This module is used to manage Azure Virtual Networks, Subnets and Peerings, with optional IPAM (IP Address Management) support.
This module is composite and includes sub modules that can be used independently for pre-existing virtual networks. These sub modules are:
- subnet - The subnet module is used to manage subnets within a virtual network.
- peering - The peering module is used to manage virtual network peerings.
This module supports managing virtual networks and their associated subnets and peerings together or independently.
The module supports:
- Creating a new virtual network
- Creating a new subnet
- Creating a new virtual network peering
- Associating DNS servers with a virtual network
- Associating a DDOS protection plan with a virtual network
- Associating a network security group with a subnet
- Associating a route table with a subnet
- Associating a service endpoint with a subnet
- Associating a virtual network gateway with a subnet
- Assigning delegations to subnets
- IPAM pool allocation for virtual network address space
- IPAM pool allocation for individual subnets
- Choice of IPAM or traditional static addressing per virtual network
This module provides comprehensive IPAM (IP Address Management) support through Azure Virtual Network Manager IPAM pools.
- VNet address space allocation from centralized IPAM pools
- Subnet address allocation from IPAM pools
- Dual-stack support - one IPv4 pool and one IPv6 pool per virtual network
- All standard subnet features work with IPAM subnets (NSGs, service endpoints, delegations, etc.)
- Centralized IP governance through Azure Network Manager
- Automatic conflict prevention during address allocation
- Simplified address management across multiple deployments
chilecentral, jioindiawest, malaysiawest, qatarcentral, southafricawest, westindia, westus3
Note: IPAM is available in all other regions where Azure Virtual Network Manager is supported. For the most up-to-date regional availability, consult the Azure products by region page.
- ipam_basic - Complete IPAM usage with VNet and multiple subnets
- existing_vnet_ipam_subnets - Adding IPAM subnets to existing VNet managed by IPAM
- ipam_vnet_only - IPAM VNet creation without subnets
Address space is requested from an IPAM pool as a single allocation per pool. The following are enforced by the Azure Resource Provider (they are platform rules, not module limitations):
| Rule | Detail |
|---|---|
| One pool per IP type | At most one IPv4 pool and one IPv6 pool per virtual network. |
| No duplicate pools | The same pool cannot be referenced more than once on a VNet or subnet. |
| No IPAM + static mix | A virtual network uses either IPAM pools or a static address_space, not both. |
| Subnet pools are a subset | A subnet may only reference pools that its virtual network already uses. |
Sizing: set the size on the single pool entry using either number_of_ip_addresses (for example "256") or prefix_length (for example 24). To request more address space from a pool, increase that value - do not add a second entry for the same pool.
Resolved prefixes (summarization vs. fragmentation): Azure resolves one allocation into one or more CIDR blocks. Contiguous free space is summarized into a single larger prefix (for example two /21 worth of space surface as one /20); fragmented free space is returned as multiple non-adjacent prefixes (for example a single allocation may surface as /25 + /28). This is why one pool can show a varying number of address prefixes. The module exposes these resolved prefixes as a read-only output, so summarization or fragmentation does not cause Terraform drift.
Some Azure controllers modify subnet properties out-of-band - outside Terraform - after the subnet is created. The most common case is Azure Virtual Network Manager (AVNM) routing configurations (or Azure Policy DeployIfNotExists) attaching a managed route table to a subnet. On the next terraform plan the module sees the externally-added routeTable and tries to revert it to the configured value (null), producing perpetual drift and fighting the external controller on every apply.
The module implements the AVM ignore_body_changes interface (TFFR8). It maps to the azapi provider's write-only ignore_body_changes argument: the listed body paths are ignored after create, so the external controller can own them without drift.
There are two ways to set it, and they compose:
- Per subnet (most common): set
ignore_body_changeson an individual entry of thesubnetsmap. This takes precedence over the module-wide value for that subnet. - Module-wide / other resources: the root
ignore_body_changesobject is keyed by resource type (the same snake_case key an AzAPIresource_typesmap uses).virtual_networkstargets the virtual network itself,virtual_networks_subnetsapplies to every subnet, andvirtual_networks_virtual_network_peeringsapplies to every peering.
module "vnet" {
source = "Azure/avm-res-network-virtualnetwork/azurerm"
# ... version, name, location, parent_id, address_space ...
subnets = {
workload = {
name = "snet-workload"
address_prefixes = ["10.0.1.0/24"]
# Per-subnet: let AVNM / Azure Policy own the route table association
# out-of-band. Do NOT also set route_table on this subnet (see note below).
ignore_body_changes = ["properties.routeTable"]
}
}
# Module-wide equivalents (applied to every subnet / the vnet itself):
ignore_body_changes = {
virtual_networks = ["tags"] # e.g. tags applied by Azure Policy
virtual_networks_subnets = {
virtual_networks_subnets = ["properties.routeTable"]
}
}
}Supported paths. Any body property expressed in dot notation, for example properties.routeTable or the top-level tags. The provider ignores whichever paths you list; it does not restrict them to a fixed set, so newer properties work without a module change. Commonly used subnet paths:
| Path | Property |
|---|---|
properties.routeTable |
Route table association (AVNM routing / Policy DINE) - the canonical case |
properties.networkSecurityGroup |
Network security group association |
properties.serviceEndpoints |
Service endpoints |
properties.delegations |
Subnet delegations |
Important - don't manage the same property twice. Several of these properties are also settable through dedicated inputs (route_table, network_security_group, service_endpoints, delegations). When you ignore a path so an external controller can own it, leave the corresponding input unset. Setting the input and ignoring the path means the module renders a value the provider is told to ignore - confusing and self-defeating.
Behaviour and requirements.
- Paths use dot notation. Individual list items cannot be targeted - ignore the whole list property. Each entry must be a non-empty string; blank entries are rejected with a validation error.
ignore_body_changesis a write-only argument (stored in provider-private state). Supplying a non-empty value requires Terraform >= 1.11 and AzAPI >= 2.12. Changes to the list take effect only after anapply.- Because empty lists collapse to no argument, the default (nothing ignored) keeps the module usable on Terraform < 1.11 - existing configurations are unaffected.
- While a path is ignored, configuration changes at that path are not sent to Azure until you remove the path from the list.
- Azure Virtual Network Manager: Required for all IPAM functionality
- Supported Azure region: IPAM must be available in your target region (see Regional Support)
- azapi provider: Version ~> 2.12 required for IPAM resource management
- Proper permissions: Network Manager and IPAM pool management permissions
Version 0.2.0 rewrote the module from azurerm resources to azapi resources and changed the state layout without shipping moved blocks. Current tooling can bridge the resource-type changes: Terraform v1.8.0 added provider-supported moves between resource types, and AzAPI v2.1.0 added moves from azurerm resources to azapi_resource. This module requires Terraform >= 1.9, < 2.0 and AzAPI ~> 2.12. The addresses below were verified against Terraform's move validation and AzAPI's cross-type state conversion using a synthetic v0.1.x state, but the migration has not been applied end to end against a real v0.1.3 deployment. Back up the state first, treat the addresses below as templates, and verify them against terraform state list.
Write the moved blocks in the root configuration that calls this module, not in the module source. Replace module.vnet with the actual module address and repeat the keyed blocks for every subnet and peering. The current configuration must use the existing Azure resource names: set each subnet name to its old map key and each peering name to the old generated value peering-<key>.
moved {
from = module.vnet.azurerm_virtual_network.vnet
to = module.vnet.azapi_resource.vnet
}
moved {
from = module.vnet.azurerm_subnet.subnet["subnet_key"]
to = module.vnet.module.subnet["subnet_key"].azapi_resource.subnet
}
moved {
from = module.vnet.azurerm_virtual_network_peering.vnet_peering["peering_key"]
to = module.vnet.module.peering["peering_key"].azapi_resource.this[0]
}The static subnet destination is deliberately unindexed. The subnet submodule already declares moved { from = azapi_resource.subnet, to = azapi_resource.subnet[0] } for the v0.15.0 IPAM change, and Terraform rejects two statements that move into the same instance with an Ambiguous move statements error. Targeting the unindexed address lets Terraform chain the two moves. If the target subnet uses ipam_pools, target module.vnet.module.subnet["subnet_key"].azapi_resource.subnet_ipam[0] instead; that address is indexed because no such chained move exists for it. The peering destination is for the full-virtual-network peering used by v0.1.x and selected by the current default peer_complete_vnets = true.
These v0.1.x resources have no destination address because v0.2.0 folded them into the virtual network or subnet body. Configure the equivalent current input first, then use terraform state rm for each address that exists:
| State address | Equivalent current configuration |
|---|---|
module.vnet.azurerm_virtual_network_dns_servers.vnet_dns[0] |
dns_servers on the virtual network |
module.vnet.azurerm_subnet_network_security_group_association.vnet["subnet_key"] |
subnets["subnet_key"].network_security_group |
module.vnet.azurerm_subnet_route_table_association.vnet["subnet_key"] |
subnets["subnet_key"].route_table |
module.vnet.azurerm_subnet_nat_gateway_association.nat_gw["subnet_key"] |
subnets["subnet_key"].nat_gateway |
Do not remove an association from state until the current subnet configuration contains the same NSG, route table, or NAT gateway ID. Otherwise, a later subnet update can remove that association from Azure.
AzAPI's cross-type state conversion initializes id, name, parent_id, and type, but not body. The first plan after adding the moves therefore shows the configured body being reconciled; this is expected. Review and adjust the configuration until the plan contains only the expected state moves and in-place updates.
Never apply a plan that replaces the virtual network, subnets, or peerings. After applying the reviewed in-place migration, run terraform plan again and iterate until it reports no changes. If a non-replacing plan cannot be established, importing the existing resources into a fresh configuration and state remains the conservative alternative.
Later releases introduced these additional breaking changes:
| Version | Breaking change |
|---|---|
| v0.11.0 | Removed resource_group_name and subscription_id; supply the resource group resource ID with parent_id. |
| v0.12.0 | Removed the retry options multiplier and randomization_factor, including nested subnet and peering retry objects. |
| v0.15.0 | Removed service_endpoints in favor of service_endpoints_with_location, and required a moved block for existing IPAM subnets. Reversed in v0.20.0: service_endpoints is supported again with names only, while service_endpoints_with_location now raises a validation error. |
| v0.19.0 | Moved locks, role assignments, and diagnostic settings from azurerm to azapi. Locks and diagnostic settings migrate through moved blocks; role assignments are recreated once. |
Use GitHub Releases as the authoritative changelog for all versions.
To use this module in your Terraform configuration, you'll need to provide values for the required variables.
This example shows the most basic usage of the module. It creates a new virtual network with subnets using traditional static addressing.
module "avm-res-network-virtualnetwork" {
source = "Azure/avm-res-network-virtualnetwork/azurerm"
address_space = ["10.0.0.0/16"]
location = "eastus2"
name = "vnet-demo-eastus2-001"
parent_id = "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-demo-eastus2-001"
subnets = {
"subnet1" = {
name = "subnet1"
address_prefixes = ["10.0.0.0/24"]
}
"subnet2" = {
name = "subnet2"
address_prefixes = ["10.0.1.0/24"]
}
}
}This example demonstrates IPAM usage with both VNet and subnet address allocation from IPAM pools.
module "avm-res-network-virtualnetwork" {
source = "Azure/avm-res-network-virtualnetwork/azurerm"
location = "East US"
name = "myIPAMVNet"
parent_id = "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup"
# VNet address space from IPAM pool
ipam_pools = [{
id = azapi_resource.ipam_pool.id
prefix_length = 24
}]
# Multiple subnets allocated from IPAM pool
subnets = {
"web_subnet" = {
name = "subnet-web"
ipam_pools = [{
pool_id = azapi_resource.ipam_pool.id
prefix_length = 26
}]
}
"app_subnet" = {
name = "subnet-app"
ipam_pools = [{
pool_id = azapi_resource.ipam_pool.id
prefix_length = 26
}]
}
"data_subnet" = {
name = "subnet-data"
ipam_pools = [{
pool_id = azapi_resource.ipam_pool.id
prefix_length = 27
}]
}
}
}This example shows how to create a subnet for a pre-existing virtual network using the subnet module.
module "avm-res-network-subnet" {
source = "Azure/avm-res-network-virtualnetwork/azurerm//modules/subnet"
parent_id = "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Network/virtualNetworks/myVNet"
name = "subnet1"
address_prefixes = ["10.0.0.0/24"]
}- "IPAM subnet creation failed": Ensure parent VNet was created with IPAM pools for its address space
- "Region not supported": Check the IPAM Regional Support section above
- "Network Manager not found": Ensure Azure Virtual Network Manager exists before creating IPAM pools
- "Subnet overlap errors": Module uses retry logic to handle allocation conflicts automatically
- "Pool exhausted": Check that your IPAM pool has sufficient available address space for the requested subnets
CannotHaveDuplicatePoolIds: The same pool is referenced more than once. Use a singleipam_poolsentry and increasenumber_of_ip_addressesinstead of adding duplicate entries.only one association of each IP type is allowed: Only one IPv4 pool and one IPv6 pool are permitted per virtual network. Remove the additional same-family pool.CannotMixAddressPrefixAndPoolInPayload: A virtual network cannot combine IPAM pools with a staticaddress_space. Choose one addressing model.SubnetPoolsMustBeSubsetOfVnetPools: A subnet references a pool that its virtual network does not use. Reference the pool on the VNet first.- A single pool shows multiple or changing address prefixes: Expected behavior. One allocation is resolved into one or more CIDRs (summarized when contiguous, split when fragmented). These resolved prefixes are read-only and do not cause Terraform drift.
The following requirements are needed by this module:
The following resources are used by this module:
- azapi_resource.diagnostic_settings (resource)
- azapi_resource.lock (resource)
- azapi_resource.role_assignments (resource)
- azapi_resource.vnet (resource)
- modtm_telemetry.telemetry (resource)
- random_uuid.telemetry (resource)
- azapi_client_config.telemetry (data source)
- modtm_module_source.telemetry (data source)
The following input variables are required:
Description: (Optional) The location/region where the virtual network is created. Changing this forces a new resource to be created.
Type: string
Description: (Optional) The ID of the resource group where the virtual network will be deployed.
Type: string
The following input variables are optional (have default values):
Description: (Optional) The address spaces applied to the virtual network. You can supply more than one address space.
Either address_space or ipam_pools must be specified, but not both.
Type: set(string)
Default: null
Description: (Optional) The BGP community to send to the virtual network gateway.
Type: string
Default: null
Description: Specifies an AzureNetwork DDoS Protection Plan.
id: The ID of the DDoS Protection Plan. (Required)enable: Enables or disables the DDoS Protection Plan on the Virtual Network. (Required)
Type:
object({
id = string
enable = bool
})Default: null
Description: A map of diagnostic settings to create on the Key Vault. The map key is deliberately arbitrary to avoid issues where map keys maybe unknown at plan time.
name- (Optional) The name of the diagnostic setting. One will be generated if not set, however this will not be unique if you want to create multiple diagnostic setting resources.log_categories- (Optional) A set of log categories to send to the log analytics workspace. Defaults to[].log_groups- (Optional) A set of log groups to send to the log analytics workspace. Defaults to["allLogs"].metric_categories- (Optional) A set of metric categories to send to the log analytics workspace. Defaults to["AllMetrics"].log_analytics_destination_type- (Optional) The destination type for the diagnostic setting. Possible values areDedicatedandAzureDiagnostics. Defaults toDedicated.workspace_resource_id- (Optional) The resource ID of the log analytics workspace to send logs and metrics to.storage_account_resource_id- (Optional) The resource ID of the storage account to send logs and metrics to.event_hub_authorization_rule_resource_id- (Optional) The resource ID of the event hub authorization rule to send logs and metrics to.event_hub_name- (Optional) The name of the event hub. If none is specified, the default event hub will be selected.marketplace_partner_resource_id- (Optional) The full ARM resource ID of the Marketplace resource to which you would like to send Diagnostic LogsLogs.
Type:
map(object({
name = optional(string, null)
log_categories = optional(set(string), [])
log_groups = optional(set(string), ["allLogs"])
metric_categories = optional(set(string), ["AllMetrics"])
log_analytics_destination_type = optional(string, "Dedicated")
workspace_resource_id = optional(string, null)
storage_account_resource_id = optional(string, null)
event_hub_authorization_rule_resource_id = optional(string, null)
event_hub_name = optional(string, null)
marketplace_partner_resource_id = optional(string, null)
}))Default: {}
Description: (Optional) Specifies a list of IP addresses representing DNS servers.
dns_servers: List of IP addresses of DNS servers.
Type:
object({
dns_servers = list(string)
})Default: null
Description: This variable controls whether or not telemetry is enabled for the module.
For more information see https://aka.ms/avm/telemetryinfo.
If it is set to false, then no telemetry will be collected.
Type: bool
Default: true
Description: (Optional) Enable VM Protection for the virtual network. Defaults to false.
Type: bool
Default: false
Description: (Optional) Specifies the encryption settings for the virtual network.
enabled: Specifies whether encryption is enabled for the virtual network.enforcement: Specifies the enforcement mode for the virtual network. Possible values areAllowUnencryptedandDropUnencrypted.
Note: When using DropUnencrypted enforcement, the AllowDropUnecryptedVnet subscription feature must be registered first. See the vnet-encryption-setup example for details.
Type:
object({
enabled = bool
enforcement = string
})Default: null
Description: (Optional) Specifies the extended location of the virtual network.
name: The name of the extended location.type: The type of the extended location.
Type:
object({
name = string
type = string
})Default: null
Description: (Optional) The flow timeout in minutes for the virtual network. Defaults to 4.
Type: number
Default: null
Description: (Optional) Paths in each resource's body whose changes the azapi provider ignores after creation, letting an out-of-band controller own those properties without producing perpetual terraform plan drift. Prefer Terraform's lifecycle.ignore_changes when the paths are static; use this variable when the paths must be derived from variables or other non-static values.
Keys follow the same naming rule as an AzAPI resource_types map (the snake_case ARM resource type with the Microsoft. prefix dropped), scoped per resource and per submodule:
virtual_networks- Ignored body paths for the virtual network managed by this module (for example["tags"]when Azure Policy applies tags out-of-band).virtual_networks_subnets- Override slot for the subnet submodule. Supply only the keys you want to override.virtual_networks_subnets- Ignored body paths applied to every subnet, for example["properties.routeTable"]for the AVNMManagedOnlyrouting / Azure Policy DINE scenario. A per-subnetignore_body_changesentry in thesubnetsmap takes precedence over this shared value.
virtual_networks_virtual_network_peerings- Override slot for the peering submodule.virtual_networks_virtual_network_peerings- Ignored body paths applied to every peering resource.
Paths use dot notation, for example properties.routeTable or the top-level tags. Individual list items cannot be targeted; ignore the whole list property instead. While a path is ignored, configuration changes at that path are not sent to Azure until the path is removed from the list.
Important: several subnet properties are also settable through dedicated inputs (for example route_table, network_security_group, service_endpoints, delegations). When you ignore a path so an out-of-band controller can own it, leave the corresponding input unset - do not manage the same property from both places.
Supplying a non-empty value requires Terraform 1.11 or later, because ignore_body_changes is a write-only argument held in provider-private state; changes take effect only after an apply. Leaving every list empty (the default) emits no argument, so the module remains usable on earlier Terraform versions.
Type:
object({
virtual_networks = optional(list(string), [])
virtual_networks_subnets = optional(object({
virtual_networks_subnets = optional(list(string), [])
}), {})
virtual_networks_virtual_network_peerings = optional(object({
virtual_networks_virtual_network_peerings = optional(list(string), [])
}), {})
})Default: {}
Description: (Optional) Specifies the IPAM settings for requesting an address_space from an IP Pool. Only one IPv4 and one IPv6 pool can be specified.
id: The ID of the IPAM pool.number_of_ip_addresses: (Optional) The number of IP addresses to request from the IPAM pool. If not specified, it will be calculated based on theprefix_length.prefix_length: (Optional) The length of the /XX CIDR range to request. for example 24 for a /24. Prefix length must be between 2 and 29 for IPv4 and 48 and 64 for IPv6.
Type:
list(object({
id = string
number_of_ip_addresses = optional(string)
prefix_length = optional(number)
}))Default: null
Description: (Optional) Controls the Resource Lock configuration for this resource. The following properties can be specified:
kind- (Required) The type of lock. Possible values are\"CanNotDelete\"and\"ReadOnly\".name- (Optional) The name of the lock. If not specified, a name will be generated based on thekindvalue. Changing this forces the creation of a new resource.
Type:
object({
kind = string
name = optional(string, null)
})Default: null
Description: (Optional) The name of the virtual network to create. If null, existing_virtual_network must be supplied.
Type: string
Default: null
Description: (Optional) A map of virtual network peering configurations. Each entry specifies a remote virtual network by ID and includes settings for traffic forwarding, gateway transit, and remote gateways usage.
name: The name of the virtual network peering configuration.remote_virtual_network_resource_id: The resource ID of the remote virtual network.allow_forwarded_traffic: (Optional) Enables forwarded traffic between the virtual networks. Defaults to false.allow_gateway_transit: (Optional) Enables gateway transit for the virtual networks. Defaults to false.allow_virtual_network_access: (Optional) Enables access from the local virtual network to the remote virtual network. Defaults to true.do_not_verify_remote_gateways: (Optional) Disables the verification of remote gateways for the virtual networks. Defaults to false.enable_only_ipv6_peering: (Optional) Enables only IPv6 peering for the virtual networks. Defaults to false.peer_complete_vnets: (Optional) Enables the peering of complete virtual networks for the virtual networks. Defaults to true.local_peered_address_spaces: (Optional) The address spaces to peer with the remote virtual network. Only used whenpeer_complete_vnetsis set to false.remote_peered_address_spaces: (Optional) The address spaces to peer from the remote virtual network. Only used whenpeer_complete_vnetsis set to false.local_peered_subnets: (Optional) The subnets to peer with the remote virtual network. Only used whenpeer_complete_vnetsis set to false.remote_peered_subnets: (Optional) The subnets to peer from the remote virtual network. Only used whenpeer_complete_vnetsis set to false.use_remote_gateways: (Optional) Enables the use of remote gateways for the virtual networks. Defaults to false.create_reverse_peering: (Optional) Creates the reverse peering to form a complete peering.reverse_name: (Optional) If you have selectedcreate_reverse_peering, then this name will be used for the reverse peer.reverse_allow_forwarded_traffic: (Optional) If you have selectedcreate_reverse_peering, enables forwarded traffic between the virtual networks. Defaults to false.reverse_allow_gateway_transit: (Optional) If you have selectedcreate_reverse_peering, enables gateway transit for the virtual networks. Defaults to false.reverse_allow_virtual_network_access: (Optional) If you have selectedcreate_reverse_peering, enables access from the local virtual network to the remote virtual network. Defaults to true.reverse_do_not_verify_remote_gateways: (Optional) If you have selectedcreate_reverse_peering, disables the verification of remote gateways for the virtual networks. Defaults to false.reverse_enable_only_ipv6_peering: (Optional) If you have selectedcreate_reverse_peering, enables only IPv6 peering for the virtual networks. Defaults to false.reverse_peer_complete_vnets: (Optional) If you have selectedcreate_reverse_peering, enables the peering of complete virtual networks for the virtual networks. Defaults to true.reverse_local_peered_address_spaces: (Optional) If you have selectedcreate_reverse_peering, the address spaces to peer with the remote virtual network. Only used whenreverse_peer_complete_vnetsis set to false.reverse_remote_peered_address_spaces: (Optional) If you have selectedcreate_reverse_peering, the address spaces to peer from the remote virtual network. Only used whenreverse_peer_complete_vnetsis set to false.reverse_local_peered_subnets: (Optional) If you have selectedcreate_reverse_peering, the subnets to peer with the remote virtual network. Only used whenreverse_peer_complete_vnetsis set to false.reverse_remote_peered_subnets: (Optional) If you have selectedcreate_reverse_peering, the subnets to peer from the remote virtual network. Only used whenreverse_peer_complete_vnetsis set to false.reverse_use_remote_gateways: (Optional) If you have selectedcreate_reverse_peering, enables the use of remote gateways for the virtual networks. Defaults to false.sync_remote_address_space_enabled: (Optional) If the peering sync status changes a plan will be created to sync the peering address space with an azapi update resource. Defaults to false.sync_remote_address_space_triggers: (Optional) A value that when changed will trigger a resync of the remote address space. This must be supplied ifsync_remote_address_space_enabledistrue. Defaults to null.
timeouts (Optional) supports the following:
create- (Defaults to 30 minutes) Used when creating the Virtual Network Peering.delete- (Defaults to 30 minutes) Used when deleting the Virtual Network Peering.read- (Defaults to 5 minutes) Used when retrieving the Virtual Network Peering.update- (Defaults to 30 minutes) Used when updating the Virtual Network Peering.
retry (Optional) supports the following:
error_message_regex- (Optional) A list of regular expressions to match against the error message returned by the API. If any of these match, the retry will be triggered.interval_seconds- (Optional) The number of seconds to wait between retries. Defaults to 10.max_interval_seconds- (Optional) The maximum number of seconds to wait between retries. Defaults to 180.
Type:
map(object({
name = string
remote_virtual_network_resource_id = string
allow_forwarded_traffic = optional(bool, false)
allow_gateway_transit = optional(bool, false)
allow_virtual_network_access = optional(bool, true)
do_not_verify_remote_gateways = optional(bool, false)
enable_only_ipv6_peering = optional(bool, false)
peer_complete_vnets = optional(bool, true)
local_peered_address_spaces = optional(list(object({
address_prefix = string
})))
remote_peered_address_spaces = optional(list(object({
address_prefix = string
})))
local_peered_subnets = optional(list(object({
subnet_name = string
})))
remote_peered_subnets = optional(list(object({
subnet_name = string
})))
use_remote_gateways = optional(bool, false)
create_reverse_peering = optional(bool, false)
reverse_name = optional(string)
reverse_allow_forwarded_traffic = optional(bool, false)
reverse_allow_gateway_transit = optional(bool, false)
reverse_allow_virtual_network_access = optional(bool, true)
reverse_do_not_verify_remote_gateways = optional(bool, false)
reverse_enable_only_ipv6_peering = optional(bool, false)
reverse_peer_complete_vnets = optional(bool, true)
reverse_local_peered_address_spaces = optional(list(object({
address_prefix = string
})))
reverse_remote_peered_address_spaces = optional(list(object({
address_prefix = string
})))
reverse_local_peered_subnets = optional(list(object({
subnet_name = string
})))
reverse_remote_peered_subnets = optional(list(object({
subnet_name = string
})))
reverse_use_remote_gateways = optional(bool, false)
sync_remote_address_space_enabled = optional(bool, false)
sync_remote_address_space_triggers = optional(any, null)
timeouts = optional(object({
create = optional(string, "30m")
read = optional(string, "5m")
update = optional(string, "30m")
delete = optional(string, "30m")
}), {})
retry = optional(object({
error_message_regex = optional(list(string), ["ReferencedResourceNotProvisioned"])
interval_seconds = optional(number, 10)
max_interval_seconds = optional(number, 180)
}), {})
}))Default: {}
Description: Retry configuration for the resource operations
Type:
object({
error_message_regex = optional(list(string), ["ReferencedResourceNotProvisioned"])
interval_seconds = optional(number, 10)
max_interval_seconds = optional(number, 180)
})Default: {}
Description: (Optional) A map of role assignments to create on the . The map key is deliberately arbitrary to avoid issues where map keys maybe unknown at plan time.
role_definition_id_or_name- The ID or name of the role definition to assign to the principal.principal_id- The ID of the principal to assign the role to.description- (Optional) The description of the role assignment.skip_service_principal_aad_check- (Optional) If set to true, skips the Azure Active Directory check for the service principal in the tenant. Defaults to false.condition- (Optional) The condition which will be used to scope the role assignment.condition_version- (Optional) The version of the condition syntax. Leave asnullif you are not using a condition, if you are then valid values are '2.0'.delegated_managed_identity_resource_id- (Optional) The delegated Azure Resource Id which contains a Managed Identity. Changing this forces a new resource to be created. This field is only used in cross-tenant scenario.principal_type- (Optional) The type of theprincipal_id. Possible values areUser,GroupandServicePrincipal. It is necessary to explicitly set this attribute when creating role assignments if the principal creating the assignment is constrained by ABAC rules that filters on the PrincipalType attribute.
Note: only set
skip_service_principal_aad_checkto true if you are assigning a role to a service principal.
Type:
map(object({
role_definition_id_or_name = string
principal_id = string
description = optional(string, null)
skip_service_principal_aad_check = optional(bool, false)
condition = optional(string, null)
condition_version = optional(string, null)
delegated_managed_identity_resource_id = optional(string, null)
principal_type = optional(string, null)
}))Default: {}
Description: (Optional) A map of subnets to create
address_prefix- (Optional) The address prefix to use for the subnet. One ofaddress_prefix,address_prefixes, oripam_poolsmust be specified.address_prefixes- (Optional) The address prefixes to use for the subnet. One ofaddress_prefix,address_prefixes, oripam_poolsmust be specified.ipam_pools- (Optional) IPAM pools to allocate address space from. When specified, the subnet will request address space from these pools. Each pool configuration supports:pool_id: Resource ID of the IPAM pool to allocate fromnumber_of_ip_addresses: (Optional) The number of IP addresses to request from the IPAM pool. If not specified, it will be calculated based on theprefix_length.prefix_length: (Optional) The CIDR prefix length for this subnet (e.g., 24 for /24, 26 for /26)allocation_type: Type of allocation - "Static" (default) or "Dynamic"
ignore_body_changes- (Optional) A per-subnet list of body property paths (dot notation, relative to the request body) whose changes theazapiprovider should ignore after creation, letting an out-of-band controller own those properties without perpetual drift. This is the per-item override for this subnet and takes precedence over the module-wideignore_body_changes.virtual_networks_subnets.virtual_networks_subnetsvalue. The canonical use case is AVNMManagedOnlyrouting or Azure Policy DINE attaching a route table out-of-band: set["properties.routeTable"]. Other common paths:properties.networkSecurityGroup,properties.serviceEndpoints,properties.delegations; a top-leveltagspath is also valid. Uses dot notation and cannot target individual list items (ignore the whole list). Important: these properties are also settable via dedicated inputs (route_table,network_security_group,service_endpoints,delegations) - when you ignore a path so an external controller can own it, leave the matching input unset so the module and the controller don't fight over it. Supplying a non-empty value is a write-only argument (requires Terraform >= 1.11); changes take effect only after anapply. Defaults to[].enforce_private_link_endpoint_network_policies-enforce_private_link_service_network_policies-name- (Required) The name of the subnet. Changing this forces a new resource to be created.default_outbound_access_enabled- (Optional) Whether to allow internet access from the subnet. Defaults tofalse.private_endpoint_network_policies- (Optional) Enable or Disable network policies for the private endpoint on the subnet. Possible values areDisabled,Enabled,NetworkSecurityGroupEnabledandRouteTableEnabled. Defaults toEnabled. Only applied whenprivate_endpoint_network_policies_enabledistrue.private_endpoint_network_policies_enabled- (Optional) Controls whether theprivateEndpointNetworkPoliciesproperty is sent to Azure for the subnet. Defaults totrue. Set tofalseto omit the property entirely, which is required in regions that do not support it (e.g. South Africa West) because they reject the property outright. Note: unlikeprivate_link_service_network_policies_enabled(wherefalsesendsDisabled), setting this tofalseremoves the property from the request rather than sending a value; to sendDisabled, leave thistrueand setprivate_endpoint_network_policies = "Disabled".private_link_service_network_policies_enabled- (Optional) Enable or Disable network policies for the private link service on the subnet. Setting this totruewill Enable the policy and setting this tofalsewill Disable the policy. Defaults totrue.service_endpoint_policies- (Optional) The map of objects with IDs of Service Endpoint Policies to associate with the subnet.service_endpoints- (Optional) A set of service endpoint names to associate with the subnet, for example["Microsoft.Storage", "Microsoft.Sql"]. Possible values include:Microsoft.AzureActiveDirectory,Microsoft.AzureCosmosDB,Microsoft.ContainerRegistry,Microsoft.EventHub,Microsoft.KeyVault,Microsoft.ServiceBus,Microsoft.Sql,Microsoft.Storage,Microsoft.Storage.GlobalandMicrosoft.Web. Locations are not configurable because Azure implicitly expands service-endpoint locations, which causes perpetual drift.service_endpoints_with_location- Removed. Useservice_endpointsinstead. This attribute is still declared so that setting it fails with an explanatory error rather than being silently discarded; setting it is always an error.
delegation (This setting is deprecated, use delegations instead) supports the following:
name- (Required) A name for this delegation.service_delegation- (Required) The service delegation to associate with the subnet. This is an object with anameproperty that specifies the name of the service delegation.
delegations supports the following:
name- (Required) A name for this delegation.service_delegation- (Required) The service delegation to associate with the subnet. This is an object with anameproperty that specifies the name of the service delegation.
nat_gateway supports the following:
id- (Optional) The ID of the NAT Gateway which should be associated with the Subnet. Changing this forces a new resource to be created.
network_security_group supports the following:
id- (Optional) The ID of the Network Security Group which should be associated with the Subnet. Changing this forces a new association to be created.
route_table supports the following:
id- (Optional) The ID of the Route Table which should be associated with the Subnet. Changing this forces a new association to be created.
timeouts (Optional) supports the following:
create- (Defaults to 30 minutes) Used when creating the Subnet.delete- (Defaults to 30 minutes) Used when deleting the Subnet.read- (Defaults to 5 minutes) Used when retrieving the Subnet.update- (Defaults to 30 minutes) Used when updating the Subnet.
retry (optional) supports the following:
error_message_regex- (Optional) A list of regular expressions to match against the error message returned by the API. If any of these match, the retry will be triggered.interval_seconds- (Optional) The number of seconds to wait between retries. Defaults to 10.max_interval_seconds- (Optional) The maximum number of seconds to wait between retries. Defaults to 180.
role_assignments supports the following:
role_definition_id_or_name- The ID or name of the role definition to assign to the principal.principal_id- The ID of the principal to assign the role to.description- (Optional) The description of the role assignment.skip_service_principal_aad_check- (Optional) If set to true, skips the Azure Active Directory check for the service principal in the tenant. Defaults to false.condition- (Optional) The condition which will be used to scope the role assignment.condition_version- (Optional) The version of the condition syntax. Leave asnullif you are not using a condition, if you are then valid values are '2.0'.delegated_managed_identity_resource_id- (Optional) The delegated Azure Resource Id which contains a Managed Identity. Changing this forces a new resource to be created. This field is only used in cross-tenant scenario.principal_type- (Optional) The type of theprincipal_id. Possible values areUser,GroupandServicePrincipal. It is necessary to explicitly set this attribute when creating role assignments if the principal creating the assignment is constrained by ABAC rules that filters on the PrincipalType attribute.
Type:
map(object({
address_prefix = optional(string)
address_prefixes = optional(list(string))
name = string
ipam_pools = optional(list(object({
pool_id = string
number_of_ip_addresses = optional(string)
prefix_length = optional(number)
allocation_type = optional(string, "Static")
})))
ignore_body_changes = optional(list(string), [])
nat_gateway = optional(object({
id = string
}))
network_security_group = optional(object({
id = string
}))
private_endpoint_network_policies = optional(string, "Enabled")
private_endpoint_network_policies_enabled = optional(bool, true)
private_link_service_network_policies_enabled = optional(bool, true)
route_table = optional(object({
id = string
}))
service_endpoint_policies = optional(map(object({
id = string
})))
service_endpoints = optional(set(string))
default_outbound_access_enabled = optional(bool, false)
sharing_scope = optional(string, null)
# Retained solely so that setting it produces an explanatory error instead
# of being silently discarded during object type conversion. See the
# validation block below. Remove in a future release.
service_endpoints_with_location = optional(list(object({
service = string
locations = optional(list(string), ["*"])
})))
delegations = optional(list(object({
name = string
service_delegation = object({
name = string
})
})))
timeouts = optional(object({
create = optional(string, "30m")
read = optional(string, "5m")
update = optional(string, "30m")
delete = optional(string, "30m")
}), {})
retry = optional(object({
error_message_regex = optional(list(string), ["ReferencedResourceNotProvisioned"])
interval_seconds = optional(number, 10)
max_interval_seconds = optional(number, 180)
}), {})
role_assignments = optional(map(object({
role_definition_id_or_name = string
principal_id = string
description = optional(string, null)
skip_service_principal_aad_check = optional(bool, false)
condition = optional(string, null)
condition_version = optional(string, null)
delegated_managed_identity_resource_id = optional(string, null)
principal_type = optional(string, null)
})))
}))Default: {}
Description: (Optional) Tags of the resource.
Type: map(string)
Default: null
Description: Timeouts for the resource operations
Type:
object({
create = optional(string, "30m")
read = optional(string, "5m")
update = optional(string, "30m")
delete = optional(string, "30m")
})Default: {}
The following outputs are exported:
Description: The address spaces of the virtual network.
Description: The resource name of the virtual network.
Description: Information about the peerings created in the module.
Please refer to the peering module documentation for details of the outputs
Description: The Azure Virtual Network resource. This will be null if an existing vnet is supplied.
Description: The resource ID of the virtual network.
Description: Information about the subnets created in the module.
Please refer to the subnet module documentation for details of the outputs
The following Modules are called:
Source: Azure/avm-utl-interfaces/azure
Version: 0.6.0
Source: ./modules/peering
Version:
Source: ./modules/subnet
Version:
The software may collect information about you and your use of the software and send it to Microsoft. Microsoft may use this information to provide services and improve our products and services. You may turn off the telemetry as described in the repository. There are also some features in the software that may enable you and Microsoft to collect data from users of your applications. If you use these features, you must comply with applicable law, including providing appropriate notices to users of your applications together with a copy of Microsoft’s privacy statement. Our privacy statement is located at https://go.microsoft.com/fwlink/?LinkID=824704. You can learn more about data collection and use in the help documentation and our privacy statement. Your use of the software operates as your consent to these practices.