Azure / Azure/Azure-Landing-Zones

Ability to use existing ddos for hub vnet Feature Request

Open
#460 3 comments 1 reaction 1 assignee View on GitHub

@matt-FFFFFF is already working on this.

Since May 19, 2025.

Transfer From: caf-enterprise-scale :arrow_right:
Dominant language
PowerShell
Stars
97
Forks
70
Avg merge
3d 1h
Merged PRs (30d)
7

Description

Community Note
  • Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
  • Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
  • If you are interested in working on this issue or have submitted a pull request, please leave a comment
Description
Is your feature request related to a problem?

I would reaaly like to have the option to use an existing ddos service for the hub Vnet instead of the present options which either disables it or creates a new one if enabled. DDoS is an expensive service & we have already created one post deployment of the LZ (using another terraform script) which we are using across all our spokes too.

When I run the terraform script for the LZ now, it is creating a new ddos & replacing it with our existing one on the hub vnet. If I disable the ddos in network settings option then it disassociates the existing ddos from the hub.

Describe the solution you'd like

I would like to have the option to add/use an existing ddos for the hub using the existing ddos id.

Additional context

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.