platform-break-glass
Type: regulative
Decision
Break-glass must be used only where automation cannot execute the change.
Why
An unrestricted role with no usage boundary becomes the fast path, and the repository stops being the record.
Violations
- Break-glass used for a change a pull request could have made.
Anchor
no-human-touch
Implements
Files
- platform-management/access-control/parameters/accessControl.bicepparam
- platform-management/access-control/bicep/accessControl.bicep
- .github/workflows/template-landing-zones.yml
Links
- deployment-declarative-lifecycle (depends-on) — Stack deny assignments override role actions, so break-glass reaches platform resources by being excluded from them.
- guardrail (depends-on) — Policy denies apply regardless of role actions, so break-glass cannot deploy an unapproved resource type.
← Back to knowledge graph