@@ -7,15 +7,17 @@ resource "azurerm_virtual_network" "core" {
77 lifecycle { ignore_changes = [tags ] }
88
99 subnet {
10- name = " AzureBastionSubnet"
11- address_prefixes = [local . bastion_subnet_address_prefix ]
12- security_group = azurerm_network_security_group. bastion . id
10+ name = " AzureBastionSubnet"
11+ address_prefixes = [local . bastion_subnet_address_prefix ]
12+ security_group = azurerm_network_security_group. bastion . id
13+ default_outbound_access_enabled = false
1314 }
1415
1516 subnet {
16- name = " AzureFirewallSubnet"
17- address_prefixes = [local . firewall_subnet_address_space ]
18- route_table_id = var. firewall_force_tunnel_ip != " " ? azurerm_route_table. fw_tunnel_rt [0 ]. id : null
17+ name = " AzureFirewallSubnet"
18+ address_prefixes = [local . firewall_subnet_address_space ]
19+ route_table_id = var. firewall_force_tunnel_ip != " " ? azurerm_route_table. fw_tunnel_rt [0 ]. id : null
20+ default_outbound_access_enabled = false
1921 }
2022
2123 subnet {
@@ -24,6 +26,7 @@ resource "azurerm_virtual_network" "core" {
2426 private_endpoint_network_policies = " Disabled"
2527 private_link_service_network_policies_enabled = true
2628 security_group = azurerm_network_security_group. app_gw . id
29+ default_outbound_access_enabled = false
2730 }
2831
2932 subnet {
@@ -33,6 +36,7 @@ resource "azurerm_virtual_network" "core" {
3336 private_link_service_network_policies_enabled = true
3437 security_group = azurerm_network_security_group. default_rules . id
3538 route_table_id = azurerm_route_table. rt . id
39+ default_outbound_access_enabled = false
3640
3741 delegation {
3842 name = " delegation"
@@ -50,6 +54,7 @@ resource "azurerm_virtual_network" "core" {
5054 private_endpoint_network_policies = " Disabled"
5155 security_group = azurerm_network_security_group. default_rules . id
5256 route_table_id = azurerm_route_table. rt . id
57+ default_outbound_access_enabled = false
5358 }
5459
5560 subnet {
@@ -58,6 +63,7 @@ resource "azurerm_virtual_network" "core" {
5863 private_endpoint_network_policies = " Disabled"
5964 security_group = azurerm_network_security_group. default_rules . id
6065 route_table_id = azurerm_route_table. rt . id
66+ default_outbound_access_enabled = false
6167 }
6268
6369 subnet {
@@ -66,6 +72,7 @@ resource "azurerm_virtual_network" "core" {
6672 private_endpoint_network_policies = " Disabled"
6773 security_group = azurerm_network_security_group. default_rules . id
6874 route_table_id = azurerm_route_table. rt . id
75+ default_outbound_access_enabled = false
6976
7077 delegation {
7178 name = " delegation"
@@ -84,7 +91,7 @@ resource "azurerm_virtual_network" "core" {
8491 address_prefixes = [local . airlock_notifications_subnet_address_prefix ]
8592 private_endpoint_network_policies = " Disabled"
8693 security_group = azurerm_network_security_group. default_rules . id
87-
94+ default_outbound_access_enabled = false
8895 delegation {
8996 name = " delegation"
9097
@@ -102,6 +109,7 @@ resource "azurerm_virtual_network" "core" {
102109 private_endpoint_network_policies = " Disabled"
103110 security_group = azurerm_network_security_group. default_rules . id
104111 route_table_id = azurerm_route_table. rt . id
112+ default_outbound_access_enabled = false
105113 }
106114
107115 subnet {
@@ -110,13 +118,15 @@ resource "azurerm_virtual_network" "core" {
110118 private_endpoint_network_policies = " Disabled"
111119 security_group = azurerm_network_security_group. default_rules . id
112120 route_table_id = azurerm_route_table. rt . id
121+ default_outbound_access_enabled = false
113122
114123 service_endpoints = [" Microsoft.ServiceBus" ]
115124 }
116125
117126 subnet {
118- name = " AzureFirewallManagementSubnet"
119- address_prefixes = [local . firewall_management_subnet_address_prefix ]
127+ name = " AzureFirewallManagementSubnet"
128+ address_prefixes = [local . firewall_management_subnet_address_prefix ]
129+ default_outbound_access_enabled = false
120130 }
121131}
122132
0 commit comments