finds.dev← search

// the find

Azure/terraform-azurerm-caf-enterprise-scale

★ 960 · HCL · MIT · updated Sep 2026

Azure landing zones Terraform module

A Terraform module that deploys the Cloud Adoption Framework management group hierarchy, the core Azure Policy and RBAC baseline, and optional connectivity, management and identity resources. It is aimed at platform teams building an Azure landing zone with AzureRM who want the CAF reference design as a starting point. The README now marks it deprecated: it will get no further updates, and new deployments should use Azure Verified Modules for Platform Landing Zones.

- The archetype definitions and policy assignments are plain JSON templates under modules/archetypes/lib, so you can read exactly what a landing zone enforces without tracing through HCL. The policy library has its own update workflow and scripts, which shows it was maintained as data, not hand-edited.

- The connectivity input is a typed object tree covering hub VNets, subnets, VPN and ExpressRoute gateways, Azure Firewall, and a separate Virtual WAN branch with routing intent. The DNS block has close to a hundred per-service private link flags with defaults, which is the detail teams usually end up writing by hand.

- The examples directory includes a remote-state variant and an orchestration variant that split core, management and connectivity into separate Terraform states. Splitting state that way is the part most teams get wrong on their own, and the examples show a working layout.

- It is deprecated. The README says it will receive no updates and points to Azure Verified Modules. Anything adopted now is a fork you maintain, and any AzureRM or policy changes after this point will not reach you.

- The baseline is old: Terraform ~> 1.7 and azurerm ~> 3.108. Moving to azurerm 4.x means working through the breaking changes yourself, and nothing in the repo tells you which of them are already known.

- Both custom_landing_zones and archetype_config_overrides are typed as `any`. Terraform won't catch a misspelled key or a wrong nested type until plan time, and the schema lives in a README comment block rather than in enforced types.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →