CLI runbook có kiểm soát
Một workflow an toàn là preflight → plan → create → verify → operate → cleanup → verify cleanup. Trước create, xác nhận identity, project, zone, billing và quota. Lệnh phải thể hiện target; không dựa vào default context hoặc copy nguyên command không hiểu.
Debug sau create
RUNNING chỉ nói VM process đang chạy. Hãy kiểm tra image, disk, network interface, service account, serial output và health endpoint. Startup script phải có log, không chứa secret và xử lý chạy lại an toàn. Nếu SSH fail, phân loại vấn đề: route/firewall/IAP, OS Login/IAM, instance boot hay application port.
Cleanup proof
Ghi resource IDs trước khi xóa. Xác định policy giữ hay xóa boot disk, attached disk, static IP, firewall rule và snapshot. Sau cleanup chạy list/describe lại, lưu evidence đã redacted và không xóa project production để “dọn nhanh”.
Bài tập
Viết command runbook tạo VM lab nhỏ, verify expected state, lấy serial output khi startup lỗi, SSH theo path an toàn và dọn toàn bộ dependency. Nếu không có billing-safe project, hoàn thành bằng design + read-only inspection.