SOLVED

Peering between tw vnets accross subscription -- terraform

%3CLINGO-SUB%20id%3D%22lingo-sub-3256791%22%20slang%3D%22en-US%22%3EPeering%20between%20tw%20vnets%20accross%20subscription%20--%20terraform%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3256791%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3Bi%20have%20two%20folders%2C%20one%20for%20connectivity%20subscription%20and%20the%20second%20for%20identity%20subscription.%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20to%20configure%20the%20peering%20between%20the%20vnet%20of%20connectivity%20and%20the%20vnet%20of%20identity%20%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20to%20call%20the%26nbsp%3B%20%22remote_virtual_network_id%22%20from%20the%20other%20folder%20of%20identity%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22hamma91_0-1647284852695.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F355627iC750CB263CFA6361%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22hamma91_0-1647284852695.png%22%20alt%3D%22hamma91_0-1647284852695.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3258687%22%20slang%3D%22en-US%22%3ERe%3A%20Peering%20between%20tw%20vnets%20accross%20subscription%20--%20terraform%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3258687%22%20slang%3D%22en-US%22%3Ebest%20one%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-3258676%22%20slang%3D%22en-US%22%3ERe%3A%20Peering%20between%20tw%20vnets%20accross%20subscription%20--%20terraform%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3258676%22%20slang%3D%22en-US%22%3EHello%20you%20need%20to%20use%20aliases%20like%20this%20(%20provider%20version%20to%20update)%20%3A%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20main.tf%3CBR%20%2F%3Eprovider%20%22azurerm%22%20%7B%3CBR%20%2F%3Ealias%20%3D%20%22vnet1%22%3CBR%20%2F%3Eversion%20%3D%20%22%3D2.23.0%22%3CBR%20%2F%3Efeatures%20%7B%7D%3CBR%20%2F%3E%3CBR%20%2F%3Eclient_id%20%3D%20var.vnet1_client_id%3CBR%20%2F%3Etenant_id%20%3D%20var.vnet1_tenant_id%3CBR%20%2F%3Eclient_secret%20%3D%20var.vnet1_client_secret%3CBR%20%2F%3Esubscription_id%20%3D%20var.vnet1_subscription_id%3CBR%20%2F%3E%3CBR%20%2F%3E%7D%3CBR%20%2F%3E%3CBR%20%2F%3Eprovider%20%22azurerm%22%20%7B%3CBR%20%2F%3Ealias%20%3D%20%22vnet2%22%3CBR%20%2F%3Eversion%20%3D%20%22%3D2.23.0%22%3CBR%20%2F%3Efeatures%20%7B%7D%3CBR%20%2F%3E%3CBR%20%2F%3Eclient_id%20%3D%20var.vnet2_client_id%3CBR%20%2F%3Etenant_id%20%3D%20var.vnet2_tenant_id%3CBR%20%2F%3Eclient_secret%20%3D%20var.vnet2_client_secret%3CBR%20%2F%3Esubscription_id%20%3D%20var.vnet2_subscription_id%3CBR%20%2F%3E%3CBR%20%2F%3E%7D%3CBR%20%2F%3E%3CBR%20%2F%3Eresource%20%22azurerm_virtual_network_peering%22%20%22peer-to-vnet1%22%20%7B%3CBR%20%2F%3Ename%20%3D%20%22peer-to-%24%7Bvar.vnet1_name%7D%22%3CBR%20%2F%3Eresource_group_name%20%3D%20var.vnet2_resource_group_name%3CBR%20%2F%3Evirtual_network_name%20%3D%20var.vnet2_name%3CBR%20%2F%3Eremote_virtual_network_id%20%3D%20var.vnet1_id%3CBR%20%2F%3Eallow_virtual_network_access%20%3D%20var.allow_virtual_network_access_vnet2_to_vnet1%3CBR%20%2F%3Eallow_forwarded_traffic%20%3D%20var.allow_forwarded_traffic_vnet2_to_vnet1%3CBR%20%2F%3Eallow_gateway_transit%20%3D%20var.allow_gateway_transit_vnet2_to_vnet1%3CBR%20%2F%3Euse_remote_gateways%20%3D%20var.use_remote_gateways_vnet2_to_vnet1%3CBR%20%2F%3Eprovider%20%3D%20azurerm.vnet2%3CBR%20%2F%3E%7D%3CBR%20%2F%3E%3CBR%20%2F%3Eresource%20%22azurerm_virtual_network_peering%22%20%22peer-to-vnet2%22%20%7B%3CBR%20%2F%3Ename%20%3D%20%22peer-to-%24%7Bvar.vnet2_name%7D%22%3CBR%20%2F%3Eresource_group_name%20%3D%20var.vnet1_resource_group_name%3CBR%20%2F%3Evirtual_network_name%20%3D%20var.vnet1_name%3CBR%20%2F%3Eremote_virtual_network_id%20%3D%20var.vnet2_id%3CBR%20%2F%3Eallow_virtual_network_access%20%3D%20var.allow_virtual_network_access_vnet1_to_vnet2%3CBR%20%2F%3Eallow_forwarded_traffic%20%3D%20var.allow_forwarded_traffic_vnet1_to_vnet2%3CBR%20%2F%3Eallow_gateway_transit%20%3D%20var.allow_gateway_transit_vnet1_to_vnet2%3CBR%20%2F%3Euse_remote_gateways%20%3D%20var.use_remote_gateways_vnet1_to_vnet2%3CBR%20%2F%3Eprovider%20%3D%20azurerm.vnet1%3CBR%20%2F%3E%7D%3CBR%20%2F%3EIn%20variables.tf%3CBR%20%2F%3E%3CBR%20%2F%3E%23Varibles%20related%20to%20Vnet%202%20%3A%20spoke%3CBR%20%2F%3E%3CBR%20%2F%3Evariable%20%22vnet2_resource_group_name%22%20%7B%3CBR%20%2F%3Etype%20%3D%20string%3CBR%20%2F%3Edescription%20%3D%20%22name%20of%20the%20ressource%20group%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet2_name%22%20%7B%3CBR%20%2F%3Etype%20%3D%20string%3CBR%20%2F%3Edescription%20%3D%20%22Names%20of%20the%20spoke%20virtual%20network%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet2_id%22%20%7B%3CBR%20%2F%3Edescription%20%3D%20%22Id%20of%20the%20spoke%20virtual%20network%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22allow_virtual_network_access_vnet2_to_vnet1%22%20%7B%3CBR%20%2F%3Etype%20%3D%20bool%3CBR%20%2F%3Edescription%20%3D%20%22(Optional)%20Controls%20if%20the%20VMs%20in%20the%20remote%20virtual%20network%20can%20access%20VMs%20in%20the%20local%20virtual%20network.%20default%20to%20true.%22%3CBR%20%2F%3Edefault%20%3D%20true%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22allow_forwarded_traffic_vnet2_to_vnet1%22%20%7B%3CBR%20%2F%3Etype%20%3D%20bool%3CBR%20%2F%3Edescription%20%3D%20%22(Optional)%20Controls%20if%20forwarded%20traffic%20from%20VMs%20in%20the%20remote%20virtual%20network%20is%20allowed.%20default%20to%20false.%22%3CBR%20%2F%3Edefault%20%3D%20true%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22allow_gateway_transit_vnet2_to_vnet1%22%20%7B%3CBR%20%2F%3Etype%20%3D%20bool%3CBR%20%2F%3Edescription%20%3D%20%22(Optional)%20Controls%20gatewayLinks%20can%20be%20used%20in%20the%20remote%20virtual%20network%E2%80%99s%20link%20to%20the%20local%20virtual%20network.%22%3CBR%20%2F%3Edefault%20%3D%20false%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22use_remote_gateways_vnet2_to_vnet1%22%20%7B%3CBR%20%2F%3Etype%20%3D%20bool%3CBR%20%2F%3Edescription%20%3D%20%22(Optional)%20Controls%20if%20remote%20gateways%20can%20be%20used%20on%20the%20local%20virtual%20network.%20If%20the%20flag%20is%20set%20to%20true%2C%20and%20allow_gateway_transit%20on%20the%20remote%20peering%20is%20also%20true%2C%20virtual%20network%20will%20use%20gateways%20of%20remote%20virtual%20network%20for%20transit.%20Only%20one%20peering%20can%20have%20this%20flag%20set%20to%20true.%20This%20flag%20cannot%20be%20set%20if%20virtual%20network%20already%20has%20a%20gateway.%20default%20to%20false.%22%3CBR%20%2F%3Edefault%20%3D%20false%3CBR%20%2F%3E%7D%3CBR%20%2F%3E%3CBR%20%2F%3E%23variables%20related%20to%20Vnet%201%20%3A%20hub%3CBR%20%2F%3Evariable%20%22vnet1_resource_group_name%22%20%7B%3CBR%20%2F%3Etype%20%3D%20string%3CBR%20%2F%3Edescription%20%3D%20%22name%20of%20the%20ressource%20group%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet1_name%22%20%7B%3CBR%20%2F%3Etype%20%3D%20string%3CBR%20%2F%3Edescription%20%3D%20%22Names%20of%20the%20hub%20virtual%20network%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet1_id%22%20%7B%3CBR%20%2F%3Edescription%20%3D%20%22Id%20of%20the%20spoke%20virtual%20network%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22allow_virtual_network_access_vnet1_to_vnet2%22%20%7B%3CBR%20%2F%3Etype%20%3D%20bool%3CBR%20%2F%3Edescription%20%3D%20%22(Optional)%20Controls%20if%20the%20VMs%20in%20the%20remote%20virtual%20network%20can%20access%20VMs%20in%20the%20local%20virtual%20network.%20default%20to%20true.%22%3CBR%20%2F%3Edefault%20%3D%20true%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22allow_forwarded_traffic_vnet1_to_vnet2%22%20%7B%3CBR%20%2F%3Etype%20%3D%20bool%3CBR%20%2F%3Edescription%20%3D%20%22(Optional)%20Controls%20if%20forwarded%20traffic%20from%20VMs%20in%20the%20remote%20virtual%20network%20is%20allowed.%20default%20to%20false.%22%3CBR%20%2F%3Edefault%20%3D%20true%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22allow_gateway_transit_vnet1_to_vnet2%22%20%7B%3CBR%20%2F%3Etype%20%3D%20bool%3CBR%20%2F%3Edescription%20%3D%20%22(Optional)%20Controls%20gatewayLinks%20can%20be%20used%20in%20the%20remote%20virtual%20network%E2%80%99s%20link%20to%20the%20local%20virtual%20network.%22%3CBR%20%2F%3Edefault%20%3D%20true%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22use_remote_gateways_vnet1_to_vnet2%22%20%7B%3CBR%20%2F%3Etype%20%3D%20bool%3CBR%20%2F%3Edescription%20%3D%20%22(Optional)%20Controls%20if%20remote%20gateways%20can%20be%20used%20on%20the%20local%20virtual%20network.%20If%20the%20flag%20is%20set%20to%20true%2C%20and%20allow_gateway_transit%20on%20the%20remote%20peering%20is%20also%20true%2C%20virtual%20network%20will%20use%20gateways%20of%20remote%20virtual%20network%20for%20transit.%20Only%20one%20peering%20can%20have%20this%20flag%20set%20to%20true.%20This%20flag%20cannot%20be%20set%20if%20virtual%20network%20already%20has%20a%20gateway.%20default%20to%20false.%22%3CBR%20%2F%3Edefault%20%3D%20false%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet2_client_id%22%20%7B%3CBR%20%2F%3Edescription%20%3D%20%22vnet2%20SP%20creds%20for%20provider%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet2_tenant_id%22%20%7B%3CBR%20%2F%3Edescription%20%3D%20%22vnet2%20SP%20creds%20for%20provider%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet2_client_secret%22%20%7B%3CBR%20%2F%3Edescription%20%3D%20%22vnet2%20SP%20creds%20for%20provider%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet2_subscription_id%22%20%7B%3CBR%20%2F%3Edescription%20%3D%20%22vnet2%20SP%20creds%20for%20provider%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet1_client_id%22%20%7B%3CBR%20%2F%3Edescription%20%3D%20%22vnet1%20SP%20creds%20for%20provider%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet1_tenant_id%22%20%7B%3CBR%20%2F%3Edescription%20%3D%20%22vnet1%20SP%20creds%20for%20provider%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet1_client_secret%22%20%7B%3CBR%20%2F%3Edescription%20%3D%20%22vnet1%20SP%20creds%20for%20provider%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3Evariable%20%22vnet1_subscription_id%22%20%7B%3CBR%20%2F%3Edescription%20%3D%20%22vnet1%20SP%20creds%20for%20provider%22%3CBR%20%2F%3E%7D%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E
Contributor

Hello, 

 

 i have two folders, one for connectivity subscription and the second for identity subscription. 

How to configure the peering between the vnet of connectivity and the vnet of identity ? 

 

How to call the  "remote_virtual_network_id" from the other folder of identity ?

 

thanks

 

hamma91_0-1647284852695.png

 

 

2 Replies
best response confirmed by hamma91 (Contributor)
Solution
Hello you need to use aliases like this ( provider version to update) :

In main.tf
provider "azurerm" {
alias = "vnet1"
version = "=2.23.0"
features {}

client_id = var.vnet1_client_id
tenant_id = var.vnet1_tenant_id
client_secret = var.vnet1_client_secret
subscription_id = var.vnet1_subscription_id

}

provider "azurerm" {
alias = "vnet2"
version = "=2.23.0"
features {}

client_id = var.vnet2_client_id
tenant_id = var.vnet2_tenant_id
client_secret = var.vnet2_client_secret
subscription_id = var.vnet2_subscription_id

}

resource "azurerm_virtual_network_peering" "peer-to-vnet1" {
name = "peer-to-${var.vnet1_name}"
resource_group_name = var.vnet2_resource_group_name
virtual_network_name = var.vnet2_name
remote_virtual_network_id = var.vnet1_id
allow_virtual_network_access = var.allow_virtual_network_access_vnet2_to_vnet1
allow_forwarded_traffic = var.allow_forwarded_traffic_vnet2_to_vnet1
allow_gateway_transit = var.allow_gateway_transit_vnet2_to_vnet1
use_remote_gateways = var.use_remote_gateways_vnet2_to_vnet1
provider = azurerm.vnet2
}

resource "azurerm_virtual_network_peering" "peer-to-vnet2" {
name = "peer-to-${var.vnet2_name}"
resource_group_name = var.vnet1_resource_group_name
virtual_network_name = var.vnet1_name
remote_virtual_network_id = var.vnet2_id
allow_virtual_network_access = var.allow_virtual_network_access_vnet1_to_vnet2
allow_forwarded_traffic = var.allow_forwarded_traffic_vnet1_to_vnet2
allow_gateway_transit = var.allow_gateway_transit_vnet1_to_vnet2
use_remote_gateways = var.use_remote_gateways_vnet1_to_vnet2
provider = azurerm.vnet1
}
In variables.tf

#Varibles related to Vnet 2 : spoke

variable "vnet2_resource_group_name" {
type = string
description = "name of the ressource group"
}
variable "vnet2_name" {
type = string
description = "Names of the spoke virtual network"
}
variable "vnet2_id" {
description = "Id of the spoke virtual network"
}
variable "allow_virtual_network_access_vnet2_to_vnet1" {
type = bool
description = "(Optional) Controls if the VMs in the remote virtual network can access VMs in the local virtual network. default to true."
default = true
}
variable "allow_forwarded_traffic_vnet2_to_vnet1" {
type = bool
description = "(Optional) Controls if forwarded traffic from VMs in the remote virtual network is allowed. default to false."
default = true
}
variable "allow_gateway_transit_vnet2_to_vnet1" {
type = bool
description = "(Optional) Controls gatewayLinks can be used in the remote virtual network’s link to the local virtual network."
default = false
}
variable "use_remote_gateways_vnet2_to_vnet1" {
type = bool
description = "(Optional) Controls if remote gateways can be used on the local virtual network. If the flag is set to true, and allow_gateway_transit on the remote peering is also true, virtual network will use gateways of remote virtual network for transit. Only one peering can have this flag set to true. This flag cannot be set if virtual network already has a gateway. default to false."
default = false
}

#variables related to Vnet 1 : hub
variable "vnet1_resource_group_name" {
type = string
description = "name of the ressource group"
}
variable "vnet1_name" {
type = string
description = "Names of the hub virtual network"
}
variable "vnet1_id" {
description = "Id of the spoke virtual network"
}
variable "allow_virtual_network_access_vnet1_to_vnet2" {
type = bool
description = "(Optional) Controls if the VMs in the remote virtual network can access VMs in the local virtual network. default to true."
default = true
}
variable "allow_forwarded_traffic_vnet1_to_vnet2" {
type = bool
description = "(Optional) Controls if forwarded traffic from VMs in the remote virtual network is allowed. default to false."
default = true
}
variable "allow_gateway_transit_vnet1_to_vnet2" {
type = bool
description = "(Optional) Controls gatewayLinks can be used in the remote virtual network’s link to the local virtual network."
default = true
}
variable "use_remote_gateways_vnet1_to_vnet2" {
type = bool
description = "(Optional) Controls if remote gateways can be used on the local virtual network. If the flag is set to true, and allow_gateway_transit on the remote peering is also true, virtual network will use gateways of remote virtual network for transit. Only one peering can have this flag set to true. This flag cannot be set if virtual network already has a gateway. default to false."
default = false
}
variable "vnet2_client_id" {
description = "vnet2 SP creds for provider"
}
variable "vnet2_tenant_id" {
description = "vnet2 SP creds for provider"
}
variable "vnet2_client_secret" {
description = "vnet2 SP creds for provider"
}
variable "vnet2_subscription_id" {
description = "vnet2 SP creds for provider"
}
variable "vnet1_client_id" {
description = "vnet1 SP creds for provider"
}
variable "vnet1_tenant_id" {
description = "vnet1 SP creds for provider"
}
variable "vnet1_client_secret" {
description = "vnet1 SP creds for provider"
}
variable "vnet1_subscription_id" {
description = "vnet1 SP creds for provider"
}