landing-zone-identity
Type: regulative
Decision
A landing zone must have a single managed identity, shared across all its workflows, jobs, and service integrations.
Why
Without a single identity, every new capability multiplies the permission surface through RBAC and OIDC sprawl.
Violations
- Managed identity shared across multiple landing zones.
- Second identity introduced for a new capability.
Anchor
no-platform-ops
Implements
Files
- landing-zones/bicep/modules/identity.bicep
- landing-zones/bicep/modules/base/appRoleAssignedTo.bicep
Links
- landing-zone-repo (depends-on) — OIDC federation is scoped to the landing zone repo and environment.
← Back to knowledge graph