Service inventory
The Azure Baseline deploys the services below across its 14 subscriptions. Most are on by default; the ones with a high fixed price or a license prerequisite are built, wired and off, each one switch with its price beside it in the code. The tables below list each service by area, the subscription it runs in and the unit that manages it.
Switches live in three places: environments/core/network/eastus2/network.hcl for the hub network, environments/core/security/security.hcl for the security services, and the unit definition itself for a choice that only one unit reads. Multi-subscription topology shows which units each subscription runs.
Governance
| Service | Subscription | Unit | Default |
|---|---|---|---|
| Management groups | acme-core-root | organizations | On: mg-acme, mg-acme-core, mg-acme-plat |
| Subscriptions (created or adopted) | acme-core-root | organizations | On: the 14 subscriptions, placed under their management groups |
| Azure Policy guardrails and tag policy | acme-core-root | organizations | On: four assignments at mg-acme; the tag policy audits until enforce_tag_policy |
| Azure Policy compliance initiatives | acme-core-root | policy-compliance | On: Microsoft cloud security benchmark and SOC 2 baseline; nine more off, one switch each |
| Resource locks | Every subscription | Each unit's module | On: CanNotDelete on the resource groups that hold state, keys, logs and networks |
| Storage for OpenTofu state | acme-core-root | state-backend | On |
Identity
| Service | Subscription | Unit | Default |
|---|---|---|---|
| Entra ID groups and Azure RBAC role assignments | acme-core-identity | entra-rbac | On: group lookups (creation is create_groups), the custom auditor role |
| Privileged Identity Management | acme-core-identity | pim | Off: enable_pim in the identity stack file (Entra ID P2, about $9 per user per month) |
| Conditional Access | acme-core-identity | conditional-access | On, in report-only mode until conditional_access_state is enabled |
| Managed identities federated to GitHub | acme-core-auto | github-oidc | On: one per infrastructure and code repository |
| Managed identity of the secrets repository | acme-core-security | secrets-syncer | On |
| Entra ID diagnostic settings | acme-core-root | entra-diagnostics | On: enable_entra_log_export (needs Entra ID P1 or P2) |
Network
| Service | Subscription | Unit | Default |
|---|---|---|---|
| Virtual networks and network security groups | acme-core-network, acme-core-auto, the four plat subscriptions | vnet-hub, vnet-runner, vnet-spoke | On: the hub, the runner VNet and one spoke per stage |
| Virtual network peering | acme-core-auto, plat subscriptions | vnet-peering | On: every spoke to the hub |
| Route tables | acme-core-auto, plat subscriptions | routes-spoke | On: default and organization routes to the firewall |
| Azure Firewall and Firewall Policy | acme-core-network | firewall, firewall-policy | On: Standard, three zones; hub_egress, firewall_sku, firewall_zones |
| NAT gateway per spoke | plat subscriptions, acme-core-auto | vnet-spoke, vnet-runner | Off: only with hub_egress = "spoke_nat", about $33 per month each |
| Azure DNS Private Resolver | acme-core-network | dns-resolver | On: enable_dns_private_resolver, about $365 per month for both endpoints |
| Azure Private DNS zones and links | acme-core-network, every VNet | private-dns, private-dns-link | On: internal.company.com and ten Private Link zones |
| Azure DNS public zones with DNSSEC | acme-core-dns | dns-zones | On: the apex zone and the stage zones; DNSSEC on the apex, prod and staging zones |
| VPN Gateway, point-to-site | acme-core-network | client-vpn | Off: enable_client_vpn, about $263 per month plus connection hours |
| Network Watcher and VNet flow logs | Every subscription | subscription-baseline, VNet units | On: flow logs to the audit storage |
| Traffic Analytics | Every VNet | VNet units | Off: enable_traffic_analytics (ingestion cost) |
| Azure Virtual Network Manager IPAM pools | acme-core-network | ipam | Off: enable_avnm_ipam, about $0.10 per managed subscription-hour |
Security
| Service | Subscription | Unit | Default |
|---|---|---|---|
| Microsoft Defender for Cloud | Every subscription | subscription-baseline | On: Containers, Storage, Key Vault, Resource Manager; off: Servers, Cosmos DB, CSPM, API |
| Defender for Storage malware scanning | Every subscription | subscription-baseline | Off: defender_storage_malware_scanning, $0.15 per GB scanned |
| Defender for Cloud continuous export | Every subscription but acme-core-security | observability-link | On: to the security workspace |
| Microsoft Sentinel | acme-core-security | observability-sink | Off: enable_sentinel, $2.46 per GB analytics tier |
| Azure DDoS Network Protection | acme-core-security | ddos-plan | Off: enable_ddos_protection, $2,944 per month |
| Key Vault for the SOPS keys | acme-core-security | sops-keys | On: one key per stage |
| Key Vault for the audit customer-managed key | acme-core-audit | audit-cmk | On |
| Key Vault for CI | acme-core-auto | platform-kv | On |
| Key Vault for the workload contract | plat subscriptions | kv-publish | On: one per stage |
Logging and alerting
| Service | Subscription | Unit | Default |
|---|---|---|---|
| Log Analytics, audit workspace | acme-core-audit | audit-workspace | On: 365-day retention |
| Storage, immutable audit archive | acme-core-audit | audit-storage | On: 365-day immutability, customer-managed key |
| Log Analytics, security workspace | acme-core-security | observability-sink | On: 365-day retention |
| Azure Monitor action group | acme-core-security | observability-sink | On: email to the security mailbox |
| Log Analytics, stage application workspaces | plat subscriptions | observability-link | On: retention 30 days (sandbox, dev), 90 (staging), 365 (prod) |
| Azure Monitor activity-log alerts | Every subscription | activity-alerts | On: enable_cis_alerts, ten per subscription |
| Azure Monitor scheduled query alerts | acme-core-audit | cis-alerts | On: enable_cis_alerts, six KQL alerts |
Delivery
| Service | Subscription | Unit | Default |
|---|---|---|---|
| Azure Container Registry | acme-core-artifacts | acr | On: Standard, about $20 per month; Premium is the switch for private endpoints and retention |
| Storage for shared build inputs | acme-core-artifacts | shared-storage | On |
| Storage for the Unity Catalog metastore | acme-core-artifacts | uc-metastore | On, with its Databricks access connector |
| Azure Container Apps job for GitHub runners | acme-core-auto | github-runners | On: enable_github_runners, scale to zero, about $0.12 per runner-hour |
Prices are list prices in eastus2 as the code comments state them. The tool and provider versions that deploy these services are on the versions page.