landing-zone-automation
Type: regulative
Decision
Automation jobs must run inside the landing zone's own subscription.
Why
Without isolation, all landing zones would share a runtime the platform has no subscription to host.
Violations
- Automation job running from a resource outside the landing zone subscription.
Anchor
no-fixed-cost
Implements
Files
- landing-zones/bicep/modules/landingzone-automation.bicep
- landing-zones/bicep/modules/base/jobs-cron.bicep
- landing-zones/bicep/modules/base/managedEnvironments.bicep
Links
- platform-identity-graph (depends-on) — Jobs query Entra ID, so the Graph read permissions are what make that call possible.
← Back to knowledge graph