an operational runbook for App Service private access failures by separating DNS, Private Endpoint, access restrictions, Application Gateway, application logs and rollback evidence.
Read articleKQL snippet: correlate private App Service and Application Gateway
A short query to separate WAF, gateway, private DNS, access restrictions and App Service logs during a private access incident.
Read article