Multi-Cloud Governance¶
Summary
Multi-cloud governance is the operating model for an enterprise that runs workloads on two or more public clouds. In this topic the clouds are AWS, GCP, Alibaba Cloud, and Tencent Cloud, with Azure common in Western estates. It is not a product. It is a control plane assembled from identity federation, policy-as-code, cloud-organization guardrails, posture scanning, landing zones, IaC and GitOps, OpenTelemetry-based observability, and FinOps on the FOCUS billing schema. The organizing idea is one intent, enforced natively in each cloud: define rules once in Git and enforce them at CI, at the Terraform run, at the cloud organization boundary, and at the Kubernetes API server.
Key Facts¶
| Fact | Value (checked 2026-09-25) |
|---|---|
| Scope | Cross-cutting pattern: networking, identity, DNS, policy, security baseline, landing zones, IaC, GitOps, observability, FinOps |
| Latest Version (date): key standards | FOCUS 1.4 (ratified 2026-06-04). CIS AWS Foundations v7.0.0 (2026-04) |
| Latest Version (date): policy engines | OPA 1.21.0 (2026-09-24). Gatekeeper 3.23.1 (2026-08-27). Kyverno 1.19.1 (2026-09-10) |
| Latest Version (date): IaC and scanners | Crossplane 2.4.2 (2026-09-22). Cloud Custodian 0.9.52 (2026-09-03). Prowler 5.43.0 (2026-09-21) |
| Licenses | OPA, Gatekeeper, Kyverno, Crossplane, Cloud Custodian, Prowler: Apache-2.0. Terraform: BSL 1.1. OpenTofu: MPL-2.0 |
| CNCF status | OPA, Kyverno (2026-03), Crossplane (2025) Graduated. Cloud Custodian Incubating. OpenTofu Sandbox |
| Recent shifts | Crossplane v2 (namespaced XRs/MRs, no claims). Kyverno CEL policies GA (1.17). Wiz is part of Google (2026-03). Prisma Cloud became Cortex Cloud. AWS Interconnect -- multicloud GA with Google Cloud (2026-04). AWS App Mesh end of support 2026-09-30 |
Full version and tool tables: Reference: Tool and Standard Versions.
Governance Control Plane at a Glance¶
Policies and IaC live in Git. Preventive checks run in CI, on Terraform runs, at the cloud organization boundary, and in Kubernetes admission. Detective tools scan what actually runs, and audit and FOCUS billing data flow back as evidence.
flowchart LR
IDP["Central IdP<br/>(SAML / OIDC)"] --> ORG
GIT["Git: IaC + policy"] --> CI["CI policy checks<br/>(Conftest, Checkov, Trivy)"]
CI --> RUN["Terraform run<br/>(Sentinel / OPA)"]
RUN --> ORG["Cloud org guardrails<br/>(SCP, Azure Policy, Org Policy,<br/>Alibaba control policies)"]
GIT --> ADM["K8s admission<br/>(Gatekeeper / Kyverno)"]
ORG --> DET["Detective controls<br/>(Cloud Custodian, Prowler, CSPM)"]
ADM --> EV["Evidence: SIEM, policy reports"]
DET --> EV
ORG --> COST["FOCUS billing exports<br/>(FinOps)"]
The detailed architecture and the pull-request-to-runtime sequence are in Explanation: Governance Control Plane and Policy Flow.
Governance Domains¶
1. Policy and Guardrails¶
Preventive policy runs at four layers: CI (Conftest/OPA, Checkov, Trivy), Terraform runs (Sentinel or OPA on HCP Terraform), cloud-organization guardrails (AWS SCPs and RCPs, Azure Policy, GCP Organization Policy, Alibaba control policies), and Kubernetes admission (Gatekeeper, Kyverno, ValidatingAdmissionPolicy). Cloud Custodian adds detect-and-remediate for live resources. See Explanation: Policy Engines and Their Trade-offs and How-to: Policy as Code.
2. Security Baseline and Posture¶
CIS Foundations benchmarks exist for AWS (v7.0.0), Azure, GCP, and Alibaba Cloud, but not Tencent Cloud (use MLPS 2.0). Posture is scanned by native services (AWS Security Hub CSPM, Microsoft Defender for Cloud, GCP Security Command Center, Alibaba Security Center), open source (Prowler, Cloud Custodian), or CNAPPs (Wiz, Cortex Cloud, Orca). See Explanation: Security Baseline and Compliance and Reference: Security and Compliance Reference.
3. Landing Zones¶
Each cloud has its own accelerator: AWS Control Tower plus Landing Zone Accelerator, Azure Landing Zones on Azure Verified Modules (the caf-enterprise-scale module is deprecated), the Google Cloud Enterprise Foundations Blueprint or Fabric FAST, Alibaba Agentic Cloud Governance Center (renamed from Cloud Governance Center on 2026-06-24), and Tencent Cloud Control Center. Standardize the intent, and let each accelerator implement it. See Explanation: Landing Zones.
4. Identity Federation (IAM)¶
One IdP (Okta, Entra ID, Keycloak) federates humans via SAML/OIDC. CI and workloads use OIDC token exchange: AWS AssumeRoleWithWebIdentity, GCP Workload Identity Federation, Alibaba AssumeRoleWithOIDC (RRSA for ACK), and Tencent CAM OIDC. SPIFFE/SPIRE provides a cloud-independent workload identity overlay. See Explanation: Identity Federation.
5. Multi-Cloud Networking¶
Hub-spoke, full-mesh, transit-backbone, and SD-WAN topologies trade latency against blast radius and cost. Provider-managed cross-cloud links (GCP Cross-Cloud Interconnect, AWS Interconnect -- multicloud) now complement fabrics like Equinix Fabric and Megaport, but China-region clouds still rely on Express Connect / Direct Connect. See Explanation: Networking Patterns.
6. DNS and Traffic Management¶
Route 53, Cloud DNS, Alidns, and DNSPod handle latency, geo, weighted, and failover routing. A GSLB layer (Route 53, Cloudflare, NS1) unifies policy across clouds. China needs ICP filing and usually split-horizon DNS. See Explanation: DNS and Traffic Management.
7. Infrastructure-as-Code¶
Terraform/OpenTofu has the broadest provider coverage (including aliyun/alicloud and tencentcloudstack/tencentcloud). Pulumi suits developer-heavy teams. Crossplane v2 suits Kubernetes-first platform teams, with community providers for Alibaba and Tencent. See Explanation: Infrastructure-as-Code and IaC Comparison.
8. CI/CD and GitOps¶
Argo CD ApplicationSets or Flux remote Kustomizations reconcile workloads to EKS, GKE, ACK, and TKE clusters from one management plane. Secrets come from External Secrets Operator or SOPS with per-cloud KMS. See Explanation: CI/CD and GitOps.
9. Observability¶
OpenTelemetry is the common layer: per-cloud collector gateways export OTLP to one backend (Grafana LGTM, Datadog, Dynatrace), tagged with cloud.provider and cloud.region. See Explanation: Observability Architecture and How-to: Observability.
10. Cost Management (FinOps)¶
The FinOps Framework runs Inform, Optimize, and Operate phases, with Crawl/Walk/Run maturity per capability. FOCUS gives one billing schema. AWS, Azure, Google Cloud, and OCI export it, Alibaba (preview) and Tencent support FOCUS 1.0, and FOCUS 1.4 was ratified in 2026-06. See Explanation: FinOps Model and How-to: FinOps and Cost Management.
Evaluation¶
| Strengths of a governed multi-cloud model | Costs and risks |
|---|---|
| Regulatory and data-residency fit (for example, Alibaba/Tencent for mainland China, AWS/GCP elsewhere) | Every control is implemented 2-4 times in different policy languages |
| Negotiating leverage and best-of-breed services per cloud | Tooling coverage is uneven: cross-cloud CSPM, Crossplane providers, and FinOps tools are thinnest for Tencent and Alibaba |
| Blast-radius isolation between providers | Cross-cloud egress and interconnect costs, plus two or more on-call skill sets |
| Open standards (OTel, FOCUS, OIDC, OPA/CEL) reduce lock-in at the governance layer | Lowest-common-denominator abstractions forfeit each provider's strengths |
Fits when regulation, M&A, or market reach (for example, China plus rest of world) forces more than one provider, and a platform team exists to own the control plane. Avoid when multi-cloud is only a hedge: a single cloud with strong landing-zone guardrails is cheaper to govern.
Topic Map¶
- How-to Guides: policy-as-code recipes (Conftest, Gatekeeper, Kyverno, Cloud Custodian, Prowler), identity-federation snippets, multi-cloud IaC, Argo CD, OTel collectors, FOCUS queries, troubleshooting.
- Reference: versions, interconnect and DNS services, Terraform and Crossplane providers, workload identity, CIS benchmarks, CSPM and policy tools, landing zones, FOCUS, commitments, tagging, OTel conventions.
- Explanation: governance control plane, policy flow, engine trade-offs, CSPM market, landing zones, networking, IaC, GitOps, observability, FinOps, identity, threat model.
Related Topics¶
- Clouds: AWS, Google Cloud, Alibaba Cloud, Tencent Cloud, Kubernetes
- IaC: Terraform, OpenTofu, Pulumi, IaC Comparison
- GitOps: Argo CD, Flux, GitOps Comparison
- Secrets and identity: HashiCorp Vault, External Secrets Operator, SOPS, Secrets Comparison
- Observability: OpenTelemetry, OpenTelemetry Collector, LGTM stack
- Networking and mesh: Cilium, Istio
- Domain: Infrastructure, Infrastructure comparisons, Public Cloud Landing Zones (per-cloud landing zones side by side)
Sources¶
- FinOps Foundation: Framework and 2026 Framework update
- FOCUS specification
- CIS Benchmarks and CIS Benchmarks April 2026 update
- Open Policy Agent CHANGELOG
- OPA Gatekeeper
- Kyverno: CNCF graduation
- Crossplane documentation and CNCF: Crossplane graduation
- Cloud Custodian
- Prowler
- Landing Zone Accelerator on AWS
- Azure Landing Zones: Terraform
- Google Cloud Well-Architected Framework
- AWS: network-to-network connectivity options
- AWS Interconnect -- multicloud GA (InfoQ)
- Alibaba Cloud Express Connect
- Tencent Cloud Direct Connect
- Google completes acquisition of Wiz
- OpenTelemetry documentation
- CNCF Cloud Native Landscape
- HashiCorp Terraform documentation
- Pulumi documentation
- Argo CD documentation and Flux documentation
- SPIFFE / SPIRE
- Equinix Fabric and Megaport
Questions¶
- What is the realistic blast-radius trade-off between hub-spoke and full-mesh topologies for an APAC-centric enterprise running AWS + Alibaba Cloud, now that GCP Cross-Cloud Interconnect reaches Alibaba but AWS Interconnect does not?
- How do Alibaba RAM role-session-name and
oidc:subconstraints compare with AWS IAM trust-policy patterns when federating from a single IdP? - Are the Crossplane Alibaba (
provider-upjet-alibabacloud) and Tencent providers mature enough for production, or is Terraform/OpenTofu the safer choice for China-cloud resources? - What is the current state of OTLP ingestion stability in Alibaba Cloud SLS and Tencent CLS?
- Which FOCUS version do Alibaba (preview) and Tencent exports target by the time FOCUS 1.4 is widely adopted, and when does Alibaba's export reach GA?
- Is there a CIS-equivalent benchmark for Tencent Cloud comparable to the other clouds? (The landing-zone accelerator question is answered: Tencent Cloud Control Center; see the Tencent Cloud topic.)
- How should an enterprise normalize FinOps unit economics (cost per transaction) when one transaction spans two clouds?