Skip to main content

Virtual Network

Azure Virtual Network (VNet) is a regional private network in which Azure resources get private addresses. The Azure Enterprise Baseline builds every network of the landing zone from one module: the hub in acme-core-network, one spoke per plat stage, and the runner network in acme-core-auto.

What it does​

A virtual network has an address space and is divided into subnets, which span every availability zone of the region. A subnet can be delegated to a service that injects its own resources into it (Container Apps environments, Databricks workspaces, the DNS resolver), can carry service endpoints that keep traffic to a platform service such as Storage or Key Vault on the Azure backbone, and can have a network security group (NSG) of stateful allow and deny rules. Azure's managed services expect subnets with exact reserved names, such as AzureFirewallSubnet and GatewaySubnet.

How BuiltForProd uses it​

Three units share modules/virtual-network, and every range comes from the address plan vnet_map.yaml through the ipam unit (see Azure Virtual Network Manager):

NetworkUnitSubscriptionSubnets
acme-eus2-network-vnetvnet-hubacme-core-networkAzureFirewallSubnet, AzureFirewallManagementSubnet, GatewaySubnet, snet-dns-inbound, snet-dns-outbound, snet-endpoints, AzureBastionSubnet
acme-eus2-<stage>-vnetvnet-spokeeach plat subscriptionsnet-aks, snet-endpoints, snet-ingress, snet-pls, snet-aca, snet-dbx-host, snet-dbx-container, snet-data
acme-eus2-auto-runner-vnetvnet-runneracme-core-autosnet-aca-runners, snet-endpoints

Each stage spoke is a /16, with the cluster nodes in snet-aks (/18), private endpoints in snet-endpoints, the internal ingress load balancer in snet-ingress, the Private Link Service addresses in snet-pls, and three delegated subnets: snet-aca for Container Apps and snet-dbx-host and snet-dbx-container for Databricks. The hub's AzureBastionSubnet is reserved address space with nothing deployed in it.

Azure/acme-azure-platform-baseline/vnet_map.yaml (lines 38-48)
prod:
primary_cidr: 10.0.0.0/16
subnets:
snet-aks: { cidr: 10.0.0.0/18 }
snet-endpoints: { cidr: 10.0.64.0/22 }
snet-ingress: { cidr: 10.0.68.0/24 }
snet-pls: { cidr: 10.0.69.0/26 }
snet-aca: { cidr: 10.0.72.0/23, delegation: Microsoft.App/environments }
snet-dbx-host: { cidr: 10.0.80.0/21, delegation: Microsoft.Databricks/workspaces }
snet-dbx-container: { cidr: 10.0.88.0/21, delegation: Microsoft.Databricks/workspaces }
snet-data: { cidr: 10.0.96.0/22 }

The same baseline on every network.

  • No public subnets. Every workload subnet has default_outbound_access_enabled = false, so it reaches the internet only through the hub firewall or, in the spoke NAT egress mode, its own NAT gateway.
  • One NSG per subnet (<prefix>-<subnet>-nsg, except the Azure-managed subnets) with a DenyInternetInbound rule at priority 4000; traffic from the VNet, the peering, the firewall and load balancers keeps Azure's default rules. The spoke's snet-ingress adds one allow rule at priority 200 for TCP 443 from the AzureFrontDoor.Backend service tag, the path of the dev stage's public origin. NSG event and rule-counter logs go to the audit workspace.
  • Service endpoints, which are free: Storage, Key Vault and Container Registry on snet-aks, snet-aca and snet-aca-runners; Storage and Key Vault on the Databricks subnets. Data stores use private endpoints in snet-endpoints, where network policies are on so NSGs and routes apply to them.
  • VNet flow logs to the regional audit storage through Network Watcher, and the DDoS Network Protection plan when enable_ddos_protection is on.
  • A CanNotDelete lock on each network's resource group.

The hub uses the DNS Private Resolver's inbound address as its DNS server; the spokes and the runner network keep Azure-provided DNS, which resolves the central private zones they are linked to. The two blueprint infrastructure identities hold Network Contributor on the hub's resource group, so they can create peerings and private endpoints there without a hand-off step. Two guard scripts, check-no-hardcoded-cidrs.py and check-vnet-maps.py, run in pre-commit and CI so that no address is written anywhere but the map.

Terms you will see​

TermMeaning
HubThe shared network in acme-core-network with the firewall, gateway and resolver.
SpokeA stage's own network in its plat subscription, peered with the hub.
Subnet delegationA subnet handed to one Azure service that injects its resources there.
Network security groupThe stateful allow and deny rules attached to a subnet.
Service endpointA subnet setting that sends traffic for a platform service over the backbone.
Service tagA Microsoft-maintained name for a service's address ranges, such as AzureFrontDoor.Backend.

Where to read more​