Azure Tag
An Azure Tag is a key-value metadata pair attached to a resource, resource group, or subscription, used to organize resources for cost allocation, automation, and governance without affecting how the resource actually functions. Tags like `environment:production` or `team:payments` let teams filter cost reports, target automation scripts, and enforce policy based on metadata rather than resource names alone.
Azure Tag
Tags don't affect how a resource runs — they're metadata used for cost allocation, automation, and governance queries.
Why It Matters in Production
Swiggy tags every resource with costCenter, environment, and owner, letting finance generate a per-team Azure spend report without needing a separate subscription per team.
az resource tag --tags costCenter=orders environment=prod
--ids /subscriptions//resourceGroups/swiggy-orders-prod-rg
Common MistakeRelying on tags for security boundaries — tags are metadata only and are not enforced as access controls unless paired with Azure Policy.
Frequently Asked Questions
What can Azure Tags actually be used for beyond labeling?
Tags drive cost allocation reports that break down spend by team, environment, or cost center; they're used as scope conditions in Azure Policy to enforce rules only on tagged resources (e.g., requiring backups on anything tagged `environment:production`); and automation runbooks or Logic Apps can target resources by tag rather than hardcoded names, so a script can act on 'everything tagged `team:payments`' without maintaining a resource ID list that goes stale.
What's a common pitfall with Azure Tags in larger organizations?
Tag key inconsistency — one team uses `Environment`, another uses `env`, another `stage`, and cost/automation queries silently miss resources using the 'wrong' casing or key name because tag matching is often case-sensitive on the key. The fix is enforcing a tag taxonomy via Azure Policy (`deny` or `append` effects on required tag keys) at subscription creation time, not after hundreds of resources already exist with inconsistent metadata that then needs a manual cleanup pass.