All skills
aktsmm avatar

/azure-env-builder

@848fd9b
by yamapanaktsmm/agent-skills26 stars
4

[Alpha] Experimental Azure environment builder for infrastructure and deployment design. Use when building Azure infrastructure, generating Bicep with AVM modules, deploying apps to App Service/AKS/Container Apps, designing Hub-Spoke/AKS/AI Foundry architectures, or creating low-cost Azure operations demos.

Use this Skill: https://skilld.dev/gh/aktsmm/agent-skills/azure-env-builder

This session only. Nothing lands on disk.

referencesreview-checklist.md

≈734 tokens on demand. Your agent reads this file only when SKILL.md points to it.

レビューチェックリスト

一般

  • 環境名とリソース命名が命名規約に従っている
  • env/<environment>/README.md に目的・スコープ・手順が記載されている
  • 認証情報・シークレットがハードコードされていない
  • タグ (環境/プロジェクト/コストセンター) が設定されている

Azure CLI 方式

  • deploy.ps1 に対象リソースグループ / サブスクリプションが明示されている
  • -WhatIf / dry-run の結果が確認済み
  • ログ / 出力が env/<environment>/logs/ に保存されている

Bicep 方式

  • az bicep build でエラーなくビルドできる
  • az bicep lint で警告がない (または理由が明記)
  • パラメータファイルにデフォルトが設定され、必須項目が明確
  • what-if の結果が確認済みで、意図しないリソース削除がない
  • 公式サンプル (MCP) を参考にしている

ネットワーク

  • VNet / サブネット設計が要件を満たしている
  • Private Endpoint が必要なリソースに設定されている
  • NSG / UDR が適切に設定されている
  • DNS 設定 (Private DNS Zone) が正しい

データサービス

  • SQL Database: TDE / 監査設定が有効
  • Cosmos DB: パーティションキー設計が適切
  • Redis: TLS 1.2 以上、AAD 認証が有効
  • バックアップ / リテンション設定が要件を満たす

コンピュート

  • AKS: プライベートクラスター設定 (必要な場合)
  • Container Apps: VNet 統合 (必要な場合)
  • App Service: VNet 統合 + Private Endpoint

監視・可観測性

  • Log Analytics Workspace が作成されている
  • Diagnostic Settings が主要リソースに設定
  • アラートルールが定義されている

セキュリティ

  • Managed Identity (User-Assigned 推奨) が設定されている
  • Key Vault 参照でシークレット管理
  • 最低限の RBAC ロールで権限設計されている
  • Microsoft Defender for Cloud の推奨事項を確認

DR・バックアップ

  • Recovery Services Vault が設定 (必要な場合)
  • バックアップポリシーが要件を満たす
  • Geo 冗長 / ゾーン冗長の設定が適切
  • Recovery Services vault / Backup Vault を作る場合、soft delete retention と削除時の運用手順(保護停止、backup data 削除、container unregister、soft-deleted instance の purge 待ち)を README または運用メモに記載している

ドキュメント

  • 手順の再現性が確認できる
  • 変更ログ / 履歴が追跡可能 (コミットや README の更新)
  • 次のアクションまたは改善点が記載されている
  • アーキテクチャ図が含まれている (推奨)

Source: SKILL.md on GitHub

2 warnings4mo4 checks · Risk SAFE
  • Gen Agent Trust Hub4mo

    The skill is a comprehensive Azure infrastructure automation tool that uses Azure Bicep and Azure Verified Modules (AVM) to scaffold and deploy enterprise environments. It follows security best practices, such as using Managed Identities and Azure Key Vault for secret management. No malicious patterns, obfuscation, or unauthorized data access were detected. All external references target official Microsoft domains or well-known infrastructure tools like Flux CD.

  • Socket4mo

    No alerts

  • Snyk4mo

    Risk: MEDIUM · 2 issues

  • Runlayer7mo

    17/17 files flagged

Signed by skilld at 848fd9b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 18 hours ago.

Activeupdated 3 months ago
argument-hint
構築したい Azure 構成、アプリ、制約条件
user-invocable
true
metadata
{
  "author": "yamapan (https://github.com/aktsmm)"
}

README badge

README badge for aktsmm/agent-skills/azure-env-builder