Skip to content

XVirtualNetwork

Experimental

This API is experimental and may change without notice.

A virtual network with its subnets, network security groups and IPAM-driven address space.

API

Group azure.platform.example.org
Kind XVirtualNetwork
Plural xvirtualnetworks
Scope Namespaced
Versions v1alpha1 (referenceable)
Source compositions/azure/virtualnetwork/xrd.yaml

Spec

Field Type Required Default Description
name immutable string yes — Name of the Azure Virtual Network.
resourceGroupRef object yes — Reference to the resource group hosting the Virtual Network.
    resourceGroupRef.name string yes — Logical name of the XResourceGroup.
location string no swedencentral Azure region for the Virtual Network.
ipamAllocation object yes — Allocate address space dynamically from Azure Network Manager IPAM.
    ipamAllocation.numberOfAllocatedIpAddresses integer yes 256 Number of IP addresses to allocate from the IPAM pool (e.g. 256 for a /24).
    ipamAllocation.ipamPoolId string no — Resource ID of the IPAM pool.
subnets []object yes — Child subnets to create with this virtual network.
    subnets[].name string yes — —
    subnets[].numberOfAllocatedIpAddresses integer yes — Number of IP addresses to allocate. Constraints: min: 1.
    subnets[].securityRules []object no — Optional Network Security Group rules.
        subnets[].securityRules[].name string yes — —
        subnets[].securityRules[].priority integer yes — Constraints: min: 100, max: 4096.
        subnets[].securityRules[].direction string no Inbound One of: Inbound, Outbound.
        subnets[].securityRules[].access string no Allow One of: Allow, Deny.
        subnets[].securityRules[].protocol string no Tcp One of: Tcp, Udp, Icmp, *.
        subnets[].securityRules[].sourcePortRange string no * —
        subnets[].securityRules[].destinationPortRange string no * —
        subnets[].securityRules[].sourceAddressPrefix string no * —
        subnets[].securityRules[].destinationAddressPrefix string no * —
tags (nullable) map[string]string no null Optional tags to apply to the Virtual Network.

Fields marked immutable are fixed once the resource is created; changing one is rejected by the API server. An immutable object pins the fields nested under it too. To change one, delete the resource and create it again.

Example

Address space is drawn from an IPAM pool, so teams request a number of addresses instead of a CIDR. Each entry in spec.subnets produces a subnet, a network security group and the association between them. The Azure resource is named vnet-<spec.name>.

apiVersion: azure.platform.example.org/v1alpha1
kind: XVirtualNetwork
metadata:
  name: crd-dev
spec:
  name: crd-dev
  resourceGroupRef:
    name: crd-dev
  ipamAllocation:
    numberOfAllocatedIpAddresses: 256
    # yamllint disable-line rule:line-length
    ipamPoolId: /subscriptions/297651e0-733c-45f9-b295-ad80c68785f1/resourceGroups/rg-crd-dev/providers/Microsoft.Network/networkManagers/vnm-crd-dev/ipamPools/ipam-crd-dev
  subnets:
    - name: management
      numberOfAllocatedIpAddresses: 32
      securityRules:
        - name: allow-ssh
          priority: 1000
          direction: Inbound
          access: Allow
          protocol: Tcp
          sourcePortRange: "*"
          destinationPortRange: "22"
          sourceAddressPrefix: 85.93.238.149

Taken from teams/crd-dev/network.yaml, which is applied to the cluster by Flux, so it cannot drift from a working manifest.

Status

Populated by Crossplane once the underlying Azure resources exist. Every composite in this repository exposes the provisioned Azure resource ID as status.id.

Field Type Required Default Description
id string no — Azure resource ID of the Virtual Network.
name string no — Name of the provisioned Virtual Network.
addressSpace []string no — Allocated address prefixes for the Virtual Network.
subnets []object no — Provisioned subnet and NSG resource IDs.
    subnets[].name string no — —
    subnets[].id string no — Azure resource ID of the subnet.
    subnets[].networkSecurityGroupId string no — Azure resource ID of the subnet NSG.

Common problems

The virtual network stays not-Ready and the provider reports an invalid IPAM pool.

Cause. spec.ipamAllocation.ipamPoolId is empty or points at a pool in another subscription.

Fix. Copy status.id from the XNetworkManagerIPAMPool into ipamPoolId.

Subnet creation fails with an overlapping address space error.

Cause. The sum of each subnet's numberOfAllocatedIpAddresses exceeds the network's own allocation.

Fix. Raise spec.ipamAllocation.numberOfAllocatedIpAddresses or shrink the subnets.

A security rule is rejected by Azure.

Cause. Two rules in the same subnet share a priority, which must be unique per direction.

Fix. Give each rule a distinct priority between 100 and 4096.

Reference