# Governance Constraints - static-webapp-test

> This document captures the governance constraints and Azure Policy requirements that must be addressed in the Bicep implementation.

- Skill: `tools-only/governance-constraints-static-webapp-test` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add tools-only/governance-constraints-static-webapp-test`
- Raw SKILL.md: https://api.skillmd.com/api/skills/tools-only/governance-constraints-static-webapp-test/raw
- Safety review: pending (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: tools-only (https://skillmd.com/u/tools-only)
- Updated: 2026-09-29
- Page: https://skillmd.com/skills/tools-only/governance-constraints-static-webapp-test

---

# Governance Constraints - static-webapp-test

> Generated by bicep-plan agent | 2024-12-17

This document captures the governance constraints and Azure Policy requirements
that must be addressed in the Bicep implementation.

## Discovery Source

| Query              | Results                       | Timestamp           |
| ------------------ | ----------------------------- | ------------------- |
| Policy Assignments | Legacy - not formally queried | 2024-12-17 (approx) |
| Tag Policies       | Legacy - not formally queried | 2024-12-17 (approx) |

> **Note**: This artifact predates formal Azure Resource Graph discovery requirements.
> Constraints below were documented based on best practices, not live ARG queries.

## Azure Policy Compliance

| Category       | Constraint                       | Implementation                          |
| -------------- | -------------------------------- | --------------------------------------- |
| Naming         | CAF naming convention            | Use standard prefixes                   |
| Tagging        | Required tags on all resources   | Include Environment, ManagedBy, etc.    |
| Security       | SQL Azure AD-only auth           | Must use Azure AD auth, no SQL auth     |
| Data Residency | Allowed locations: swedencentral | Set location parameter to swedencentral |

## Required Tags

All resources must include the following tags:

```bicep
tags: {
  Environment: environment  // dev, staging, prod
  Project: projectName      // static-webapp-test
  ManagedBy: 'Bicep'
  Owner: 'DevOps Team'
}
```

## Security Policies

| Policy           | Requirement                        |
| ---------------- | ---------------------------------- |
| HTTPS Only       | Required - SWA enforces by default |
| TLS Version      | Minimum TLS 1.2                    |
| Public Access    | Acceptable (no blocking policy)    |
| Managed Identity | Preferred for SQL connectivity     |
| Key Vault        | Not required (no secrets in scope) |

## Cost Policies

| Policy            | Constraint            |
| ----------------- | --------------------- |
| Budget            | $50/month             |
| SKU Restrictions  | Free/Basic tiers only |
| Reserved Capacity | Not applicable        |

## Network Policies

| Policy            | Constraint                      |
| ----------------- | ------------------------------- |
| Private Endpoints | Not required (cost prohibitive) |
| VNet Integration  | Not required                    |
| Public Endpoints  | Allowed for internal tool       |

---

_Governance constraints extracted from requirements and architecture assessment._

