π‘οΈ Azure API Management service in a capacity-based tier has no active APIsπ’
- Contextual name: π‘οΈ Capacity-based service has no active APIsπ’
- ID:
/ce/ca/azure/api-management/no-active-apis - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
COST
Statsβ
not available
Logicβ
- π§ prod.logic.yamlπ’
Descriptionβ
Descriptionβ
This policy identifies successfully provisioned Azure API Management services in non-Consumption tiers that are older than 30 days and have no active related API records in Cloudaware CMDB.
Rationaleβ
Non-Consumption API Management tiers reserve capacity and continue to incur service costs even when the service contains no APIs. Consumption-tier services are excluded because they use a consumption-based cost model.
Impactβ
An empty capacity-based service creates avoidable cost and inventory overhead. Deleting it without review can disrupt planned deployments or dependencies involving networking, identities, certificates, policies, custom domains, or DNS.
Auditβ
This policy flags an Azure API Management Service as
INCOMPLIANTif it is in theSucceededprovisioning state, uses a non-Consumption SKU, was created more than 30 days ago, and has no non-disappeared related Azure API Management API records.
Remediationβ
Remediationβ
Verify the API inventory directly in Azure before changing or deleting the service.
From Azure Portalβ
- Open API Management services.
- Select the affected service.
- Under APIs, confirm that no APIs are listed.
If APIs exist in Azure but are absent from Cloudaware CMDB, investigate collection permissions or synchronization before proceeding.
From Azure CLIβ
Run the following command:
az apim api list \
--resource-group <resource-group-name> \
--service-name <api-management-service-name>An empty result confirms that Azure currently reports no APIs for the service.
Review and Remediateβ
- Confirm the service owner and verify that no API deployment is planned.
- Review custom domains, DNS records, networking, private endpoints, identities, certificates, named values, policies, diagnostic settings, and automation that references the service.
- If the service is unused, delete it through the approved change process.
- If the service is reserved for planned use or retains required dependencies,
... see more
policy.yamlβ
Linked Framework Sectionsβ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| πΌ Cloudaware Framework β πΌ Waste Reduction | 30 | no data |