landing-zone-allowed-public-ip
Type: regulative
Decision
Data-plane access from outside Azure must originate from the platform-trusted public IP.
Why
Without a trusted source address, application teams cannot reach Azure data-plane resources from their laptops.
Violations
- Platform configuring PaaS firewall rules on behalf of the application team.
- IP address hardcoded in an application pipeline instead of read from the platform variable.
Anchor
no-platform-ops
Implements
Files
Links
← Back to knowledge graph