1. Secure Cosmos DB Onboarding: RBAC, Managed Identity and CMK
| External — Microsoft Product Content | Internal — Bank Process and Governance |
|---|---|
| Cosmos DB control-plane and data-plane RBAC | Internal access-request and approval process |
| Built-in and custom roles | Human-user and technical-user onboarding |
| Microsoft Entra ID and managed identities | MIM/Group ID creation and assignment |
| Group-based access management | Role Sync and future Group ID access model |
| Customer-managed keys and Key Vault integration | CMK ownership, Key Vault access and audit evidence |
| RBAC troubleshooting and common errors | Support ownership and escalation process |
2. Cosmos DB Resilience, Backup and Disaster Recovery
| External — Microsoft Product Content | Internal — Bank Process and Governance |
|---|---|
| Availability zones and multi-region deployment | BCM initiation and approval process |
| Single-write and multi-write region design | Internal RPO and RTO expectations |
| Automatic and manual failover options | Failover ownership and communication process |
| Continuous backup and point-in-time restore | Restore-request and validation process |
| Failure scenarios and recovery options | Change, incident and escalation requirements |
| Microsoft support process for backend failover | BCM evidence and exercise documentation |
3. Cosmos DB Cost and RU Optimisation
| External — Microsoft Product Content | Internal — Bank Process and Governance |
|---|---|
| Request Unit calculation and consumption | Internal cost ownership and reporting |
| Manual versus autoscale throughput | Lower-environment throughput standards |
| Database-level versus container-level throughput | Approval process for high-cost configurations |
| Query, partition-key and indexing impact on RUs | Audit-to-Deny policy lifecycle |
| TTL and storage optimisation | Cost exception and expiry process |
| Monitoring and identifying high-RU operations | Cost tracker and periodic review process |
4. Cosmos DB Performance Troubleshooting for Application Teams
| External — Microsoft Product Content | Internal — Bank Process and Governance |
|---|---|
| Troubleshooting latency and throttling | First-level checks before escalation |
| HTTP 429 errors and SDK retry behaviour | Application-team versus SRE ownership |
| Hot-partition identification | Required information in support tickets |
| Query and indexing optimisation | Internal incident and escalation process |
| Regional preference and SDK configuration | Log, metric and evidence requirements |
| Cosmos DB monitoring and diagnostic tools | GitLab tracking and follow-up ownership |
5. Policy-Compliant Cosmos DB Deployment
| External — Microsoft Product Content | Internal — Bank Process and Governance |
|---|---|
| Secure Cosmos DB deployment patterns | Internal Control Plane and pipeline workflow |
| Backup, networking, CMK and RBAC configuration | Mandatory policy metadata and category values |
| Private endpoint configuration | CI validation and release requirements |
| Azure Policy effects: Audit, Deny, DINE and AINE | Internal policy review and approval lifecycle |
| ARM, Bicep and Terraform considerations | Policy tracker, evidence and ownership |
| Recommended compliance controls | Exception and remediation process |
6. Cosmos DB Migration and Adoption
| External — Microsoft Product Content | Internal — Bank Process and Governance |
|---|---|
| Account and container migration approaches | Application onboarding and eligibility assessment |
| Container Copy and supported migration tools | Internal approval for Preview features |
| Source-to-target connectivity requirements | Migration Factory engagement process |
| Data validation and reconciliation | Naming and policy-compliance checks |
| Migration performance and RU planning | Production-readiness and change approval |
| Rollback and post-migration validation | Ownership, support and decommissioning process |





0 comments:
Post a Comment