快速入門:使用 Bicep 透過 Azure Virtual Network Manager 建立網格網路拓撲

使用 Bicep 來管理所有虛擬網路的連線,以開始使用 Azure Virtual Network Manager。

在本快速入門中,您會部署三個虛擬網路,並使用 Azure Virtual Network Manager 來建立網狀網路拓撲。 然後您會驗證已套用連線設定。

使用 Azure Virtual Network Manager 針對網格虛擬網路拓撲部署的資源圖表。

此範例的 Bicep 解決方案細分為模組,以在資源群組和訂用帳戶範圍上啟用部署。 以下章節將介紹 Azure Virtual Network Manager 獨有的元件。 除了這些元件外,該解決方案還部署虛擬網路、使用者指派身份及角色分配。

定義虛擬網路管理員資源

此資源在 API 版本 Microsoft.Network/networkManagers時建立2022-09-01實例,實現連接群組以實現虛擬網路間的連接。 設定 networkManagerScopes 為實例所管理的訂閱或管理群組,並保留 Connectivity 在 networkManagerScopeAccesses 實例中,以便實例能部署連接設定。

@description('This is the Azure Virtual Network Manager which will be used to implement the connected group for inter-vnet connectivity.')
resource networkManager 'Microsoft.Network/networkManagers@2022-09-01' = {
  name: 'vnm-learn-prod-${location}-001'
  location: location
  properties: {
    networkManagerScopeAccesses: [
      'Connectivity'
    ]
    networkManagerScopes: {
      subscriptions: [
        '/subscriptions/${subscription().subscriptionId}'
      ]
      managementGroups: []
    }
  }
}

定義靜態與動態網路群組

此解決方案支援靜態會員網路群組或動態會員網路群組。 networkGroupMembershipType 參數用於選擇要部署哪一個;兩個資源中只會建立其中一個。

靜態會員網絡群組

靜態網路群組資源在 Microsoft.Network/networkManagers/networkGroups API 版本 2022-09-01中會明確命名其成員名稱。 巢狀 staticMembers 資源會透過資源識別碼加入輻射虛擬網路 A、B 和 C,以及中樞虛擬網路。 若要指定您自己的虛擬網路,請變更 spokeNetworkGroupMembers 和 hubVnetId 參數。

@description('This is the static network group for the all VNETs.')
resource networkGroupSpokesStatic 'Microsoft.Network/networkManagers/networkGroups@2022-09-01' = if (networkGroupMembershipType == 'static') {
  name: 'ng-learn-prod-${location}-static001'
  parent: networkManager
  properties: {
    description: 'Network Group - Static'
  }

  // add spoke vnets A, B, and C to the static network group
  resource staticMemberSpoke 'staticMembers@2022-09-01' = [for spokeMember in spokeNetworkGroupMembers: if (contains(groupedVNETs,last(split(spokeMember,'/')))) {
    name: 'sm-${(last(split(spokeMember, '/')))}'
    properties: {
      resourceId: spokeMember
    }
  }]

  resource staticMemberHub 'staticMembers@2022-09-01' = {
    name: 'sm-${(toLower(last(split(hubVnetId, '/'))))}'
    properties: {
      resourceId: hubVnetId
    }
  }
}

動態會員網絡群組

動態網路群組資源宣告無成員。 成員資格由 Azure 原則 定義填充,該定義見「定義動態成員政策」。

@description('This is the dynamic group for all VNETs.')
resource networkGroupSpokesDynamic 'Microsoft.Network/networkManagers/networkGroups@2022-09-01' = if (networkGroupMembershipType == 'dynamic') {
  name: 'ng-learn-prod-${location}-dynamic001'
  parent: networkManager
  properties: {
    description: 'Network Group - Dynamic'
  }
}

定義網狀連接性配置

在 API 版本 Microsoft.Network/networkManagers/connectivityConfigurations時,連接配置資源2022-09-01將網路群組與網狀網路拓撲關聯起來。 屬性 appliesToGroups 參考你部署的網路群組,然後你設 connectivityTopology 為 Mesh。

@description('This connectivity configuration defines the connectivity between VNETs using Direct Connection. The hub will be part of the mesh, but gateway routes from the hub will not propagate to spokes.')
resource connectivityConfigurationMesh 'Microsoft.Network/networkManagers/connectivityConfigurations@2022-09-01' = {
  name: 'cc-learn-prod-${location}-mesh001'
  parent: networkManager
  properties: {
    description: 'Mesh connectivity configuration'
    appliesToGroups: [
      {
        networkGroupId: (networkGroupMembershipType == 'static') ? networkGroupSpokesStatic.id : networkGroupSpokesDynamic.id
        isGlobal: 'False'
        useHubGateway: 'False'
        groupConnectivity: 'DirectlyConnected'
      }
    ]
    connectivityTopology: 'Mesh'
    deleteExistingPeering: 'True'
    hubs: []
    isGlobal: 'False'
  }
}

用部署腳本提交設定

要將設定部署到目標網路群組,請使用部署腳本呼叫 Deploy-AzNetworkManagerCommit PowerShell 指令。 部署腳本需要一個具備足夠權限的身份,才能對虛擬網路管理員執行 PowerShell 腳本。 Bicep 檔案建立一個由使用者管理的身分,並在目標資源群組中賦予其參與者角色。 欲了解更多關於部署腳本及相關身份的資訊,請參閱「 在 ARM 範本中使用部署腳本」。

以下資源為 Microsoft.Resources/deploymentScripts API 版本 2020-10-01的資源。 它執行一個內嵌的 PowerShell 腳本,以使用者指定的身份登入並呼叫 Deploy-AzNetworkManagerCommit。 針對您自己的部署,變更屬性 azPowerShellVersion、retentionInterval 和 timeout。 更改傳遞的 arguments值:網路管理員名稱、目標位置、設定 ID、訂閱 ID、設定類型及資源群組名稱。

@description('Create a Deployment Script resource to perform the commit/deployment of the Network Manager connectivity configuration.')
resource deploymentScript 'Microsoft.Resources/deploymentScripts@2020-10-01' = {
  name: deploymentScriptName
  location: location
  kind: 'AzurePowerShell'
  identity: {
    type: 'UserAssigned'
    userAssignedIdentities: {
      '${userAssignedIdentityId}': {}
    }
  }
  properties: {
    azPowerShellVersion: '8.3'
    retentionInterval: 'PT1H'
    timeout: 'PT1H'
    arguments: '-networkManagerName "${networkManagerName}" -targetLocations ${location} -configIds ${configurationId} -subscriptionId ${subscription().subscriptionId} -configType ${configType} -resourceGroupName ${resourceGroup().name}'
    scriptContent: '''
    param (
      # AVNM subscription id
      [parameter(mandatory=$true)][string]$subscriptionId,

      # AVNM resource name
      [parameter(mandatory=$true)][string]$networkManagerName,

      # string with comma-separated list of config ids to deploy. ids must be of the same config type
      [parameter(mandatory=$true)][string[]]$configIds,

      # string with comma-separated list of deployment target regions
      [parameter(mandatory=$true)][string[]]$targetLocations,

      # configuration type to deploy. must be either connectivity or securityadmin
      [parameter(mandatory=$true)][ValidateSet('Connectivity','SecurityAdmin')][string]$configType,

      # AVNM resource group name
      [parameter(mandatory=$true)][string]$resourceGroupName
    )
  
    $null = Login-AzAccount -Identity -Subscription $subscriptionId
  
    [System.Collections.Generic.List[string]]$configIdList = @()  
    $configIdList.addRange($configIds) 
    [System.Collections.Generic.List[string]]$targetLocationList = @() # target locations for deployment
    $targetLocationList.addRange($targetLocations)     
    
    $deployment = @{
        Name = $networkManagerName
        ResourceGroupName = $resourceGroupName
        ConfigurationId = $configIdList
        TargetLocation = $targetLocationList
        CommitType = $configType
    }
  
    try {
      Deploy-AzNetworkManagerCommit @deployment -ErrorAction Stop
    }
    catch {
      Write-Error "Deployment failed with error: $_"
      throw "Deployment failed with error: $_"
    }
    '''
    }
}

定義動態會員政策

當你設定部署使用dynamic網路群組成員制時,解決方案也會部署 Azure 原則 定義與指派。

以下資源為 Microsoft.Authorization/policyDefinitions API 版本 2021-06-01的資源。 它使用 Microsoft.Network.Data 政策模式和效果 addToNetworkGroup ,將匹配的虛擬網路加入由 所 networkGroupId識別的網路群組中。 政策規則會匹配攜帶標籤 _avnm_quickstart_deployment 且存在於本樣本資源群組中的虛擬網路。 在條件中更改標籤名稱和資源群組過濾器 like ,使其符合你自己的環境。

@description('This is a Policy definition for dynamic group membership')
resource policyDefinition 'Microsoft.Authorization/policyDefinitions@2021-06-01' = {
  name: uniqueString(networkGroupId)
  properties: {
    description: 'AVNM quickstart dynamic group membership Policy'
    displayName: 'AVNM quickstart dynamic group membership Policy'
    mode: 'Microsoft.Network.Data'
    policyRule: {
      if: {
        allof: [
          {
            field: 'type'
            equals: 'Microsoft.Network/virtualNetworks'
          }
          {
            // virtual networks must have a tag where the key is '_avnm_quickstart_deployment'
            field: 'tags[_avnm_quickstart_deployment]'
            exists: true
          }
          {
            // virtual network ids must include this sample's resource group ID - limiting the chance that dynamic membership impacts other vnets in your subscriptions
            field: 'id'
            like: '${subscription().id}/resourcegroups/${resourceGroupName}/*'
          }
        ]
      }
      then: {
        // 'addToNetworkGroup' is a special effect used by AVNM network groups
        effect: 'addToNetworkGroup'
        details: {
          networkGroupId: networkGroupId
        }
      }
    }
  }
}

部署 Bicep 解決方案

部署必要條件

  • 具有有效訂用帳戶的 Azure 帳戶。 免費建立帳戶。
  • 在目標訂閱範圍內建立政策定義與政策指派的權限。 使用部署參數 networkGroupMembershipType=Dynamic 部署所需的 Policy 資源以取得網路群組成員資格時,您需要這些權限。 預設是 static,不會部署 Policy。
  • 此解決方案中的所有資源皆可在 Azure Samples GitHub 倉庫中取得。 你可以從倉庫下載 Bicep 解決方案,或是將倉庫複製到你本機的電腦。

下載 Bicep 解決方案

  1. 可在此 連結下載範例倉庫的 ZIP 檔案庫。
  2. 解壓下載的 ZIP 檔案。 在終端機中,進入解壓縮後的 avnm-mesh-connected-group 目錄。 這個解決方案的 Bicep 檔案在子bicep目錄中。

或者,你也可以用 git 來複製倉庫:

git clone https://github.com/Azure-Samples/avnm-mesh-connected-group
cd avnm-mesh-connected-group

連線到 Azure

登入您的 Azure 帳戶並且選取您的訂用帳戶

若要開始您的設定,請登入您的 Azure 帳戶:

Connect-AzAccount

然後,連線到您的訂用帳戶:

Set-AzContext -Subscription <subscription name or id>
安裝 Azure PowerShell 模組

使用此命令來安裝最新的 Az.Network Azure PowerShell 模組:

 Install-Module -Name Az.Network -RequiredVersion 5.3.0

部署參數

  • resourceGroupName: [必要] 你想部署虛擬網路管理器和範例虛擬網路的資源群組名稱。
  • 地點:[需要] 資源部署地點。
  • networkGroupMembershipType:[可選] 要部署的 Network Group 成員類型。 預設是 static,但你也可以用 dynamic 來做動態群組成員。

附註

選擇動態群組成員會部署 Azure 原則 來管理成員,這需要更多權限。

具有靜態網路群組成員資格的預設部署

New-AzSubscriptionDeployment -Name avnm-mesh-connected-group -Location <deploymentLocation> -TemplateFile ./bicep/main.bicep -resourceGroupName <newOrExistingResourceGroup>

動態網路群組成員部署

若要使用 Azure 原則 動態管理網路群組成員資格,請包含 部署參數networkGroupMembershipType,值為 dynamic。

New-AzSubscriptionDeployment -Name avnm-mesh-connected-group -Location <deploymentLocation> -TemplateFile ./bicep/main.bicep -resourceGroupName <newOrExistingResourceGroup> -networkGroupMembershipType dynamic

驗證設定部署

使用每個虛擬網路的 [網路管理員] 區段來驗證您已部署設定:

  1. 移至 vnet-learn-prod-{location}-spoke001 虛擬網路。

  2. 在 [設定] 底下,選取 [網路管理員]。

  3. 在 [連線能力設定] 索引標籤上,驗證 cc-learn-prod-{location}-mesh001 出現在清單中。

    針對虛擬網路列出的連線設定的螢幕擷取畫面。

  4. 在 vnet-learn-prod-{location}-spoke004 上重複上述步驟,您應會看到 vnet-learn-prod-{location}-spoke004 已從連線能力設定中排除。

清除資源

如果你不再需要 Azure Virtual Network Manager 及其相關的虛擬網路,請刪除資源群組及其資源來移除它們。

  1. 在 Azure 入口網站中,瀏覽至您的資源群組 - resource-group。
  2. 選取 resource-group,然後選取 [刪除資源群組]。
  3. 在 「刪除資源群組」中,請在文字框中輸入 resource-group ,然後選擇 「刪除」。
  4. 如果您使用 [動態網路群組成員資格],請瀏覽至入口網站中的 [訂用帳戶],然後選取 [原則],以刪除已部署的 Azure 原則定義和指派。 在 Policies 中,找到名為 的 AVNM quickstart dynamic group membership Policy 並將其刪除,然後對名為 的 AVNM quickstart dynamic group membership Policy 執行相同操作。

後續步驟

現在你建立了 Azure Virtual Network Manager 實例,請學習如何透過安全管理員設定來阻擋網路流量: