AzureLive-testedattested

Azure Landing Zone Core

Management-group hierarchy, policy baseline (ALZ-aligned), centralized logging and RBAC scaffolding - the flagship enterprise starter.

terraformAzureazure

Compare Landing Zone across clouds →

azure-landing-zone-corevizier v1.2.0

Verification

Live-tested

Really deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan test superseded by live test

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-29 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o azure-landing-zone-core-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/azure-landing-zone-core/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle azure-landing-zone-core-1.0.0.sigstore.json \
  azure-landing-zone-core-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "d9ee1bde04ac67a395b65ad53593a7aa369ca52f445832c57a3e0c20b06a7c3c  azure-landing-zone-core-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "landing_zone_core" {
  source  = "www.iac-bazaar.com/iac-bazaar/azure-landing-zone-core/azure"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/azure-landing-zone-core/badge)](https://www.iac-bazaar.com/catalog/azure-landing-zone-core?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, live-tested on IaC Bazaar: [Azure Landing Zone Core](https://www.iac-bazaar.com/catalog/azure-landing-zone-core?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "landing_zone_core" {
  source  = "www.iac-bazaar.com/iac-bazaar/azure-landing-zone-core/azure"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: live-tested

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

azure-landing-zone-core

Prerequisites: applying this needs tenant-root or Management Group Contributor permissions. A subscription-scoped identity is not enough.

The flagship enterprise starter: a management-group hierarchy, an optional centralized Log Analytics workspace, custom Azure Policy definitions with management-group-scoped assignments, and custom RBAC role definitions and assignments. ALZ-aligned by default, but small, transparent and fully parameterised — original work, not a wrapper over avm-ptn-alz, so you own the graph and can read every resource it creates.

Design & secure defaults

  • ALZ-aligned default hierarchy under your root MG: Platform, Landing Zones (with Corp and Online children), Sandbox, Decommissioned. Override child_management_groups to reshape it; child parent references are validated so you can't point at a missing parent.
  • Key-based references throughout. Subscriptions, policy assignments and role assignments target management groups by key (root or a child key), resolved to IDs internally — preconditions fail the plan on a typo'd key instead of producing a misplaced assignment.
  • Policies enforced by default (enforce = true) — not audit-only. Custom definitions are created at the root MG and can be referenced from an assignment as custom:<name>; built-in policy/initiative IDs work directly.
  • Centralized workspace: Entra-only auth (local_authentication_enabled = false), bounded retention (90 days), optional daily cap.
  • Least-privilege custom roles: defined and assignable at the root MG; assignments accept either a built-in role_definition_name or a custom_role_key, and a precondition enforces exactly one.

Works with Terraform and OpenTofu (>= 1.6), azurerm provider >= 4.0, < 5.0.

Requirements

RequirementVersion
Terraform / OpenTofu>= 1.6
hashicorp/azurerm>= 4.0, < 5.0

License

Commercial — LicenseRef-IaCBazaar-Commercial. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs
  • Notes

Related modules

Static validatedLive test pending

azure-budget

Azure requires a notification block, which makes the problem look solved: a notification can be created disabled, and contact_roles = Owner emails whoever holds the role, which is often a service principal with no mailbox. Insists on an enabled notification with a real address or action group, and on a Forecasted threshold so the first message arrives while there is still a month to act.

View module
Static validatedLive test pending

azure-policy

enforce = false is Azure DoNotEnforce: the assignment appears, resources are evaluated, a compliance percentage is charted - and every violating resource is created anyway. From the portal compliance view that is indistinguishable from an enforced policy. Also refuses a silent not_scopes exclusion and an unexplained denial.

View module
Static validatedLive test pending

aws-control-tower

A Control Tower landing zone from a manifest the module writes: the governed regions (the only usable ones), the Security and Sandbox units, centralized logging in the log archive account you name kept a year (access logs ten) under your KMS key (the AWS-managed key by name), the audit account, Identity Center access, and the controls you map to organizational units.

View module
Static validatedLive test pending

alicloud-landing-zone

A Resource Directory with its folders and member accounts. Two switches decide whether it works: control policies are off until the directory enables them, so a policy written elsewhere attaches to nothing; and member deletion is off by default, which makes every account this creates permanent and terraform destroy fail on it. Both are on here.

View module
Static validatedLive test pending

tencent-landing-zone

Tencent organization nodes and members. policy_type takes one value and it is Financial: what a membership grants is numbered billing permissions, not a governance boundary, and is_a_policy_boundary says false. The permissions are taken as words and written as the integers Tencent wants, and the one that moves money is asked about.

View module
Static validatedLive test pending

huawei-landing-zone

An organization, its units and its accounts. enabled_policy_types is what makes a service control policy attachable at all: without it a policy is created and fails to attach, at apply, behind a clean plan, and neither console connects the two. The account email and phone are the recovery path, so an account with none is listed as an output.

View module