Enable customized Azure Management Groups
Jelle den Burger
Hey Sergej, thank you for your feature request.
I am not sure if I fully understand what it is you want to do within meshStack. Could you provide some more details to your idea?
Thanks :-)
S
Sergej Neumann
Hi Jelle den Burger, Azure Management Groups can be used as scope for Reserved Instances, Saving Plans and Pre-Purchase Plans. Adding subscriptions of your application to a Management Group allows you to share a RI across several subscriptions of your application.
Right now, the meshStack replicator automatically compares the membership of the subscription to the defined management group and corrects this in the case of a mismatch.
Best,
Sergej
Jelle den Burger
Sergej Neumann: Thanks for the elaboration!
This also sounds a bit like an expectation mismatch: the management group where to share these resources and the management group of the landing zone are different? Or do I see that wrongly?
Would it help if the meshStack replicator leaves the management group assignment untouched?
S
Sergej Neumann
Jelle den Burger we want to use the hierarchy of the management groups. The new management group would be under the management group of the landing zone.
Your suggestion would help. However this would require adjustments in our backend. We will discuss this option internally and come back.
Jelle den Burger
Sergej Neumann : it sounds a bit similar to a solution we have for Google Cloud. There the replicator leaves folder assignments untouched (folder is the same thing as a management group basically) as long as the tenant is assigned below the hierarchy of the folder that is defined in the landing zone.
I attached an image what this could look like for Azure (currently this does not work)
In the example, the landing zone is attached to the "IT Team" management group. As long as the tenant is somewhere within that hierarchy, either on the management group itself or one of its children, the replicator would leave the assignment untouched