-
Notifications
You must be signed in to change notification settings - Fork 6
Governance Anti Patterns Containers
Anti-patterns are automatically detected in AI-generated output after each stage. When a pattern matches and no safe pattern exempts it, a warning is shown.
Container Apps, ACR, and container runtime configuration detection
2 checks
| Check | Description | Agents |
|---|---|---|
| ANTI-CONT-001 | Secrets in environment variables detected — use Key Vault references with managed identity instead. Triggers on: environment_variable, env_varExempted by: key vault, keyvault, managed identity, secret_ref, secretref
|
all agents |
| ANTI-CONT-002 | Container registry admin credentials detected — use managed identity with AcrPull role assignment. Triggers on: admin_user_enabled = true, acrpushExempted by: managed identity, acrpull
|
all agents |
Secrets in environment variables detected — use Key Vault references with managed identity instead.
Triggers on:
environment_variableenv_var
Exempted by:
key vaultkeyvaultmanaged identitysecret_refsecretref
Correct patterns:
secret_refsecretRef# Use Key Vault references with managed identitykeyVaultUrl
Container registry admin credentials detected — use managed identity with AcrPull role assignment.
Triggers on:
admin_user_enabled = trueacrpush
Exempted by:
managed identityacrpull
Correct patterns:
admin_user_enabled = falseadminUserEnabled = false"AcrPull"# Use managed identity with AcrPull role assignment
Getting Started
Stages
Interfaces
Configuration
Agent System
Features
- Backlog Generation
- Cost Analysis
- Error Analysis
- Docs & Spec Kit
- MCP Integration
- Knowledge System
- Escalation
Quality
Help
Policies — Azure
AI Services
Compute
Data Services
- Azure SQL
- Backup Vault
- Cosmos Db
- Data Factory
- Databricks
- Event Grid
- Event Hubs
- Fabric
- IoT Hub
- Mysql Flexible
- Postgresql Flexible
- Recovery Services
- Redis Cache
- Service Bus
- Stream Analytics
- Synapse Workspace
Identity
Management
Messaging
Monitoring
Networking
- Application Gateway
- Bastion
- CDN
- DDoS Protection
- DNS Zones
- Expressroute
- Firewall
- Load Balancer
- Nat Gateway
- Network Interface
- Private Endpoints
- Public Ip
- Route Tables
- Traffic Manager
- Virtual Network
- Vpn Gateway
- WAF Policy
Security
Storage
Web & App
Policies — Well-Architected
Reliability
Security
Cost Optimization
Operational Excellence
Performance Efficiency
Integration