Skip to content

Evaluate FinOps hubs alignment with CAF/WAF guardrails #2313

Description

🤖 [AI] Filed from findings raised in discussion #2283.

⚠️ Problem

We've fixed individual CAF/landing-zone policy conflicts reactively as they're reported (Key Vault RBAC — #1067/#2249; storage shared-key access — see companion issue filed alongside this one). There's likely a broader set of CAF/WAF (Cloud Adoption Framework / Well-Architected Framework) guardrails and built-in Azure Policies the hub templates don't yet account for.

🛠️ Solution

Do a systematic pass evaluating FinOps hub templates against common CAF landing-zone policies and WAF pillars, and file targeted issues for any additional gaps found, rather than continuing to fix these one at a time as customers hit them.

ℹ️ Additional context

Prompted by discussion #2283 and the pattern seen across #1067 and the storage-key issue — both are "policy X blocks deployment" reports.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions