Governance Constraints - static-webapp-test
Generated by bicep-plan agent | 2024-12-17
This document captures the governance constraints and Azure Policy requirements that must be addressed in the Bicep implementation.
Discovery Source
| Query | Results | Timestamp |
|---|---|---|
| Policy Assignments | Legacy - not formally queried | 2024-12-17 (approx) |
| Tag Policies | Legacy - not formally queried | 2024-12-17 (approx) |
Note: This artifact predates formal Azure Resource Graph discovery requirements. Constraints below were documented based on best practices, not live ARG queries.
Azure Policy Compliance
| Category | Constraint | Implementation |
|---|---|---|
| Naming | CAF naming convention | Use standard prefixes |
| Tagging | Required tags on all resources | Include Environment, ManagedBy, etc. |
| Security | SQL Azure AD-only auth | Must use Azure AD auth, no SQL auth |
| Data Residency | Allowed locations: swedencentral | Set location parameter to swedencentral |
Required Tags
All resources must include the following tags:
tags: {
Environment: environment // dev, staging, prod
Project: projectName // static-webapp-test
ManagedBy: 'Bicep'
Owner: 'DevOps Team'
}
Security Policies
| Policy | Requirement |
|---|---|
| HTTPS Only | Required - SWA enforces by default |
| TLS Version | Minimum TLS 1.2 |
| Public Access | Acceptable (no blocking policy) |
| Managed Identity | Preferred for SQL connectivity |
| Key Vault | Not required (no secrets in scope) |
Cost Policies
| Policy | Constraint |
|---|---|
| Budget | $50/month |
| SKU Restrictions | Free/Basic tiers only |
| Reserved Capacity | Not applicable |
Network Policies
| Policy | Constraint |
|---|---|
| Private Endpoints | Not required (cost prohibitive) |
| VNet Integration | Not required |
| Public Endpoints | Allowed for internal tool |
Governance constraints extracted from requirements and architecture assessment.