Azure China - Alibaba China - Alibaba Global - Azure Europe

1. Introduction

The goal of this document is to provide information on using Terraform to deploy Aviatrix Azure + Alibaba in China, providing connectivity to a symmetrical layout in Europe for end to end testing.
There are a few options on connecting to China:
OPT1:- Europe Azure Transit > S2C < China Azure Transit
OPT2:- Europe Azure Transit > Europe Ali Transit > S2C < China Ali Transit < China Azure Transit
OPT3:- As above but with Europe Ali Transit > S2C/VPC Peering < China Ali Transit
(VPC Peering leveraged, CEN is another option, but this is not covered here)

The code can be used to apply OPT1 to OPT3, the code is setup currently to leverage OPT3 using ‘vpc peering’, largely because this offers a better throughput and a slight improvement on latency compared to the other two options.
The code can easily be customized to achieve OPT1 and OPT2 for testing
CEN has not been dealt with here (customer requirement didn’t extend here so this hasn’t been reviewed)

The Terraform code used for the China deployment leveraged Jorge Cortes’ Repo (see below)

1.1 References

(official Aviatrix documentation)
Terraform code Repos:
(Azure Controller in China)
(Azure Transit + NSG in China)
(Alibaba Transit + NSG in China)

2. Azure Controller - China

Deployment in China requires a dedicated Aviatrix Controller / Copilot, the ‘Azure Controller in China’ link above pretty much covers the deployment so won’t be delved into further.

2.1 Don’t forget to register Azure Resource Providers (RPs)

Easy to forget as the Azure China subscription will be ‘new’, therefore the RPs will need to be registered.
You can add ‘skip_provider_registration = false ‘ to the terraform provider BUT it’s quicker and easier to get the RP registration done beforehand.

Here the Terraform provider shows the registration was set to ‘true’ to skip as the RPs were registered using the ‘az cli’

2.1.2 Which RPs to register

As a minimum at least the following (

2.1.3 Where and how to register RPs?

Register via the Azure portal/console or using az cli, see link below:

2.1.4 ICP cert domain


+ ICP cert domain (Internet Content Provider) license is required for our SSL connectivity. The following are registered, adding the 2nd level domain ‘’ is sufficient

Where to add this?


3. Deploying

There are two Terraform repos ‘ALIAZCHINA’ and ‘ALIAZGLOBAL’, the former deploys in China and the latter deploys in EUROPE (though can be changed to US or other region).
Check the respective repo READMEs for additional info.

3.1 Summary of Deployment

Deploy ALIAZCHINA first
Obtain the ALI China transit private IPs and furnish the ALIAZGLOBAL repo ‘’ with these (s2c)
Obtain the ALI Global transit private IPs and furnish the ALIAZCHINA repo ‘’ with these (for s2c)





3.2 Repo ‘aliazchina’ Terraform code

Check this GitHub repo’s README for more details.

3.3 Repo ‘aliazglobal’ Terraform code

Check this GitHub repo’s README for more details.

4.0 Copilot output showing the ALI Global to ALI China S2C

LHS = Copilot in Global
RHS =Copilot in China
Want to print your doc?
This is not the way.
Try clicking the ⋯ next to your doc name or using a keyboard shortcut (
) instead.