Reviewed commit: be11bdcb5 (origin/main), from the 2026-07-28 full-repo review.
Severity: HIGH. Every non-USD tenant either cannot buy an Azure Savings Plan, or buys a different commitment level than the one approved.
Where
providers/azure/services/savingsplans/client.go:261 (purchase) and :355 (validate)
What
The armbillingbenefits.Commitment sent to the OrderAlias API always carries CurrencyCode: toPtr("USD"), with Amount taken verbatim from spDetails.HourlyCommitment.
Azure requires the commitment currency to match the billing account's currency. Nothing in the provider reads or validates it, and common.Recommendation carries no currency at all.
Failure scenario
A EUR-billed MCA subscription whose recommendation says EUR 12.00/hr. The alias is created with {Amount: 12.00, CurrencyCode: "USD"}.
Either Azure rejects it, which is a silent purchase failure for every non-USD tenant, or Azure accepts it as a $12.00/hr commitment: a different real commitment level than the one approved, and one that a USD-denominated MaxPurchaseAmount cap was never checked against in the right units.
Fix direction
Resolve the billing account currency (or thread a currency through the recommendation) and fail closed when it is unknown or does not match, rather than asserting USD.
Related
Same class as PR LeanerCloud/cloud-commitments-cli#1515's MaxPurchaseAmount currency rule and LeanerCloud/cloud-commitments-cli#1087 (AWS Savings Plans purchase path is USD-only), but a distinct provider and call site.
Reviewed commit:
be11bdcb5(origin/main), from the 2026-07-28 full-repo review.Severity: HIGH. Every non-USD tenant either cannot buy an Azure Savings Plan, or buys a different commitment level than the one approved.
Where
providers/azure/services/savingsplans/client.go:261(purchase) and:355(validate)What
The
armbillingbenefits.Commitmentsent to the OrderAlias API always carriesCurrencyCode: toPtr("USD"), withAmounttaken verbatim fromspDetails.HourlyCommitment.Azure requires the commitment currency to match the billing account's currency. Nothing in the provider reads or validates it, and
common.Recommendationcarries no currency at all.Failure scenario
A EUR-billed MCA subscription whose recommendation says EUR 12.00/hr. The alias is created with
{Amount: 12.00, CurrencyCode: "USD"}.Either Azure rejects it, which is a silent purchase failure for every non-USD tenant, or Azure accepts it as a $12.00/hr commitment: a different real commitment level than the one approved, and one that a USD-denominated
MaxPurchaseAmountcap was never checked against in the right units.Fix direction
Resolve the billing account currency (or thread a currency through the recommendation) and fail closed when it is unknown or does not match, rather than asserting USD.
Related
Same class as PR LeanerCloud/cloud-commitments-cli#1515's
MaxPurchaseAmountcurrency rule and LeanerCloud/cloud-commitments-cli#1087 (AWS Savings Plans purchase path is USD-only), but a distinct provider and call site.