# Operations ## Prerequisites Install Azure CLI and authenticate to the desired tenant before launching the TUI. The application reads the tenant from `az account show`, filters subscriptions to that tenant and to the `Enabled` state, and explicitly passes each subscription to Azure CLI. It never runs `az account set`. Network routing, DNS, private-endpoint connectivity and firewall access remain environmental prerequisites. A discovered server may still reject a PostgreSQL connection. ## Profiles Profiles live in the platform application configuration directory as `profiles.json`. The file contains no password. On macOS and Windows the TUI can reference a system-keychain secret; otherwise a password is session-only. An unsupported future profile-file format is rejected without overwriting it. ## Dependency lock `Cargo.lock` is part of the source of truth. Use locked Cargo commands. If the manifest changes, regenerate the lockfile through the controlled maintainer dependency-resolution process before running CI or release jobs. CI does not repair or regenerate a lockfile.