Azure — Hub-and-Spoke Landing Zone
The enterprise pattern: a hub virtual network carrying the shared firewall, bastion and gateway, with workload spokes peered to it. Reports clean. Note the boundary edges — traffic that crosses from one virtual network to another names the gateway it crosses at, which is what stops the engine reporting an unexplained boundary crossing.
Make it your own.
title "Azure landing zone — hub and spoke"
provider azure
internet {
user staff "Staff"
user customers "Customers"
}
onprem hq "Head office" {
server ad "Directory server"
}
cloud sub "Production subscription" {
region westeurope {
network hub "Hub VNet" cidr 10.0.0.0/16 {
firewall fw "Azure Firewall"
bastion bastion "Bastion host"
vpn-gateway vpngw "VPN gateway"
app-gateway agw "Application gateway"
}
network spoke-app "Spoke — application" cidr 10.1.0.0/16 {
subnet app "Application" private cidr 10.1.1.0/24 {
app-service api "Order API" count 3 tier api
}
subnet mgmt "Management" private cidr 10.1.2.0/24 {
vm jump "Jump host"
}
}
network spoke-data "Spoke — data" cidr 10.2.0.0/16 {
subnet data "Data" isolated cidr 10.2.1.0/24 {
sql-database orders "Orders database"
}
}
key-vault kv "Key vault"
monitor mon "Azure Monitor"
}
}
customers -> agw : https 443
staff -> agw : https 443
agw -> api : https 443 via fw
staff -> bastion : ssh 22
bastion -> jump : ssh 22 via fw
ad -> vpngw : ipsec 500
vpngw -> api : ldaps 636 via fw
api -> orders : tds 1433 via fw
api -> kv : https 443
mon ..> api
mon ..> orders