Cloud Governance
Preventive policy, tagging, quotas and cost and security guardrails.
4 to work through
-
intermediate
A DR test fails: the secondary region cannot launch enough instances. What happened, and what standing checks prevent it?
2 min answer -
intermediate
A platform's cloud spend has grown faster than traffic for six consecutive quarters, with no single service responsible. What governance changes address this, and why do purely technical optimisations fail to hold?
2 min answer -
advanced
Several 2023–2024 regional cloud outages were triggered by automated control-plane or configuration changes rather than by hardware failure or code deploys. How should change management, progressive rollout and control/data-plane independence be designed?
2 min answer -
advanced
You inherit a cloud estate with one account, no tags, shared root credentials and no policy enforcement. What are your first three changes and in what order?
2 min answer
5 terms in this topic
Cloud Governance
The account structure, identity model, guardrails and cost attribution that make a cloud estate operable by many teams without becoming ungovernable.
practicePreventive Guardrail
A control that makes a non-compliant action impossible, rather than detecting it afterwards and generating a ticket.
patternRevocation Path
A separate, short-TTL, fail-closed channel for security-critical configuration changes, coexisting with an eventually-consistent cached channel for o…
conceptService Quota
A per-account, per-region cap on how much of a resource may be used — a common and easily-avoided cause of scaling failures and DR failures.
practiceTagging Strategy
A defined, enforced set of metadata labels applied to every resource, without which cost allocation, ownership and lifecycle automation are all impossible.
Neighbouring topics
Cloud Architecture
General material on designing for cloud platforms.
Compute Models
Instances, containers and functions, and what each is priced and shaped for.
Cloud Storage
Object, block and file storage, and the access patterns each suits.
Cloud Databases
Managed relational, key-value, document and analytical services.
Containers
Images, registries, immutability and the deployment model they enable.
Kubernetes
The reconciliation loop, and whether the workload needs what it provides.
Serverless
Scale to zero, per-request billing, cold starts and connection limits.
Autoscaling
Signals, delays and bounds — and the maximum that caps a runaway bill.
Load Balancing
Distributing traffic, health checking, and removing failures from rotation.
Multi-Region Architecture
Surviving a region, and the data consistency price of doing so.
Availability Zones
The unit of correlated physical failure, and what zones do not protect against.
Disaster Recovery
Backup-restore, pilot light, warm standby and active-active postures.
Backup Strategies
Scope, immutability, separation, and the restore drill that makes it real.
Infrastructure as Code
Declarative infrastructure, drift, state files and rebuild-from-empty.
Landing Zones
A governed foundation of accounts, network, identity and guardrails.
Managed Services
Which operational responsibilities actually transfer, and which do not.
Cloud Migration
Per-application disposition, sequencing and the capability change underneath.
Multi-Cloud
Best-of-breed, portfolio and portable — three very different costs.
Edge Computing
Moving compute towards the user, and what cannot follow it.