🔒 Step 4: Governance Constraints - Static Web Application
- 🔍 Discovery Source
- 📋 Azure Policy Compliance
- 🔄 Plan Adaptations Based on Policies
- 🚫 Deployment Blockers
- 🏷️ Required Tags
- 🔐 Security Policies
- 💰 Cost Policies
- 🌐 Network Policies
Generated by @bicep-plan agent | 2024-12-17
| ⬅️ Previous | 📑 Index | Next ➡️ |
|---|---|---|
| 03-des-cost-estimate.md | README | 04-implementation-plan.md |
This document captures the governance constraints and Azure Policy requirements that must be addressed in the Bicep implementation.
🔍 Discovery Source
| Query | Results | Timestamp |
|---|---|---|
| Policy Assignments | Legacy - not formally queried | 2024-12-17 (approx) |
| Tag Policies | Legacy - not formally queried | 2024-12-17 (approx) |
Note: This artifact predates formal Azure Resource Graph discovery requirements. Constraints below were documented based on best practices, not live ARG queries.
📋 Azure Policy Compliance
| Category | Constraint | Implementation |
|---|---|---|
| Naming | CAF naming convention | Use standard prefixes |
| Tagging | Required tags on all resources | Include Environment, ManagedBy, etc. |
| Security | SQL Azure AD-only auth | Must use Azure AD auth, no SQL auth |
| Data Residency | Allowed locations: swedencentral | Set location parameter to swedencentral |
🔄 Plan Adaptations Based on Policies
No policy-driven plan adaptations required. The static web app architecture complies with all discovered constraints.
🚫 Deployment Blockers
No deployment blockers detected. All governance constraints can be satisfied by the planned implementation.
🏷️ Required Tags
All resources must include the following tags:
tags: {
Environment: environment // dev, staging, prod
Project: projectName // static-webapp-test
ManagedBy: 'Bicep'
Owner: 'DevOps Team'
}
🔐 Security Policies
| Policy | Requirement |
|---|---|
| HTTPS Only | Required - SWA enforces by default |
| TLS Version | Minimum TLS 1.2 |
| Public Access | Acceptable (no blocking policy) |
| Managed Identity | Preferred for SQL connectivity |
| Key Vault | Not required (no secrets in scope) |
💰 Cost Policies
| Policy | Constraint |
|---|---|
| Budget | $50/month |
| SKU Restrictions | Free/Basic tiers only |
| Reserved Capacity | Not applicable |
🌐 Network Policies
| Policy | Constraint |
|---|---|
| Private Endpoints | Not required (cost prohibitive) |
| VNet Integration | Not required |
| Public Endpoints | Allowed for internal tool |
Governance constraints extracted from requirements and architecture assessment.
Generated by Azure Agentic InfraOps | GitHub