Skip to content

docs: EA·구독·RI 관계와 역할 부여 가이드 추가 - #69

Open
hellices wants to merge 3 commits into
mainfrom
docs/ea-subscription-reservation-roles
Open

hellices wants to merge 3 commits into
mainfrom
docs/ea-subscription-reservation-roles

Conversation

@hellices

@hellices hellices commented Sep 14, 2026 •

Copy link
Copy Markdown
Owner

변경 내용

  • EA 청구 계정·Account·Azure 구독의 관계를 간단히 설명합니다.
  • RI 구매·조회·일반 관리·역할 부여에 필요한 역할, 대상, 부여자를 표로 정리합니다.
  • Microsoft Learn의 EA 계층 원본 PNG를 수정 없이 사용하고 출처와 CC BY 4.0 라이선스를 표시합니다.
  • Cost Management + Billing 서비스와 Azure RBAC 기술 분류를 등록합니다. 수동 메뉴 등록은 추가하지 않습니다.
  • 새 문서 추가로 실패하던 고정 주제/문서 수 검사를 실제 카탈로그와 원본 문서 목록 비교로 바꿉니다.

Microsoft Learn 원문 재대조 후 수정

  • 공식 Microsoft Learn MCP로 원문을 재조회하고, Account Owner 수·부서 관리자 위임·구매 역할과 부여자·Reservations Contributor·출처 제목과 인용을 바로잡았습니다.

  • 출처 확인일: 2026-09-15 (UTC). 본문 H1 기준 출처 12개를 기록합니다.

  • EA 관리자 구매 조건은 구매 가이드의 구독 역할 요건과 EA 역할표 각주 6의 정책 예외를 구분합니다. 정책 비활성화를 구독 RBAC 면제로 단정하지 않습니다.

  • 위 조건 차이가 남아 있으므로 전체 의미 검증 완료를 주장하지 않으며 needs-review / last_verified: null을 유지합니다. 실제 Azure 역할 부여·RI 구매를 실행한 검증은 아닙니다.

  • 이전 기록은 최초 작성 당시의 이력입니다. 기존 리뷰의 사실관계와 수정 근거는 별도 PR 코멘트에 보존합니다.

  • 반영 커밋: 1444b17b49a630baf249dc6bc6d2737f9158e2ae

  • TZ=UTC python -m pytest tests/docs -q: 1,881 passed.

  • 메타데이터·공식 출처·링크·공개 안전성 검사, mkdocs build --strict, 검색 색인 검증, pre-Pages 보존 감사 통과. 보존 감사: 62/62 기준선 문서 보존, 현재 67개 문서.

  • 생성 HTML의 역할 표·Reservations Contributor·EA 구매 조건 확인 범위 안내를 확인했습니다.

  • 검증 통과는 사이트·검사 결과이며, 위에 명시한 EA 구매 조건 차이를 실제 Azure에서 해결했다는 뜻이 아닙니다.

최초 작성 시 검증 기록

  • TZ=UTC python -m pytest tests/docs -q: 1,881개 통과
  • 메타데이터·공식 출처·링크·공개 안전성 검사 통과
  • mkdocs build --strict, 검색 색인 검증, pre-Pages 보존 감사 통과
  • 브라우저에서 3개 주요 절, 2개 역할/부여자 표, 공식 원본 이미지와 출처·라이선스 링크 확인
  • 이미지 원본과 게시 결과의 SHA-256 일치 확인

최초 작성 시 검토 기록

  • 기술 내용은 공개 Microsoft Learn 원문 11개로 확인했습니다.
  • 검토일은 실제 검토 시각의 UTC 날짜인 2026-09-14로 기록했습니다(KST 2026-09-15).
  • 실행 API 예제나 내부 Engineering Hub 자료는 공개 콘텐츠에 포함하지 않습니다.

공식 이미지 출처: https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/understand-ea-roles

EA 청구 구조와 구독·예약 역할의 부여자를 간결하게 설명하고 Microsoft Learn 원본 계층도에 출처와 라이선스를 표시합니다.

새 문서가 추가되어도 게시 테스트가 고정 문서 수에 의존하지 않도록 실제 카탈로그와 원본 경로를 비교합니다.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@my-reviewer-agent my-reviewer-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

검토 범위에서 보고할 이슈가 없습니다.

리뷰 범위: 변경사항 일부만 검토했습니다.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

The guide has unresolved verification, source metadata, citation, and permission guidance issues.

Pull request overview

Adds a Korean guide covering EA accounts, Azure subscriptions, reservations, and delegated permissions, while making catalog tests dynamic.

Changes:

  • Adds the EA and reservation permissions guide with an official hierarchy image.
  • Registers Cost Management + Billing and Azure RBAC taxonomy entries.
  • Replaces hard-coded catalog counts with dynamic validation.
File summaries
File Summary
tests/docs/test_topics.py Updates canonical topic and document validation dynamically.
tests/docs/test_faceted_discovery.py Derives discovery assertions from the actual catalog.
docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md Adds the guide; 8 nit findings remain covering verification status, source titles, delegation guidance, citation alignment, policy exceptions, minimum permissions, and Account Owner wording.
docs-taxonomy.yml Registers the new service and technology classifications.
Review details

Suppressed comments (8)

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:9

  • 이 문서는 Azure 역할·범위·위임 동작을 다수 단정하면서 verified로 표시되어 있지만, 이 검토에서는 Microsoft Learn 원문 전체를 조회해 모든 주장을 의미적으로 대조할 수 없었습니다. 저장소 계약상 URL 목록만으로는 검증 완료가 아니므로, 전체 원문 검증을 마칠 때까지 verification_status: needs-review로 두고 last_verified도 비워 주세요.
verification_status: verified

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:12

  • The linked page's current title is “Understand admin roles for Enterprise Agreements in Azure”, so this official_sources entry does not record the actual source title required by the repository's verification contract. Please update the title to match the Learn page.
  - title: Manage Azure Enterprise Agreement roles

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:24

  • The linked page's current title is “View reservations in the Azure portal and PowerShell”, not “Permissions to view and manage Azure reservations”. Since the repository requires the title of the verified source, please update this entry (or cite the intended page if this is meant to be a different article).
  - title: Permissions to view and manage Azure reservations

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:67

  • Department Administrators are scoped to managing accounts and Account Owners; the EA role documentation assigns Department Administrators through an Enterprise Administrator. Listing an existing Department Administrator as someone who can grant another Department Administrator creates an incorrect request path. Please limit this cell to an existing EA Administrator.
| **Department Administrator — 부서 관리자** | 자기 부서의 계정과 Account Owner 관리. 이 역할만으로 구독을 생성하지는 못함 | EA 관리자 또는 해당 부서의 기존 부서 관리자 |

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:129

  • This paragraph describes the portal's Reservations → Role assignment flow, but its only citation is [tenant-reservation-roles], whose URL is explicitly the PowerShell procedure. Cite the portal-capable reservations article here, or change the paragraph to describe the PowerShell flow so readers can verify and follow the referenced procedure.
([테넌트 예약 역할과 부여 절차][tenant-reservation-roles], [EA 청구 범위][billing-scopes])

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:113

  • EA 관리자가 항상 적격 구독의 built-in Owner 또는 Reservation Purchaser여야 한다고 단정하지만, Reserved Instances 정책이 비활성화된 EA에서는 EA 관리자만 구매할 수 있는 예외가 있습니다. 정책 상태에 따른 예외를 이 조건에 포함하지 않으면 구매 권한 안내가 공식 조건과 충돌합니다.
  EA 관리자도 구매하려면 적격 구독의 built-in Owner 또는 Reservation Purchaser가 필요합니다.

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:131

  • 마지막 요약이 앞의 표에 있는 최소 권한 경로인 Reservation Purchaser를 빠뜨리고 구독 Owner만 권장합니다. 이대로면 구매자에게 불필요하게 넓은 Owner 권한을 요청하게 되므로 Reservation Purchaser(또는 Owner)를 명시해 주세요.
**정리하면, RI 구매 권한은 구독 Owner에게, 구매한 RI의 관리 권한은 예약 주문 Owner 또는 EA 관리자에게 요청합니다.**

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:56

  • EA에서는 하나의 Enrollment account 아래에 여러 Account Owner를 둘 수 있는데, 이 문장은 정확히 한 명으로 제한하고 있습니다. 권한 위임 구성을 오해하지 않도록 하나 이상의 Account Owner로 수정해 주세요.
- **Account / Enrollment account**: 계정마다 **Account Owner 한 명**이 있으며, 그 아래에 구독을 만듭니다.
  • Files reviewed: 4/5 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@hellices

Copy link
Copy Markdown
Owner Author

@copilot 리뷰 내용 반영

Co-authored-by: hellices <5661904+hellices@users.noreply.github.com>

Copilot AI commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

@copilot 리뷰 내용 반영

리뷰 코멘트 8건 모두 반영했습니다 (커밋 참고): verification_status를 needs-review로 되돌리고 last_verified를 비웠고, 두 출처 title을 실제 Learn 페이지 제목으로 수정했습니다. 부서 관리자 부여자를 기존 EA 관리자로 한정하고, Account Owner를 "하나 이상"으로 수정했습니다. EA 관리자 구매 조건에 Reserved Instances 정책 활성/비활성 예외를 추가하고, 테넌트 예약 역할 인용을 포털 절차를 다루는 문서로 교체했습니다. 마지막 요약 문장에 Reservation Purchaser 경로도 추가했습니다.

@my-reviewer-agent my-reviewer-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

이슈 1건을 인라인 코멘트로 남겼습니다.

리뷰 범위: 변경사항 일부만 검토했습니다.

EA 관리자는 **EA 계약 범위**, 이 예약 역할은 **테넌트 범위**를 대상으로 한다는 차이가 있습니다.
([테넌트 예약 역할과 부여 절차][reservation-access], [EA 청구 범위][billing-scopes])

**정리하면, RI 구매 권한은 구독 Owner 또는 Reservation Purchaser에게, 구매한 RI의 관리 권한은 예약 주문 Owner 또는 EA 관리자에게 요청합니다.**

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[warning] 현재 요약은 구매 권한을 “구독 Owner 또는 Reservation Purchaser에게” 요청하도록 안내합니다. 그러나 앞의 ‘RI 구매’ 표는 Reservation Purchaser를 받아야 하는 역할로, 구독 Owner 또는 구독의 권한 관리자를 부여 요청 대상으로 구분합니다. Reservation Purchaser 자체는 역할 할당 권한을 제공하지 않으므로, 독자가 이 역할만 가진 구매자에게 권한을 요청하면 해당 구매자는 필요한 역할을 부여할 수 없습니다. 이는 이전 리뷰의 최소 구매 역할 누락과는 달리, 수정된 문장이 구매 역할을 부여 주체로 잘못 옮긴 문제입니다. 요약을 ‘RI 구매를 위한 Reservation Purchaser(또는 Owner) 역할은 해당 구독 Owner 또는 구독의 권한 관리자에게 요청합니다’로 고쳐 역할과 부여자를 구분해 주세요.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Unresolved documentation corrections and a catalog regression concern must be addressed before approval.

Review details

Suppressed comments (5)

Previously missed (1) — in code that hasn't changed since the last review.

tests/docs/test_topics.py:1076

  • This replaces the fixed catalog counts with an expected set derived from the same live docs/services tree that the catalog scans. If an existing canonical page is accidentally deleted, both source_paths and catalog shrink together and the test still passes, so the previous deletion/non-regression guard is lost. Keep a committed baseline or another explicit assertion for the existing catalog while allowing the intended additions.

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:56

  • The EA hierarchy supports only one Account Owner per enrollment account. Saying “one or more” can lead readers to expect that multiple Account Owners can be assigned to the same account, which is not supported; please change this to “one Account Owner.”
- **Account / Enrollment account**: 계정마다 **하나 이상의 Account Owner**가 있으며, 그 아래에 구독을 만듭니다.

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:10

  • The PR description says the technical content was checked against 11 Microsoft Learn articles, but this metadata still marks the guide needs-review and leaves last_verified null. Under the repository source-verification contract, these fields must reflect the actual review state; if the stated verification is complete, set verification_status: verified and last_verified: 2026-09-14, or make the description state that verification is still pending.
verification_status: needs-review
sources_checked_at: 2026-09-14

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:124

  • Tenant-wide access is not limited to the two roles listed here: the built-in Reservations Contributor role is also supported and can manage tenant reservations without delegating roles. Omitting it leaves the least-privileged management option out of the guide; add it and distinguish its no-delegation behavior from Reservations Administrator.
- **Reservations Administrator**: 예약 관리와 예약 역할 위임
- **Reservations Reader**: 예약 조회

docs/services/azure-cost-management-and-billing/ea-subscription-reservation-permissions/index.md:24

  • The current Learn page at this URL is titled “Permissions to view and manage Azure reservations,” not “View reservations in the Azure portal and PowerShell.” Repository guidance requires official_sources to contain the actual article title, so update this metadata entry to match the current page (or change the URL to one with the older title).
  - title: View reservations in the Azure portal and PowerShell
  • Files reviewed: 4/5 changed files
  • Comments generated: 0 new
  • Review effort level: Lite

@my-reviewer-agent

Copy link
Copy Markdown

Microsoft Learn 원문 대조에 따른 문서 수정 및 리뷰 정정

Microsoft Learn 공식 MCP의 검색·원문 조회로 인용 문서를 재대조하고, 7a0b5de에서 아래 내용을 수정했습니다. 기존 리뷰를 일괄 수용하는 대신, 공식 문서가 뒷받침하는 주장과 잘못된 지적을 구분합니다.

수정 내용과 공식 근거

  • Account Owner는 Enrollment account당 한 명으로 복원했습니다. Enrollment 전체에 여러 계정/Account Owner가 있는 것과 한 계정에 여러 Owner를 지정하는 것은 다릅니다. 1차 Copilot의 “하나 이상” 제안은 잘못됐고, 최신 리뷰의 복원 요청이 맞습니다. Learn: Account owner
  • 부서 관리자의 부여자는 EA 관리자 또는 해당 부서의 기존 부서 관리자로 복원하고 읽기 전용 역할을 제외했습니다. 원문의 Create other department administrators와 권한표가 모두 뒷받침하므로, EA 관리자만 가능하다는 1차 지적은 맞지 않습니다. Learn: Add a department administrator
  • 구매자가 받을 역할과 그 역할의 부여자를 분리했습니다. Reservation Purchaser에는 구독 역할 할당에 필요한 Microsoft.Authorization/roleAssignments/write가 없습니다. 따라서 현재 인라인 지적은 타당하며 반영했습니다. 반대로 원래 요약의 “구독 Owner에게 요청”은 부여자를 설명한 것이지 구매자에게 Owner 역할을 받으라고 권장한 것이 아닙니다. 1차 리뷰 반영 과정에서 구매 역할이 부여자로 잘못 들어간 부분을 바로잡았습니다. Learn: Reservation Purchaser
  • Reservations Contributor를 추가해 테넌트 예약 관리와 역할 위임을 구분했습니다. 최신 리뷰의 이 지적은 맞습니다. Learn: 예약 RBAC 역할
  • 출처 제목은 현재 본문 H1 기준으로 통일했습니다. EA 역할 페이지의 H1 Manage Azure Enterprise Agreement roles와 HTML/검색 제목 Understand admin roles for Enterprise Agreements in Azure는 같은 페이지에 함께 존재하므로 원래 H1 제목을 오류로 볼 수 없습니다. 예약 권한 페이지는 원래 제목인 Permissions to view and manage Azure reservations가 현재 H1과 일치합니다.
  • PowerShell 제목의 문서에도 Portal 절차가 실제로 있습니다. 원래 인용이 Portal 절차를 뒷받침하지 못한다는 지적은 맞지 않습니다. 현재 예약 권한 문서와 함께 해당 원문도 연결했습니다. Learn: 테넌트 역할의 Portal 부여 절차

EA 구매 조건과 검증 상태

예약 구매 가이드는 “정책을 끄면 구매자를 EA 관리자로 제한”하는 조건과 “중앙 구매팀의 EA 관리자도 적어도 하나의 EA 구독에 Owner/Reservation Purchaser 필요”라는 조건을 모두 명시합니다. 전자로부터 구독 RBAC 요건 면제를 도출하지 않도록 문장을 분리했습니다. EA 역할표 각주 6의 청구 계정 구매·정책 예외도 연결하고, EA 역할만으로 구매하는 모든 경로를 확정하지 않는다는 한계를 본문에 명시했습니다. 원본에도 각주 6 안내는 있었으므로 “예외가 전혀 없었다”는 해석은 부정확합니다.

확인일은 실제 재조회일인 2026-09-15로 갱신했습니다. 리뷰어의 미확인만으로 작성자의 검증 여부를 판단하지는 않지만, 위 조건 차이는 남아 있으므로 needs-review / last_verified: null을 유지합니다. 과거 날짜로 전체 검증 완료를 다시 표시하지 않습니다. 실제 Azure 테넌트의 역할 부여·RI 구매를 실행한 것은 아닙니다.

카탈로그 테스트 리뷰의 범위

이번 수정에서는 테스트 코드를 변경하지 않았습니다. 기존 문서 삭제와 참조 정리 조건에서 base의 카탈로그 테스트는 assert 65 == 66으로 실패하고 head는 통과하므로, 해당 테스트의 고정 수량 보호 소실은 사실입니다. 다만 같은 삭제를 audit_pre_pages.py --content-only가 missing initial Pages redirect_from으로 실제 검출했습니다. 따라서 프로젝트 전체의 삭제 보호가 사라졌다고 확대하거나 수량 하드코딩을 곧바로 복원할 근거는 아닙니다. 별도 감사가 역사적 기준선만 보호한다는 범위도 구분합니다.

반영 및 검증

  • 반영 커밋: 1444b17b49a630baf249dc6bc6d2737f9158e2ae
  • TZ=UTC python -m pytest tests/docs -q: 1,881 passed.
  • 메타데이터·공식 출처·링크·공개 안전성 검사, mkdocs build --strict, 검색 색인 검증, pre-Pages 보존 감사 통과. 보존 감사: 62/62 기준선 문서 보존, 현재 67개 문서.
  • 생성 HTML의 역할 표·Reservations Contributor·EA 구매 조건 확인 범위 안내를 확인했습니다.
  • 검증 통과는 사이트·검사 결과이며, 위에 명시한 EA 구매 조건 차이를 실제 Azure에서 해결했다는 뜻이 아닙니다.

참고한 기존 리뷰: 1차 Copilot, 최신 Copilot. 기존 리뷰/코멘트는 삭제하거나 덮어쓰지 않고 이 정정 기록을 추가합니다.

@my-reviewer-agent my-reviewer-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

검토 범위에서 보고할 이슈가 없습니다.

리뷰 범위: 변경사항 일부만 검토했습니다.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants