All skills
aktsmm avatar

/azure-infra-validation

@848fd9b
by yamapanaktsmm/agent-skills26 stars
4

Build and validate Azure infrastructure in a lab or sandbox using Azure CLI and official Microsoft docs. Use when creating verification environments, provisioning hub-and-spoke VNets, VPN Gateway or ExpressRoute-adjacent validation labs, checking subscription/tenant access, debugging Azure deployment constraints, comparing before/after route behavior, or cleaning up lab resources. Triggers on 'Azure 検証', '検証環境', 'PoC', 'sandbox', 'lab', 'Azure CLI で構築', 'VPN Gateway', 'VNet peering', 'BGP', 'route validation', 'summarizedGatewayPrefixes', 'デプロイして検証', 'インフラ検証'.

Use this Skill: https://skilld.dev/gh/aktsmm/agent-skills/azure-infra-validation

This session only. Nothing lands on disk.

referencesvalidation-runbook.md

≈489 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure Infra Validation Runbook

Deployment Constraint Branches

  • VpnGw1-5 non-AZ not allowed: switch to an AZ SKU such as VpnGw1AZ.
  • Public IPs must have zones configured: recreate Standard Public IPs with zones.
  • VNet overlap: reassign spoke address spaces.
  • useRemoteGateways fails early: apply it only after the hub gateway is complete.
  • MFA / tenant mismatch: switch tenant or re-login before deployment.

Phase Detail

  1. Feasibility: write the validation goal in one line, decide whether Azure-only is enough, minimize topology, and set cleanup expectations.
  2. Scope Fix: choose lab vs production, fix tenant/subscription, and define the target observation.
  3. Official Grounding: verify prerequisites, limits, SKUs, and gaps against Microsoft Learn.
  4. Preflight: run az account show, check provider registration, region availability, SKU/zone/RBAC, and decide polling evidence.
  5. Baseline Build: create RG, hub/branch/spoke VNets, GatewaySubnet, and peering. Apply remote gateway after gateway readiness.
  6. Core Deployment: create Public IPs, VPN Gateway / Route Server / NVA, and monitor long-running resources.
  7. Connectivity: create VPN or peer connections and wait for Connected.
  8. Baseline Capture: collect BGP peer status, learned routes, route table, prefix count, and observation start time.
  9. Change: apply one setting change, capture Accepted/Succeeded/correlation ID, and wait for reconfiguration.
  10. Compare: recapture routes/status, compare route count and summarization, and separate control-plane completion from route/metric impact.
  11. Cleanup or Persist: delete one-shot labs or record why they remain.

Ready Rules

  • Do not continue before Succeeded, READY, or Connected is observed.
  • Prefer scripts/watch-az-resource-state.ps1 or scripts/check-vpn-lab-status.ps1 when available.
  • Do not claim no outage from Activity Log alone; use polling, route, health, or metrics evidence.

Source: SKILL.md on GitHub

2 warnings3mo3 checks · Risk MEDIUM
  • Gen Agent Trust Hub3mo

    The skill includes PowerShell scripts that perform command execution by calling external files located in parent directories using relative path traversal. This behavior is intended to integrate with a specific workspace structure but could lead to the execution of unintended code if the environment is compromised or misconfigured.

  • Socket3mo

    1 alert: gptSecurity

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at 848fd9b. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 19 hours ago.

Activeupdated 3 months ago
user-invocable
true
metadata
{
  "author": "yamapan (https://github.com/aktsmm)"
}
Other metadata
argument-hint
tenant ID, subscription ID, target topology, validation goal, cost/cleanup expectation

README badge

README badge for aktsmm/agent-skills/azure-infra-validation