From “it’s down” to a defensible incident record.
A provider-neutral field guide and five editable templates for cloud technicians who need to collect evidence, test competing hypotheses and hand off cleanly before anyone guesses in production.
Mail app not opening? Email yohajack@gmail.com.
Manual launch checkout: request a PayPal invoice or Canadian e-Transfer instructions. The download is emailed after payment clears. Taxes, if applicable, are confirmed before payment.
“The site is down. We changed something yesterday.”
- Impact
- Unknown
- Last known good
- Unknown
- Evidence
- Screenshot only
- Rollback
- Not defined
Certificate mismatch isolated from origin health.
DNSExpected CNAME differs from public answer
TLSCertificate SAN excludes requested hostname
HTTPOrigin returns 200 through verified host header
DECISIONEscalate DNS ownership; do not restart origin
The first 30 minutes become a sequence, not a scramble.
The kit does not prescribe one magic command. It gives every observation a place and forces the next change to earn its risk.
- Frame the incident
Define impact, scope, ownership and the last known good state.
- Capture read-only evidence
Record timestamps, exact errors, paths, versions and external observations.
- Compete hypotheses
Write what would support or falsify each cause before locking onto one.
- Gate the change
Name authorization, expected signal, blast radius and rollback trigger.
- Resolve or hand off
Leave a concise record another technician can continue immediately.
One field guide. Five files you can actually edit.
The PDF explains the operating method. The Markdown and CSV files make it usable in a real ticket, shared document or spreadsheet without proprietary software.
- PDF / 24 pagesCloud Incident Triage Field GuideDNS, TLS, HTTP, VMs, performance, email and escalation
- MD / editableIncident IntakeImpact, authorization, timeline anchor and affected surface
- CSV / editableIncident TimelineTimestamped observations, actions, results and owners
- CSV / editableHypothesis BoardSupport, contradiction, falsification test and confidence
- MD / editableSafe-Change ChecklistApproval, blast radius, expected signal and rollback
- MD / editableHandoff ReportWhat happened, what was ruled out and who owns the next action
Built for operators, not outage spectators.
- Junior cloud and systems administrators
- MSP and service-desk technicians
- Independent technical consultants
- Small SaaS teams without a dedicated incident manager
What this is not
It is not a command dump, automated remediation system or promise to recover every outage. It does not replace security incident response, digital forensics, provider-specific support, backups, authorization or change control.
Single-user / single-team use is included. Redistribution of the blank bundle is not.
Ready now. Fulfilled manually while the storefront opens.
Send the purchase request, choose PayPal or e-Transfer, receive written payment instructions and get the ZIP bundle by email after payment clears.
Before you buy
Is this tied to AWS, Azure, GCP or OVHcloud?
No. The workflow is deliberately provider-neutral. It focuses on evidence, decisions, safe changes and handoff quality across providers.
Can I edit the templates?
Yes. The bundle includes Markdown and CSV files that work in common text editors, spreadsheets and documentation tools.
Does it include scripts or credentials?
No. There are no credentials or production automation scripts. The method emphasizes read-only evidence, least privilege, rollback and escalation.
Can I use it with clients?
Yes, for your own work or within one team. You may not resell or redistribute the blank bundle.
Why is checkout by email?
This is a manual launch while a dedicated storefront is being prepared. You receive the exact amount and payment method in writing before paying, then the bundle is delivered to the same email address.