Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update 101-virtual-network-manager-create-mesh #234

Merged
merged 13 commits into from
Jun 27, 2023
54 changes: 48 additions & 6 deletions quickstart/101-virtual-network-manager-create-mesh/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -58,14 +58,56 @@ resource "azurerm_network_manager_network_group" "network_group" {
network_manager_id = azurerm_network_manager.network_manager_instance.id
}

# Add the three virtual networks to the network group as static members
# Add three virtual networks to a network group as dynamic members with Azure Policy

resource "azurerm_network_manager_static_member" "static_members" {
count = 3
resource "random_pet" "network_group_policy_name" {
prefix = "network-group-policy"
}

resource "azurerm_policy_definition" "network_group_policy" {
name = "${random_pet.network_group_policy_name.id}"
policy_type = "Custom"
mode = "Microsoft.Network.Data"
display_name = "Policy Definition for Network Group"

metadata = <<METADATA
grayzu marked this conversation as resolved.
Show resolved Hide resolved
{
"category": "Azure Virtual Network Manager"
}
METADATA

policy_rule = <<POLICY_RULE
grayzu marked this conversation as resolved.
Show resolved Hide resolved
{
"if": {
"allOf": [
{
"field": "type",
"equals": "Microsoft.Network/virtualNetworks"
},
{
"allOf": [
{
"field": "Name",
"contains": "vnet"
grayzu marked this conversation as resolved.
Show resolved Hide resolved
}
]
}
]
},
"then": {
"effect": "addToNetworkGroup",
"details": {
"networkGroupId": "${azurerm_network_manager_network_group.network_group.id}"
}
}
}
POLICY_RULE
}

name = "static-member-0${count.index}"
network_group_id = azurerm_network_manager_network_group.network_group.id
target_virtual_network_id = azurerm_virtual_network.vnet[count.index].id
resource "azurerm_subscription_policy_assignment" "azure_policy_assignment" {
name = "${random_pet.network_group_policy_name.id}-policy-assignment"
policy_definition_id = azurerm_policy_definition.network_group_policy.id
subscription_id = data.azurerm_subscription.current.id
}

# Create a connectivity configuration
Expand Down
3 changes: 2 additions & 1 deletion quickstart/101-virtual-network-manager-create-mesh/readme.md
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,8 @@ This template deploys an Azure Virtual Network Manager instance with a connectiv
- [azurerm_subnet](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/subnet)
- [azurerm_virtual_network_manager](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/network_manager)
- [azurerm_network_manager_network_group](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/network_manager_network_group)
- [azurerm_network_manager_static_member](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/network_manager_static_member)
- [azurerm_policy_definition](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/policy_definition)
- [azurerm_subscription_policy_assignment](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/subscription_policy_assignment)
- [azurerm_network_manager_connectivity_configuration](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/network_manager_connectivity_configuration)
- [azurerm_network_manager_deployment](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/network_manager_deployment)

Expand Down
Loading