A Private Resolver Whose Rules Forward and Whose VNets Are Linked
A resolver is five resources - endpoints, ruleset, rules and VNet links - and the half-built state most sit in resolves Azure names and forwards nothing to on-premises; a ruleset not linked to a VNet applies to nothing; and each endpoint needs its own delegated subnet. All five created, forwarding rules required, VNet links expected (none by name), the inbound address exported.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "dns_private_resolver" {
source = "www.iac-bazaar.com/iac-bazaar/azure-dns-private-resolver/azure"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
azure-dns-private-resolver
An Azure DNS Private Resolver: an inbound endpoint on-premises can query,
an outbound endpoint that forwards the domains you name to the servers
you name, linked to the VNets that should use it. Works with Terraform
and OpenTofu (>= 1.6), azurerm provider >= 4.0, < 5.0.
A resolver with no ruleset forwards nothing. Resolver, endpoints, ruleset, rules and links are all created.
A ruleset not linked to a VNet applies to nothing. Links are
expected; none needs accept_unlinked_ruleset.
The endpoints need delegated subnets (Microsoft.Network/dnsResolvers,
/28 or larger), one each.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
azure-private-dns
A self-contained Azure Private DNS zone with virtual-network links and optional record sets for private name resolution across VNets and Private Endpoints - VM auto-registration off by default.
azure-dns-zone
An Azure public DNS zone plus a map-driven set of record sets - A, AAAA, CNAME, TXT, MX, NS, CAA and SRV - with relative naming, verbatim TXT values, and apex footgun guards.
akamai-edge-dns-zone
Authoritative Edge DNS zone with full recordset management on Akamai's DDoS-resilient anycast network.
akamai-gtm-failover
Global Traffic Management domain with datacenters and failover or weighted-round-robin properties plus liveness tests.
gcp-cloud-dns
Public/private managed zones with record sets, DNSSEC, forwarding and peering configs.
cloudflare-dns
Zone DNS records, security settings, and managed WAF rulesets for a Cloudflare zone - provider v5 ready.