allowed-resources
Type: constitutive
Rule
An Azure resource counts as approved in Gazelle when the allowed-resources list names it.
Violations
- Resource deployed because nothing denied it rather than because the allowed-resources list names it.
- Resource treated as approved because it already exists in the estate.
Anchor
no-unapproved-resources
Links
- guardrail (depends-on) — The list confers approval only as the roll of the Allowed Resources guardrail, so it names nothing until the platform assigns that guardrail.
← Back to knowledge graph