Skip to content

Commit 71cf0c1

Browse files
Hou Chi ChanCopilot
andcommitted
docs: refresh architecture diagram and clarify onboarding prerequisites
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
1 parent 5fc4f0a commit 71cf0c1

4 files changed

Lines changed: 48 additions & 4 deletions

File tree

‎README.md‎

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -25,9 +25,17 @@ The single-region request flow is:
2525
2. App Service Authentication (Easy Auth) validates the caller before the Function runs.
2626
3. The Function decrypts the request using a key stored in Azure Key Vault.
2727
4. The selected provider adapter authenticates to the phone provider and submits the SMS or voice message.
28-
5. The Function returns a success response after provider acceptance. Confirming delivery to the
28+
5. For a live request, the Function returns a success response after provider acceptance. Confirming delivery to the
2929
recipient is a separate validation step.
3030

31+
The diagram's delivery path describes **live requests**. An authorized, valid encrypted
32+
**evaluation request (`mode: 2`)** returns the matching nonce without submitting a message to the
33+
provider. Background credential refresh can still run independently. Authentication failures may
34+
return **401 or 403**; neither is a successful evaluation.
35+
36+
**East US in the diagram is illustrative, not a required or guaranteed deployment location.**
37+
Choose a region with available Linux Premium EP1 capacity and sufficient quota in your subscription.
38+
3139
Application Insights provides operational telemetry. Provider API keys stay in Key Vault; supported
3240
OAuth integrations use managed identity. This guide covers only the single-region topology shown
3341
above. Multi-region deployment, failover, and resiliency guidance are deferred.
@@ -44,15 +52,17 @@ Use a **dedicated nonproduction tenant and subscription** for your first deploym
4452
| Azure permissions | An Azure user account permitted to deploy at subscription scope, register required resource providers, and create scoped role assignments. |
4553
| Microsoft Entra permissions | A Privileged Role Administrator for the application and Microsoft Graph configuration. Setup uses the allowed-tenants preview and requires Microsoft Graph beta access. |
4654
| Policy activation | An Authentication Policy Administrator to activate the endpoint after validation. Deployment alone does not activate it. |
47-
| Region and hosting | A region supporting Linux Premium EP1. Deployed resources incur Azure charges; review the hosting plan before approval. |
55+
| Region and hosting | A region supporting Linux Premium EP1 with sufficient EP1 quota for your subscription. Resource-provider registration does not grant quota. Deployed resources incur Azure charges; review the hosting plan before approval. |
4856
| C# only | The .NET 8 SDK and NuGet access. Setup builds and publishes the selected .NET package automatically. |
4957

5058
Setup can install missing Microsoft Graph PowerShell modules and the Azure CLI Bicep component
5159
after confirmation. Azure CLI itself must already be installed. JavaScript and Python do not
5260
require a local build toolchain for this guided deployment; Python dependencies are built in Azure.
5361

5462
Review the complete [setup prerequisites](setup/docs/README.md#prerequisites-for-step-2) before
55-
deploying.
63+
deploying. If Azure reports `SubscriptionIsOverQuotaForSku`, follow the
64+
[regional quota troubleshooting steps](setup/docs/Troubleshooting.md#deployment-fails-with-subscriptionisoverquotaforsku)
65+
before retrying.
5666

5767
## Onboard your endpoint
5868

3.37 KB
Loading

‎setup/docs/README.md‎

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,11 @@ PowerShell script to deploy the endpoint, and activate policy manually after val
66
The customer does not clone this repository or download Bicep/support scripts separately.
77
`Setup-Epp.ps1` retrieves those files and the selected provider's JSON from GitHub.
88

9+
This guide deploys **one Function endpoint in one Azure region**. It does not provision Azure
10+
Front Door or a second region. A successful single-region deployment or encrypted evaluation
11+
does not establish cross-region failover or recovery; Front Door onboarding is deferred until
12+
that validation is complete.
13+
914
## Availability
1015

1116
Choose **SMS or voice**, a **Global or EU tenant scope**, **Telesign or Soprano**, and an
@@ -71,7 +76,11 @@ disclosed outbound managed-identity federated credential.
7176
principal or the endpoint app.
7277
- Microsoft Graph **beta** access for the Entra `signInAudienceRestrictions` allowed-tenants preview.
7378
The selected provider tenant is allowed in addition to the app's home tenant, which Entra always allows.
74-
- **Linux Premium EP1** available in the chosen region. Setup registers missing required Azure
79+
- **Linux Premium EP1** available in the chosen region, with sufficient subscription quota for the
80+
deployment. Regional service availability and resource-provider registration do not guarantee
81+
EP1 quota. If deployment reports `SubscriptionIsOverQuotaForSku`, resolve the
82+
[regional quota issue](Troubleshooting.md#deployment-fails-with-subscriptionisoverquotaforsku)
83+
before retrying. Setup registers missing required Azure
7584
resource providers automatically after the single approval. The Azure account needs the
7685
providers' subscription-scoped `/register/action` permission (included in Contributor/Owner).
7786
- **.NET selection only:** install the .NET 8 SDK and allow NuGet access. Setup runs `dotnet publish`

‎setup/docs/Troubleshooting.md‎

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,30 @@
11
# Troubleshooting Step 2
22

3+
## Deployment fails with SubscriptionIsOverQuotaForSku
4+
5+
This is a subscription quota check, not an authentication failure or a missing resource-provider
6+
registration. A region can support Linux Premium EP1 while your subscription has an **EP1 VMs**
7+
limit of zero there. Quotas are regional: an allowance in one region does not establish an
8+
allowance in another.
9+
10+
1. Confirm the tenant, subscription, region, and SKU in the deployment plan and Azure error.
11+
2. In the Azure portal, open **Quotas**, select **App Service**, and filter to the intended
12+
subscription and region. Review **EP1 VMs**, its current usage, and the requested deployment's
13+
requirements. This is an App Service quota, not a general-purpose Compute VM quota.
14+
3. Request an increase sufficient for the deployment and any planned scaling. Requesting an
15+
increase does not mean it is approved; verify the effective limit after approval.
16+
4. If the quota is not adjustable in the portal or the request is rejected, create an Azure
17+
support request under **Service and subscription limits (quotas)** for
18+
**Function or Web App (Windows and Linux)**. Include the region, Linux deployment type, EP1
19+
SKU, current limit, requested limit, and the error's tracking ID.
20+
5. Alternatively, choose another region only after checking its quota, service availability,
21+
and your residency and provider requirements. Review the updated deployment plan before approval.
22+
23+
See the [Azure quotas overview](https://learn.microsoft.com/azure/quotas/quotas-overview) for the
24+
quota-management and support options. Setup does not request or guarantee a quota increase.
25+
Do not change the hosting SKU, disable Easy Auth, or change provider credentials to bypass this
26+
error. After resolving quota, rerun setup and complete the normal deployed validation checks.
27+
328
## appservice list-locations rejects EP1
429

530
`EP1` is an Azure Functions Elastic Premium plan SKU, but older Azure CLI versions do not accept

0 commit comments

Comments
 (0)