Service Endpoint Policies

Overview

The serviceEndpointPolicy builder creates an Azure service endpoint policy that can be attached to a subnet. This lets you restrict a subnet’s service endpoint access to specific Azure resources such as storage accounts. To learn more, reference the Azure Docs.

  • Service Endpoint Policy (Microsoft.Network/serviceEndpointPolicies)

Builder Keywords

Applies ToKeywordPurpose
serviceEndpointPolicynameName of the service endpoint policy resource
serviceEndpointPolicyadd_definitionsAdds one or more policy definitions
serviceEndpointPolicyadd_tag / add_tagsAdds tags to the policy resource
serviceEndpointPolicydepends_onAdds explicit resource dependencies
serviceEndpointPolicyDefinitionnameName of the policy definition
serviceEndpointPolicyDefinitiondescriptionOptional description for the policy definition
serviceEndpointPolicyDefinitionserviceThe Azure service protected by the policy definition, for example EndpointServiceType.Storage
serviceEndpointPolicyDefinitionadd_service_resourcesAdds Farmer-managed service resources to the definition
serviceEndpointPolicyDefinitionlink_to_service_resourcesAdds externally managed service resources to the definition
subnetassociate_service_endpoint_policiesAssociates one or more service endpoint policies with a manually defined subnet
subnetSpecadd_service_endpoint_policiesAssociates one or more service endpoint policies with an automatically carved subnet

Example

#r "nuget:Farmer"

open Farmer
open Farmer.Builders
open Farmer.Network

let storage = storageAccount { name "policyteststorage" }

let storagePolicy =
    serviceEndpointPolicy {
        name "storage-policy"

        add_definitions [
            serviceEndpointPolicyDefinition {
                name "allow-storage"
                description "Allow access to a specific storage account"
                service EndpointServiceType.Storage
                add_service_resources [ storage ]
            }
        ]
    }

let network =
    vnet {
        name "my-vnet"
        add_address_spaces [ "10.28.0.0/16" ]

        add_subnets [
            subnet {
                name "services"
                prefix "10.28.0.0/24"
                add_service_endpoints [ EndpointServiceType.Storage, [ Location.EastUS ] ]
                associate_service_endpoint_policies [ storagePolicy ]
            }
        ]
    }

arm {
    location Location.EastUS
    add_resources [ storage; storagePolicy; network ]
}