Azure / Azure/Azure-Landing-Zones
Add recommendation for 'Deny vNet peering to non-approved vNets'
- Dominant language
- PowerShell
- Stars
- 96
- Forks
- 70
- Avg merge
- 3d 1h
- Merged PRs (30d)
- 7
Description
The policy [Deny vNet peering to non-approved vNets](https://www.azadvertizer.net/azpolicyadvertizer/Deny-VNET-Peering-To-Non-Approved-VNETs.html) is (obviously) not found in list: https://github.com/Azure/Enterprise-Scale/wiki/ALZ-Policies#intermediate-root hence, it has no recommendation or guideline on usage.
The nearest guideline is this:
https://github.com/Azure/Enterprise-Scale/wiki/Whats-new#policy-17
*"This is useful in scenarios where you only want to allow vNet peering to say a central hub vNet and not allow other vNet peerings between landing zones to be enabled."*
**Recommendation**
For the hub and spoke architecture (AdventureWorks), best practice would be to enable (assign) this policy to LZ MG, to have all traffic from spokes go to the hub - not allowing VNet peering between spokes (landing zones).
This should be reflected.
Contributor guide
Research direction
Review the ALZ-Policies#intermediate-root and What's-new#policy-17 wiki sections, along with the linked policy reference. Add the missing recommendation and usage guidance for “Deny vNet peering to non-approved vNets” in the hub-and-spoke AdventureWorks scenario. Done means the policy appears in the intermediate-root list with guidance consistent with the requested spoke-to-hub-only architecture.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100