platform-break-glass
Type: decision
Decision
Break-glass is used only when automation cannot execute the change.
Why
An unrestricted role with no usage boundary becomes the fast path, and the repository stops being the record.
Violations
- Break-glass used for a change that a pull request could have made.
Links
- deployment-declarative-lifecycle — Stack deny assignments override role actions — break-glass reaches platform resources only if excluded from them.
- azure-policy-hard-deny — Policy denies apply regardless of role actions — break-glass cannot deploy an unapproved resource type.
← Back to knowledge graph