A production-ready Azure networking architecture demonstrating enterprise-grade network design, security patterns, and application deployment using Infrastructure as Code.
Multi-VNet Enterprise Network with security-first design implementing zero-trust principles, private connectivity patterns, and automated monitoring across multiple network segments.
- 2 Virtual Networks with VNet peering (10.0.0.0/16, 10.1.0.0/16)
- 5 Subnets for network segmentation and traffic isolation
- Spring Boot API with network diagnostics and health monitoring
- Application Gateway for public load balancing with health probes
- Private Endpoints for secure Azure service access
- Network Security Groups with micro-segmentation rules
- Bastion host pattern for secure administrative access
- Private DNS resolution for internal service discovery
- NAT Gateway for secure outbound internet access
- Zero default access - all connectivity explicitly configured
# Prerequisites: Azure CLI, Terraform 1.0+, SSH keys
terraform init
terraform apply
# Test deployment
curl $(terraform output -raw app_gateway_url)/healthInternet → Application Gateway → Private VM (Spring Boot)
↓ ↓
Bastion Host ←→ Private Subnet → NAT Gateway
↓ ↓
Private Endpoint → Azure Storage
↓
VNet Peering ↔ Secondary VNet
| Subnet | Address Space | Purpose |
|---|---|---|
| Public (Primary) | 10.0.1.0/24 | Bastion host |
| Private (Primary) | 10.0.2.0/24 | App + Private Endpoint |
| App Gateway | 10.0.3.0/24 | Load balancer |
| Public (Secondary) | 10.1.1.0/24 | Reserved/future use |
| Private (Secondary) | 10.1.2.0/24 | Nginx VM for peering test |
# Public application access
curl $(terraform output -raw app_gateway_url)/api/network-test
# Private resource access via bastion
ssh -J azureuser@$(terraform output -raw bastion_ip) azureuser@$(terraform output -raw private_vm_ip)
# Cross-VNet connectivity test
ssh azureuser@primary-vm
ping $(terraform output -raw secondary_vm_ip)| Component | Count | Purpose |
|---|---|---|
| Virtual Networks | 2 | Network isolation and cross-connectivity |
| Virtual Machines | 3 | Application hosting and network testing |
| Network Security Groups | 4 | Traffic filtering and access control |
| Application Gateway | 1 | Public load balancing and SSL termination |
| Private Endpoints | 1 | Secure Azure service connectivity |
| Storage Account | 1 | Private service access demonstration |
Cloud Architecture: Network design, security patterns, load balancing, DNS resolution Infrastructure as Code: Terraform state management, modular configuration Application Development: Spring Boot REST APIs, health monitoring, diagnostics Security: Zero-trust networking, private endpoints, access controls
Enterprise Architecture: Scalable patterns for production workloads, compliance-ready design Development Teams: Automated environment provisioning, network troubleshooting tools Security: Defense-in-depth implementation with private connectivity patterns
terraform destroy
# Removes all resources in ~10 minutesTech Stack: Azure • Terraform • Spring Boot • Java • Linux • Network Security
