landing-zone-tags
Type: regulative
Decision
Tag values on a landing zone must be sourced from the platform member profile.
Why
Hand-typed tags drift from the member profile, so a resource stops showing who actually owns it.
Violations
- Tag introduced that does not apply to all application landing zones.
- ownerEmail or engineerEmail hardcoded instead of read from the profile.
Anchor
no-platform-ops
Implements
Files
- landing-zones/bicep/modules/azurePolicy.bicep
- landing-zones/managementGroup-AppName-environment.bicepparam
Links
← Back to knowledge graph