diff --git a/examples/azure-vnet-to-vnet-peering/README.md b/examples/azure-vnet-to-vnet-peering/README.md new file mode 100644 index 000000000..cf6318bb9 --- /dev/null +++ b/examples/azure-vnet-to-vnet-peering/README.md @@ -0,0 +1,24 @@ +# VNET to VNET Peering + +This template creates two VNETs in the same location, each containing a single subnet, and creates connections between them using VNET Peering. + +## main.tf +The `main.tf` file contains the actual resources that will be deployed. It also contains the Azure Resource Group definition and any defined variables. + +## outputs.tf +This data is outputted when `terraform apply` is called, and can be queried using the `terraform output` command. + +## provider.tf +You may leave the provider block in the `main.tf`, as it is in this template, or you can create a file called `provider.tf` and add it to your `.gitignore` file. + +Azure requires that an application is added to Azure Active Directory to generate the `client_id`, `client_secret`, and `tenant_id` needed by Terraform (`subscription_id` can be recovered from your Azure account details). Please go [here](https://www.terraform.io/docs/providers/azurerm/) for full instructions on how to create this to populate your `provider.tf` file. + +## terraform.tfvars +If a `terraform.tfvars` file is present in the current directory, Terraform automatically loads it to populate variables. We don't recommend saving usernames and password to version control, but you can create a local secret variables file and use `-var-file` to load it. + +If you are committing this template to source control, please insure that you add this file to your `.gitignore` file. + +## variables.tf +The `variables.tf` file contains all of the input parameters that the user can specify when deploying this Terraform template. + +![`terraform graph`](/examples/azure-vnet-to-vnet-peering/graph.png) \ No newline at end of file diff --git a/examples/azure-vnet-to-vnet-peering/deploy.ci.sh b/examples/azure-vnet-to-vnet-peering/deploy.ci.sh new file mode 100755 index 000000000..4b7c1d693 --- /dev/null +++ b/examples/azure-vnet-to-vnet-peering/deploy.ci.sh @@ -0,0 +1,37 @@ +#!/bin/bash + +set -o errexit -o nounset + +docker run --rm -it \ + -e ARM_CLIENT_ID \ + -e ARM_CLIENT_SECRET \ + -e ARM_SUBSCRIPTION_ID \ + -e ARM_TENANT_ID \ + -v $(pwd):/data \ + --workdir=/data \ + --entrypoint "/bin/sh" \ + hashicorp/terraform:light \ + -c "/bin/terraform get; \ + /bin/terraform validate; \ + /bin/terraform plan -out=out.tfplan -var resource_group=$KEY; \ + /bin/terraform apply out.tfplan; \ + /bin/terraform show;" + +# cleanup deployed azure resources via azure-cli +docker run --rm -it \ + azuresdk/azure-cli-python \ + sh -c "az login --service-principal -u $ARM_CLIENT_ID -p $ARM_CLIENT_SECRET --tenant $ARM_TENANT_ID > /dev/null; \ + az network vnet peering show -g $KEY --vnet-name $KEY'-vnet1' -n vNet1-to-vNet2; + az network vnet peering show -g $KEY --vnet-name $KEY'-vnet2' -n vNet2-to-vNet1;" + +# cleanup deployed azure resources via terraform +docker run --rm -it \ + -e ARM_CLIENT_ID \ + -e ARM_CLIENT_SECRET \ + -e ARM_SUBSCRIPTION_ID \ + -e ARM_TENANT_ID \ + -v $(pwd):/data \ + --workdir=/data \ + --entrypoint "/bin/sh" \ + hashicorp/terraform:light \ + -c "/bin/terraform destroy -force -var resource_group=$KEY;" \ No newline at end of file diff --git a/examples/azure-vnet-to-vnet-peering/deploy.mac.sh b/examples/azure-vnet-to-vnet-peering/deploy.mac.sh new file mode 100755 index 000000000..dfc34c2be --- /dev/null +++ b/examples/azure-vnet-to-vnet-peering/deploy.mac.sh @@ -0,0 +1,15 @@ +#!/bin/bash + +set -o errexit -o nounset + +if docker -v; then + + # generate a unique string for CI deployment + export KEY=$(cat /dev/urandom | env LC_CTYPE=C tr -cd 'a-z' | head -c 12) + export PASSWORD=$KEY$(cat /dev/urandom | env LC_CTYPE=C tr -cd 'A-Z' | head -c 2)$(cat /dev/urandom | env LC_CTYPE=C tr -cd '0-9' | head -c 2) + + /bin/sh ./deploy.ci.sh + +else + echo "Docker is used to run terraform commands, please install before run: https://docs.docker.com/docker-for-mac/install/" +fi \ No newline at end of file diff --git a/examples/azure-vnet-to-vnet-peering/graph.png b/examples/azure-vnet-to-vnet-peering/graph.png new file mode 100644 index 000000000..342a78062 Binary files /dev/null and b/examples/azure-vnet-to-vnet-peering/graph.png differ diff --git a/examples/azure-vnet-to-vnet-peering/main.tf b/examples/azure-vnet-to-vnet-peering/main.tf new file mode 100644 index 000000000..6bdfb8a24 --- /dev/null +++ b/examples/azure-vnet-to-vnet-peering/main.tf @@ -0,0 +1,56 @@ +# provider "azurerm" { +# subscription_id = "REPLACE-WITH-YOUR-SUBSCRIPTION-ID" +# client_id = "REPLACE-WITH-YOUR-CLIENT-ID" +# client_secret = "REPLACE-WITH-YOUR-CLIENT-SECRET" +# tenant_id = "REPLACE-WITH-YOUR-TENANT-ID" +# } + +resource "azurerm_resource_group" "rg" { + name = "${var.resource_group}" + location = "${var.location}" +} + +resource "azurerm_virtual_network" "vnet1" { + name = "${var.resource_group}-vnet1" + location = "${var.location}" + address_space = ["10.0.0.0/24"] + resource_group_name = "${azurerm_resource_group.rg.name}" + + subnet { + name = "subnet1" + address_prefix = "10.0.0.0/24" + } +} + +resource "azurerm_virtual_network" "vnet2" { + name = "${var.resource_group}-vnet2" + location = "${var.location}" + address_space = ["192.168.0.0/24"] + resource_group_name = "${azurerm_resource_group.rg.name}" + + subnet { + name = "subnet1" + address_prefix = "192.168.0.0/24" + } +} + +resource "azurerm_virtual_network_peering" "peer1" { + name = "vNet1-to-vNet2" + resource_group_name = "${azurerm_resource_group.rg.name}" + virtual_network_name = "${azurerm_virtual_network.vnet1.name}" + remote_virtual_network_id = "${azurerm_virtual_network.vnet2.id}" + allow_virtual_network_access = true + allow_forwarded_traffic = false + allow_gateway_transit = false +} + +resource "azurerm_virtual_network_peering" "peer2" { + name = "vNet2-to-vNet1" + resource_group_name = "${azurerm_resource_group.rg.name}" + virtual_network_name = "${azurerm_virtual_network.vnet2.name}" + remote_virtual_network_id = "${azurerm_virtual_network.vnet1.id}" + allow_virtual_network_access = true + allow_forwarded_traffic = false + allow_gateway_transit = false + use_remote_gateways = false +} diff --git a/examples/azure-vnet-to-vnet-peering/variables.tf b/examples/azure-vnet-to-vnet-peering/variables.tf new file mode 100644 index 000000000..2701af343 --- /dev/null +++ b/examples/azure-vnet-to-vnet-peering/variables.tf @@ -0,0 +1,9 @@ +variable "resource_group" { + description = "The name of the resource group in which the virtual networks are created" + default = "myrg" +} + +variable "location" { + description = "The location/region where the virtual networks are created. Changing this forces a new resource to be created." + default = "southcentralus" +}