Updated May 12, 2026
Azure hub-spoke network architecture template
Quick answer
An Azure hub-spoke network puts shared connectivity and security services in a hub virtual network and isolates workloads in spoke virtual networks.
Cloudeval can help diagram, review, and explain this pattern from Azure project context.

What you can expect
A practical path from source input to diagram, report context, docs, exports, and the first AI question to ask.
Start here
Use this to
Understand and review an Azure hub-spoke network pattern with diagrams and evidence.
Best source to use
Confirm routing, DNS, firewall, gateway, and private endpoint relationships. Those details determine whether the hub-spoke design is accurate.
What you need
- A hub-spoke design, ARM/Bicep output, or live Azure context.
- Knowledge of the VNets, routes, firewalls, gateways, DNS, and private endpoints involved.
- A Cloudeval project if you want reports or AI answers.
What you get
- A component-level architecture explanation.
- A diagram workflow for Azure hub-spoke review.
- Review questions for exposure, routing, and evidence quality.
Fastest path to a useful result
- 1Identify the hub VNet and spoke VNets.
- 2Map firewall, gateway, route table, DNS, and private endpoint relationships.
- 3Create or import the Azure project in Cloudeval.
- 4Review the diagram and ask one question about exposure paths.
When this works best
Use this as a public Azure pattern reference or as a review checklist for your own Cloudeval project.
Decision guide
| Check | Cloudeval path | Note |
|---|---|---|
| Hub | Shared ingress, egress, security, DNS, and monitoring. | Centralize shared controls. |
| Spokes | Workload VNets and subnets. | Keep workload boundaries clear. |
| Review focus | Routing, firewall, private endpoints, and exposure. | Missing relationships should be investigated. |
| Output | Diagram, reports, and AI questions. | Use exports for stakeholder review. |
Who this is for
- Azure network architects
- Platform teams
- Security reviewers
- Consultants building review material
How it works
- 1Define the hub virtual network for shared ingress, egress, and security services.
- 2Place workload virtual networks in spokes with clear routing and segmentation boundaries.
- 3Represent firewalls, gateways, route tables, private endpoints, DNS, and monitoring resources where used.
- 4Create or import the Azure project in Cloudeval using ARM/Bicep output or live Azure sync.
- 5Review the architecture diagram and dependency view for missing or unexpected connections.
- 6Run reports and ask questions about exposure paths, stale context, and evidence quality.
Hub-spoke architecture components
Start with the hub virtual network, workload spoke virtual networks, and subnets.
- Add Azure Firewall or a network virtual appliance, VPN or ExpressRoute gateway, route tables, private DNS, private endpoints, monitoring, and identity controls.
- Cloudeval should explain the components in text so reviewers can understand the network without opening the editor.
Terminal and agent workflow
- Use the CLI to create a project from an ARM template when the architecture is described as IaC.
- Use Cloudeval chat or MCP-enabled agents to ask which paths are exposed and which report findings support the answer.
- Export diagrams from the CLI or app when the template needs to become review material.
How to trust the result
- Check route tables, peering, DNS, and gateway paths before treating the diagram as accurate.
- Keep workload spokes isolated unless a shared service truly needs access.
- Use private endpoints and firewall rules as review items, not decorations.
FAQ
What is the purpose of an Azure hub-spoke architecture?
It centralizes shared services such as connectivity, security inspection, DNS, and monitoring while keeping workloads isolated in separate spokes.
Can Cloudeval review a hub-spoke architecture?
Yes, when the architecture is represented in a Cloudeval Azure project with enough resource, graph, and report context.
Can this template become a public diagram?
Only after a sanitization flow removes resource names, IDs, IPs, account metadata, screenshots, and sensitive findings.
Related pages
Build this workflow in Cloudeval
Start with a Cloudeval Azure project, then connect diagrams, reports, source links, CLI automation, and MCP-compatible agent workflows around the same source of truth.
