This page lists all of the Azure Services for which the APRL has guidance, recommendations and queries.
Recommendation | Impact | State | ARG Query Available |
---|---|---|---|
CG-1 - A minimum of three replicas should be kept for production image versions | Medium | Preview | Yes |
CG-2 - Zone redundant storage should be used for image versions | Medium | Preview | Yes |
CG-3 - Consider using hyper-V generation version 2 images where possible |
Recommendation | Impact | State | ARG Query Available |
---|---|---|---|
IT-1 - Use Generation 2 virtual machine source image | Low | Preview | No |
IT-2 - Replicate your Image Templates to a secondary region |
Recommendation | Impact | State | ARG Query Available |
---|---|---|---|
ASR-1 - Ensure static IP addresses configured in VM failover settings are available in the failover subnet | High | Preview | No |
Recommendation | Impact | State | ARG Query Available |
---|---|---|---|
VMSS-1 - Deploy VMSS with Flex orchestration mode instead of Uniform | Medium | Preview | Yes |
VMSS-2 - Enable VMSS application health monitoring | Medium | Preview | No |
VMSS-3 - Enable Automatic Repair policy | High | Preview | No |
VMSS-4 - Configure VMSS autoscale to custom and configure the scaling metrics | High | Preview | Yes |
VMSS-5 - Enable Predictive Autoscale and configure at least for Forecast Only | Low | Preview | Yes |
VMSS-6 - Disable Force strictly even balance across zones to avoid scale in and out fail attempts | High | Preview | Yes |
VMSS-7 - Configure Allocation Policy Spreading algorithm to Max Spreading | Medium | Preview | Yes |
VMSS-8 - Deploy VMSS across availability zones with VMSS Flex | High | Preview | Yes |
VMSS-9 - Set Patch orchestration options to Azure-orchestrated | Low | Preview | No |
Recommendation | Impact | State | ARG Query Available |
---|---|---|---|
AKS-1 - Deploy AKS cluster across availability zones | High | Preview | Yes |
AKS-2 - Isolate system pods | High | Preview | Yes |
AKS-3 - Enable AKS-managed Azure AD integration | High | Preview | Yes |
AKS-4 - Configure Azure CNI networking for dynamic allocation of IPs | Medium | Preview | Yes |
AKS-5 - Enable the cluster autoscaler on an existing cluster | High | Preview | Yes |
AKS-6 - Plan for multi-region deployment | High | Preview | No |
AKS-7 - Back up Azure Kubernetes Service | Low | Preview | No |
Recommendation | Impact | State | ARG Query Available |
---|---|---|---|
CR-1 - Use Premium tier for critical production workloads | High | Preview | Yes |
CR-2 - Enable zone redundancy | High | Preview | Yes |
CR-3 - Enable geo-replication | High | Preview | Yes |
CR-4 - Maximize pull performance | High | Preview | No |
CR-5 - Use Repository namespaces | Low | Preview | No |
CR-6 - Move Container Registry to a dedicated resource group | Low | Preview | No |
CR-7 - Manage registry size | Medium | Preview | No |
CR-8 - Disable anonymous pull access | Medium | Preview | Yes |
CR-9 - Use an Azure managed identity to authenticate to an Azure container registry | Medium | Preview | No |
CR-10 - Configure Diagnostic Settings for all Azure Resources | Medium | Preview | No |
CR-11 - Monitor Azure Container Registry with Azure Monitor | Medium | Preview | No |
CR-12 - Enable soft delete policy |
Recommendation | Impact | State | ARG Query Available |
---|---|---|---|
COSMOS-1 – Configure at least two regions for high availability | High | Preview | Yes |
COSMOS-2 – Enable service-managed failover for multi-region accounts with single write region | High | Preview | No |
COSMOS-3 – Evaluate multi-region write capability | High | Preview | Yes |
COSMOS-4 – Choose appropriate consistency mode reflecting data durability requirements | High | Preview | No |
COSMOS-5 – Configure continuous backup mode | High | Preview | Yes |
COSMOS-6 – Ensure query results are fully drained | High | Preview | No |
COSMOS-7 – Maintain singleton pattern in your client | Medium | Preview | No |
COSMOS-8 – Implement retry logic in your client | Medium | Preview | No |
COSMOS-9 – Monitor Cosmos DB health and set up alerts | Medium | Preview | No |
Recommendation | Category | Impact | State | ARG Query Available |
---|---|---|---|---|
PSQL-1 - Enable HA with zone redundancy | High Availability | High | Preview | Yes |
Recommendation | Category | Impact | State | ARG Query Available |
---|---|---|---|---|
REDIS-1 - Enable zone redundancy for Azure Cache for Redis | High Availability | High | Preview |
Recommendation | Impact | State | ARG Query Available |
---|---|---|---|
SQLDB-1 - Use Active Geo Replication to Create a Readable Secondary in Another Region | High | Preview | No |
SQLDB-2 - Use Auto Failover Groups that can include one or multiple databases, typically used by the same application | High | Preview | No |
SQLDB-3 - Use a Zone-Redundant database | Medium | Preview | Yes |
SQLDB-4 - Implement Retry Logic | High | Preview | No |
SQLDB-5 - Monitor your Azure SQL Database in near-real time to detect reliability incidents | High | Preview | No |
SQLDB-6 - Back up your keys |