Virtual Network
Azure Virtual Network (VNet) is a regional private network in which Azure resources get private addresses. The Azure Enterprise Baseline builds every network of the landing zone from one module: the hub in acme-core-network, one spoke per plat stage, and the runner network in acme-core-auto.
What it does
A virtual network has an address space and is divided into subnets, which span every availability zone of the region. A subnet can be delegated to a service that injects its own resources into it (Container Apps environments, Databricks workspaces, the DNS resolver), can carry service endpoints that keep traffic to a platform service such as Storage or Key Vault on the Azure backbone, and can have a network security group (NSG) of stateful allow and deny rules. Azure's managed services expect subnets with exact reserved names, such as AzureFirewallSubnet and GatewaySubnet.
How BuiltForProd uses it
Three units share modules/virtual-network, and every range comes from the address plan vnet_map.yaml through the ipam unit (see Azure Virtual Network Manager):
| Network | Unit | Subscription | Subnets |
|---|---|---|---|
acme-eus2-network-vnet | vnet-hub | acme-core-network | AzureFirewallSubnet, AzureFirewallManagementSubnet, GatewaySubnet, snet-dns-inbound, snet-dns-outbound, snet-endpoints, AzureBastionSubnet |
acme-eus2-<stage>-vnet | vnet-spoke | each plat subscription | snet-aks, snet-endpoints, snet-ingress, snet-pls, snet-aca, snet-dbx-host, snet-dbx-container, snet-data |
acme-eus2-auto-runner-vnet | vnet-runner | acme-core-auto | snet-aca-runners, snet-endpoints |
Each stage spoke is a /16, with the cluster nodes in snet-aks (/18), private endpoints in snet-endpoints, the internal ingress load balancer in snet-ingress, the Private Link Service addresses in snet-pls, and three delegated subnets: snet-aca for Container Apps and snet-dbx-host and snet-dbx-container for Databricks. The hub's AzureBastionSubnet is reserved address space with nothing deployed in it.
prod:
primary_cidr: 10.0.0.0/16
subnets:
snet-aks: { cidr: 10.0.0.0/18 }
snet-endpoints: { cidr: 10.0.64.0/22 }
snet-ingress: { cidr: 10.0.68.0/24 }
snet-pls: { cidr: 10.0.69.0/26 }
snet-aca: { cidr: 10.0.72.0/23, delegation: Microsoft.App/environments }
snet-dbx-host: { cidr: 10.0.80.0/21, delegation: Microsoft.Databricks/workspaces }
snet-dbx-container: { cidr: 10.0.88.0/21, delegation: Microsoft.Databricks/workspaces }
snet-data: { cidr: 10.0.96.0/22 }
The same baseline on every network.
- No public subnets. Every workload subnet has
default_outbound_access_enabled = false, so it reaches the internet only through the hub firewall or, in the spoke NAT egress mode, its own NAT gateway. - One NSG per subnet (
<prefix>-<subnet>-nsg, except the Azure-managed subnets) with aDenyInternetInboundrule at priority 4000; traffic from the VNet, the peering, the firewall and load balancers keeps Azure's default rules. The spoke'ssnet-ingressadds one allow rule at priority 200 for TCP 443 from theAzureFrontDoor.Backendservice tag, the path of the dev stage's public origin. NSG event and rule-counter logs go to the audit workspace. - Service endpoints, which are free: Storage, Key Vault and Container Registry on
snet-aks,snet-acaandsnet-aca-runners; Storage and Key Vault on the Databricks subnets. Data stores use private endpoints insnet-endpoints, where network policies are on so NSGs and routes apply to them. - VNet flow logs to the regional audit storage through Network Watcher, and the DDoS Network Protection plan when
enable_ddos_protectionis on. - A
CanNotDeletelock on each network's resource group.
The hub uses the DNS Private Resolver's inbound address as its DNS server; the spokes and the runner network keep Azure-provided DNS, which resolves the central private zones they are linked to. The two blueprint infrastructure identities hold Network Contributor on the hub's resource group, so they can create peerings and private endpoints there without a hand-off step. Two guard scripts, check-no-hardcoded-cidrs.py and check-vnet-maps.py, run in pre-commit and CI so that no address is written anywhere but the map.
Terms you will see
| Term | Meaning |
|---|---|
| Hub | The shared network in acme-core-network with the firewall, gateway and resolver. |
| Spoke | A stage's own network in its plat subscription, peered with the hub. |
| Subnet delegation | A subnet handed to one Azure service that injects its resources there. |
| Network security group | The stateful allow and deny rules attached to a subnet. |
| Service endpoint | A subnet setting that sends traffic for a platform service over the backbone. |
| Service tag | A Microsoft-maintained name for a service's address ranges, such as AzureFrontDoor.Backend. |
Where to read more
- Azure Enterprise Baseline overview for the network subscriptions.
- Virtual network peering and route tables for how the spokes reach the hub.
- Hub-and-spoke networking for the pattern behind the layout.