Q: Your Azure DevOps pipeline is green, but the application is down after deployment. How would you troubleshoot it?
Root cause isolation and troubleshooting procedure when an Azure DevOps CI/CD pipeline reports successful stage execution, but the deployed web application or API returns HTTP 500 or 503.
🛠️ Production Runbook & Step-by-Step Resolution
Stream Azure App Service / Container Live Logs
Connect to the application container via Azure CLI or Kudu console to capture runtime crash logs that occurred after the pipeline detached.
az webapp log tail --name app-production-eus --resource-group rg-production-app
# For containerized apps:
az webapp log download --name app-production-eus --resource-group rg-production-app
Validate Key Vault References & App Settings
Check if App Service App Settings contain invalid Key Vault references (@Microsoft.KeyVault(...)). If the App Service Managed Identity lacks Get permissions or Key Vault networking blocks the App Service outbound IP, the app fails on boot.
Implement Pipeline Post-Deployment Health Probes
Update the azure-pipelines.yml with a post-deployment verification task using curl or PowerShell Invoke-RestMethod that validates the live health endpoint before marking the job green.
- task: AzureCLI@2
inputs:
scriptType: 'bash'
scriptLocation: 'inlineScript'
inlineScript: |
STATUS=$(curl -s -o /dev/null -w "%{http_code}" https://$(webAppName).azurewebsites.net/healthz)
if [ "$STATUS" -ne 200 ]; then
echo "Health check failed with HTTP $STATUS"
exit 1
fi
- Stream real-time runtime logs via az webapp log tail to view application boot crashes.
- Verify Azure Key Vault references (@Microsoft.KeyVault) and App Service Managed Identity permissions.
- Check port binding: ensure WEBSITES_PORT matches the container exposed port.
- Add automated post-deployment health check tasks in azure-pipelines.yml to fail the pipeline on HTTP 5xx.