Skip to content

Multi-Cloud Governance

Summary

Multi-cloud governance is the operating model for an enterprise that runs workloads on two or more public clouds. In this topic the clouds are AWS, GCP, Alibaba Cloud, and Tencent Cloud, with Azure common in Western estates. It is not a product. It is a control plane assembled from identity federation, policy-as-code, cloud-organization guardrails, posture scanning, landing zones, IaC and GitOps, OpenTelemetry-based observability, and FinOps on the FOCUS billing schema. The organizing idea is one intent, enforced natively in each cloud: define rules once in Git and enforce them at CI, at the Terraform run, at the cloud organization boundary, and at the Kubernetes API server.

Key Facts

Fact Value (checked 2026-09-25)
Scope Cross-cutting pattern: networking, identity, DNS, policy, security baseline, landing zones, IaC, GitOps, observability, FinOps
Latest Version (date): key standards FOCUS 1.4 (ratified 2026-06-04). CIS AWS Foundations v7.0.0 (2026-04)
Latest Version (date): policy engines OPA 1.21.0 (2026-09-24). Gatekeeper 3.23.1 (2026-08-27). Kyverno 1.19.1 (2026-09-10)
Latest Version (date): IaC and scanners Crossplane 2.4.2 (2026-09-22). Cloud Custodian 0.9.52 (2026-09-03). Prowler 5.43.0 (2026-09-21)
Licenses OPA, Gatekeeper, Kyverno, Crossplane, Cloud Custodian, Prowler: Apache-2.0. Terraform: BSL 1.1. OpenTofu: MPL-2.0
CNCF status OPA, Kyverno (2026-03), Crossplane (2025) Graduated. Cloud Custodian Incubating. OpenTofu Sandbox
Recent shifts Crossplane v2 (namespaced XRs/MRs, no claims). Kyverno CEL policies GA (1.17). Wiz is part of Google (2026-03). Prisma Cloud became Cortex Cloud. AWS Interconnect -- multicloud GA with Google Cloud (2026-04). AWS App Mesh end of support 2026-09-30

Full version and tool tables: Reference: Tool and Standard Versions.

Governance Control Plane at a Glance

Policies and IaC live in Git. Preventive checks run in CI, on Terraform runs, at the cloud organization boundary, and in Kubernetes admission. Detective tools scan what actually runs, and audit and FOCUS billing data flow back as evidence.

flowchart LR
    IDP["Central IdP<br/>(SAML / OIDC)"] --> ORG
    GIT["Git: IaC + policy"] --> CI["CI policy checks<br/>(Conftest, Checkov, Trivy)"]
    CI --> RUN["Terraform run<br/>(Sentinel / OPA)"]
    RUN --> ORG["Cloud org guardrails<br/>(SCP, Azure Policy, Org Policy,<br/>Alibaba control policies)"]
    GIT --> ADM["K8s admission<br/>(Gatekeeper / Kyverno)"]
    ORG --> DET["Detective controls<br/>(Cloud Custodian, Prowler, CSPM)"]
    ADM --> EV["Evidence: SIEM, policy reports"]
    DET --> EV
    ORG --> COST["FOCUS billing exports<br/>(FinOps)"]

The detailed architecture and the pull-request-to-runtime sequence are in Explanation: Governance Control Plane and Policy Flow.

Governance Domains

1. Policy and Guardrails

Preventive policy runs at four layers: CI (Conftest/OPA, Checkov, Trivy), Terraform runs (Sentinel or OPA on HCP Terraform), cloud-organization guardrails (AWS SCPs and RCPs, Azure Policy, GCP Organization Policy, Alibaba control policies), and Kubernetes admission (Gatekeeper, Kyverno, ValidatingAdmissionPolicy). Cloud Custodian adds detect-and-remediate for live resources. See Explanation: Policy Engines and Their Trade-offs and How-to: Policy as Code.

2. Security Baseline and Posture

CIS Foundations benchmarks exist for AWS (v7.0.0), Azure, GCP, and Alibaba Cloud, but not Tencent Cloud (use MLPS 2.0). Posture is scanned by native services (AWS Security Hub CSPM, Microsoft Defender for Cloud, GCP Security Command Center, Alibaba Security Center), open source (Prowler, Cloud Custodian), or CNAPPs (Wiz, Cortex Cloud, Orca). See Explanation: Security Baseline and Compliance and Reference: Security and Compliance Reference.

3. Landing Zones

Each cloud has its own accelerator: AWS Control Tower plus Landing Zone Accelerator, Azure Landing Zones on Azure Verified Modules (the caf-enterprise-scale module is deprecated), the Google Cloud Enterprise Foundations Blueprint or Fabric FAST, Alibaba Agentic Cloud Governance Center (renamed from Cloud Governance Center on 2026-06-24), and Tencent Cloud Control Center. Standardize the intent, and let each accelerator implement it. See Explanation: Landing Zones.

4. Identity Federation (IAM)

One IdP (Okta, Entra ID, Keycloak) federates humans via SAML/OIDC. CI and workloads use OIDC token exchange: AWS AssumeRoleWithWebIdentity, GCP Workload Identity Federation, Alibaba AssumeRoleWithOIDC (RRSA for ACK), and Tencent CAM OIDC. SPIFFE/SPIRE provides a cloud-independent workload identity overlay. See Explanation: Identity Federation.

5. Multi-Cloud Networking

Hub-spoke, full-mesh, transit-backbone, and SD-WAN topologies trade latency against blast radius and cost. Provider-managed cross-cloud links (GCP Cross-Cloud Interconnect, AWS Interconnect -- multicloud) now complement fabrics like Equinix Fabric and Megaport, but China-region clouds still rely on Express Connect / Direct Connect. See Explanation: Networking Patterns.

6. DNS and Traffic Management

Route 53, Cloud DNS, Alidns, and DNSPod handle latency, geo, weighted, and failover routing. A GSLB layer (Route 53, Cloudflare, NS1) unifies policy across clouds. China needs ICP filing and usually split-horizon DNS. See Explanation: DNS and Traffic Management.

7. Infrastructure-as-Code

Terraform/OpenTofu has the broadest provider coverage (including aliyun/alicloud and tencentcloudstack/tencentcloud). Pulumi suits developer-heavy teams. Crossplane v2 suits Kubernetes-first platform teams, with community providers for Alibaba and Tencent. See Explanation: Infrastructure-as-Code and IaC Comparison.

8. CI/CD and GitOps

Argo CD ApplicationSets or Flux remote Kustomizations reconcile workloads to EKS, GKE, ACK, and TKE clusters from one management plane. Secrets come from External Secrets Operator or SOPS with per-cloud KMS. See Explanation: CI/CD and GitOps.

9. Observability

OpenTelemetry is the common layer: per-cloud collector gateways export OTLP to one backend (Grafana LGTM, Datadog, Dynatrace), tagged with cloud.provider and cloud.region. See Explanation: Observability Architecture and How-to: Observability.

10. Cost Management (FinOps)

The FinOps Framework runs Inform, Optimize, and Operate phases, with Crawl/Walk/Run maturity per capability. FOCUS gives one billing schema. AWS, Azure, Google Cloud, and OCI export it, Alibaba (preview) and Tencent support FOCUS 1.0, and FOCUS 1.4 was ratified in 2026-06. See Explanation: FinOps Model and How-to: FinOps and Cost Management.

Evaluation

Strengths of a governed multi-cloud model Costs and risks
Regulatory and data-residency fit (for example, Alibaba/Tencent for mainland China, AWS/GCP elsewhere) Every control is implemented 2-4 times in different policy languages
Negotiating leverage and best-of-breed services per cloud Tooling coverage is uneven: cross-cloud CSPM, Crossplane providers, and FinOps tools are thinnest for Tencent and Alibaba
Blast-radius isolation between providers Cross-cloud egress and interconnect costs, plus two or more on-call skill sets
Open standards (OTel, FOCUS, OIDC, OPA/CEL) reduce lock-in at the governance layer Lowest-common-denominator abstractions forfeit each provider's strengths

Fits when regulation, M&A, or market reach (for example, China plus rest of world) forces more than one provider, and a platform team exists to own the control plane. Avoid when multi-cloud is only a hedge: a single cloud with strong landing-zone guardrails is cheaper to govern.

Topic Map

  • How-to Guides: policy-as-code recipes (Conftest, Gatekeeper, Kyverno, Cloud Custodian, Prowler), identity-federation snippets, multi-cloud IaC, Argo CD, OTel collectors, FOCUS queries, troubleshooting.
  • Reference: versions, interconnect and DNS services, Terraform and Crossplane providers, workload identity, CIS benchmarks, CSPM and policy tools, landing zones, FOCUS, commitments, tagging, OTel conventions.
  • Explanation: governance control plane, policy flow, engine trade-offs, CSPM market, landing zones, networking, IaC, GitOps, observability, FinOps, identity, threat model.

Sources

Questions

  • What is the realistic blast-radius trade-off between hub-spoke and full-mesh topologies for an APAC-centric enterprise running AWS + Alibaba Cloud, now that GCP Cross-Cloud Interconnect reaches Alibaba but AWS Interconnect does not?
  • How do Alibaba RAM role-session-name and oidc:sub constraints compare with AWS IAM trust-policy patterns when federating from a single IdP?
  • Are the Crossplane Alibaba (provider-upjet-alibabacloud) and Tencent providers mature enough for production, or is Terraform/OpenTofu the safer choice for China-cloud resources?
  • What is the current state of OTLP ingestion stability in Alibaba Cloud SLS and Tencent CLS?
  • Which FOCUS version do Alibaba (preview) and Tencent exports target by the time FOCUS 1.4 is widely adopted, and when does Alibaba's export reach GA?
  • Is there a CIS-equivalent benchmark for Tencent Cloud comparable to the other clouds? (The landing-zone accelerator question is answered: Tencent Cloud Control Center; see the Tencent Cloud topic.)
  • How should an enterprise normalize FinOps unit economics (cost per transaction) when one transaction spans two clouds?