Azure Virtual Network Manager
Azure Virtual Network Manager manages virtual networks across subscriptions, including IP address management (IPAM) pools that track which ranges are in use. In the Azure Enterprise Baseline the address plan lives in one YAML file, and Virtual Network Manager is an optional mirror of it.
What it does
A network manager is scoped to management groups or subscriptions and offers several features: connectivity and security admin configurations, routing, and IPAM. IPAM organizes address space in pools that nest (an organization pool, region pools beneath it, and so on); a static CIDR in a pool records a range that is already allocated, and a virtual network can also draw its range from a pool. The service is billed per managed subscription-hour once a configuration is active.
How BuiltForProd uses it
The plan is a file. vnet_map.yaml is the only place a CIDR is written. It nests the organization range (10.0.0.0/8), a /12 per region, a /13 for the plat subscriptions and a /14 for the core subscriptions, then a primary range and purpose-named subnets per virtual network, and it reserves the ranges that are never routed:
organization_cidr: 10.0.0.0/8
reserved:
aks_pod_cidr: 192.168.0.0/16 # Azure CNI Overlay pod range, per cluster, not routable
aks_service_cidr: 172.20.0.0/16 # Kubernetes service range, per cluster
aks_dns_service_ip: 172.20.0.10
client_vpn_pools: # point-to-site address pools per access profile (outside the organization CIDR)
all: 172.16.0.0/23
plat_all: 172.16.2.0/24
lower: 172.16.3.0/24
dev_sandbox: 172.16.4.0/23
vnet_map:
"region 0":
azure_region: eastus2
region_slug: eus2
cidr: 10.0.0.0/12
plat:
cidr: 10.0.0.0/13
vnet_map_compact.yaml holds the same regions, networks and subnet names in a /11, leaving the rest of 10.0.0.0/8 free for acquisitions, on-premises ranges or peering. The vnet_map_file setting in the ipam unit picks one map, once, before the first deployment: every range differs between them, so switching later replaces every network.
The ipam unit publishes it. It runs once, in acme-core-network's global folder. It reads the chosen map, discovers the live regions from the region.hcl files of the environment tree, and publishes typed outputs that every network unit reads: the ranges and subnets of each network, the organization, region, plat and core ranges, the reserved ranges and the DNS resolver's inbound address. A plan fails when the folders and the map disagree, such as a region without a map entry or without a hub. Adding a region means adding its folders and its map entry; the unit itself needs no edit. Two guard scripts, check-vnet-maps.py and check-no-hardcoded-cidrs.py, check the maps and the code in pre-commit and CI.
The mirror is optional. enable_avnm_ipam in the unit, off by default, creates a network manager scoped to mg-acme, an organization pool, one pool per region and one per plat and core range, and a static CIDR for every network. It deploys IPAM only, with no connectivity, security admin or routing configuration, and nothing allocates from the pools: they show the plan in the portal. The unit comment lists about $0.10 per managed subscription-hour with an active configuration.
The ranges outside the organization range are reserved: 192.168.0.0/16 for the AKS pod overlay and 172.20.0.0/16 for Kubernetes services in every cluster, and four point-to-site VPN pools in 172.16.0.0/16. The second region block in the map is reserved space that no folder uses.
Terms you will see
| Term | Meaning |
|---|---|
| Address plan | vnet_map.yaml, or vnet_map_compact.yaml: the only source of every range. |
| IPAM pool | A Virtual Network Manager range that can hold child pools and static CIDRs. |
| Static CIDR | A range recorded in a pool as already allocated. |
| Reserved range | A range the plan holds outside the organization range and never routes. |
enable_avnm_ipam | The ipam unit switch that mirrors the plan into IPAM pools. |
Where to read more
- Azure Enterprise Baseline overview for the network subscriptions.
- Virtual Network for the networks built from the plan.
- Infrastructure as code for why one file feeds every unit.