Skip to main content

Azure Virtual Network Manager

Azure Virtual Network Manager manages virtual networks across subscriptions, including IP address management (IPAM) pools that track which ranges are in use. In the Azure Enterprise Baseline the address plan lives in one YAML file, and Virtual Network Manager is an optional mirror of it.

What it does​

A network manager is scoped to management groups or subscriptions and offers several features: connectivity and security admin configurations, routing, and IPAM. IPAM organizes address space in pools that nest (an organization pool, region pools beneath it, and so on); a static CIDR in a pool records a range that is already allocated, and a virtual network can also draw its range from a pool. The service is billed per managed subscription-hour once a configuration is active.

How BuiltForProd uses it​

The plan is a file. vnet_map.yaml is the only place a CIDR is written. It nests the organization range (10.0.0.0/8), a /12 per region, a /13 for the plat subscriptions and a /14 for the core subscriptions, then a primary range and purpose-named subnets per virtual network, and it reserves the ranges that are never routed:

Azure/acme-azure-platform-baseline/vnet_map.yaml (lines 19-37)
organization_cidr: 10.0.0.0/8

reserved:
aks_pod_cidr: 192.168.0.0/16 # Azure CNI Overlay pod range, per cluster, not routable
aks_service_cidr: 172.20.0.0/16 # Kubernetes service range, per cluster
aks_dns_service_ip: 172.20.0.10
client_vpn_pools: # point-to-site address pools per access profile (outside the organization CIDR)
all: 172.16.0.0/23
plat_all: 172.16.2.0/24
lower: 172.16.3.0/24
dev_sandbox: 172.16.4.0/23

vnet_map:
"region 0":
azure_region: eastus2
region_slug: eus2
cidr: 10.0.0.0/12
plat:
cidr: 10.0.0.0/13

vnet_map_compact.yaml holds the same regions, networks and subnet names in a /11, leaving the rest of 10.0.0.0/8 free for acquisitions, on-premises ranges or peering. The vnet_map_file setting in the ipam unit picks one map, once, before the first deployment: every range differs between them, so switching later replaces every network.

The ipam unit publishes it. It runs once, in acme-core-network's global folder. It reads the chosen map, discovers the live regions from the region.hcl files of the environment tree, and publishes typed outputs that every network unit reads: the ranges and subnets of each network, the organization, region, plat and core ranges, the reserved ranges and the DNS resolver's inbound address. A plan fails when the folders and the map disagree, such as a region without a map entry or without a hub. Adding a region means adding its folders and its map entry; the unit itself needs no edit. Two guard scripts, check-vnet-maps.py and check-no-hardcoded-cidrs.py, check the maps and the code in pre-commit and CI.

The mirror is optional. enable_avnm_ipam in the unit, off by default, creates a network manager scoped to mg-acme, an organization pool, one pool per region and one per plat and core range, and a static CIDR for every network. It deploys IPAM only, with no connectivity, security admin or routing configuration, and nothing allocates from the pools: they show the plan in the portal. The unit comment lists about $0.10 per managed subscription-hour with an active configuration.

The ranges outside the organization range are reserved: 192.168.0.0/16 for the AKS pod overlay and 172.20.0.0/16 for Kubernetes services in every cluster, and four point-to-site VPN pools in 172.16.0.0/16. The second region block in the map is reserved space that no folder uses.

Terms you will see​

TermMeaning
Address planvnet_map.yaml, or vnet_map_compact.yaml: the only source of every range.
IPAM poolA Virtual Network Manager range that can hold child pools and static CIDRs.
Static CIDRA range recorded in a pool as already allocated.
Reserved rangeA range the plan holds outside the organization range and never routes.
enable_avnm_ipamThe ipam unit switch that mirrors the plan into IPAM pools.

Where to read more​