Chapter 3 of 6 · Before you start

Private networking, DNS, and controlled egress

Governed foundation 3 hours in a non-production POC

Chapter 3 of 6

Confirm these requirements:

  • The approved nonproduction VNet, route table, delegated Agent Service subnet, and private-endpoint subnet exist in the recorded scope. The landing-zone owner checks their resource IDs and the approved execution host reaches the VNet. (Microsoft Foundry platform baseline guide.)
  • The parameter file has the approved VNet and private-endpoint subnet resource IDs.
  • Foundry, Storage, Azure AI Search, Cosmos DB, and Key Vault exist in that exact scope.
  • Microsoft.App, Microsoft.CognitiveServices, Microsoft.DocumentDB, Microsoft.KeyVault, Microsoft.Network, Microsoft.Search, and Microsoft.Storage are registered.
  • The network deployment operator has time-bound Network Contributor on the exact resource group.
  • The DNS operator has time-bound Private DNS Zone Contributor on the resource group that holds the seven zones, or on every reused zone.
  • Preflight has both operator object IDs and every exact DNS assignment scope.
  • Each service owner will approve the private endpoint connection on their service. The network deployment operator does not receive that approval role through this session.
  • The network, DNS, firewall, and landing-zone owners approved the topology, address space, DNS pattern, route, and firewall next hop.
  • An existing host inside the approved private network can resolve the service FQDNs.
  • The approved change record names the cutover owner, restore owner, and record location.

Use the approved execution host for connectivity and cutover. Keep workloads out of the delegated Agent Service subnet.

Implementation files#

TypeFileConsumer
Deploymentartifacts/infra/network/main.bicepThe network deployment pipeline
Deploymentartifacts/environments/sandbox.bicepparamThe network deployment pipeline

Session 02

Private networking, DNS, and controlled egress slide deck