All skills
github avatar

/azure-architecture-autopilot

@4214189 official
by githubgithub/awesome-copilot40k stars
5,040

Design Azure infrastructure using natural language, or analyze existing Azure resources to auto-generate architecture diagrams, refine them through conversation, and deploy with Bicep. When to use this skill: - "Create X on Azure", "Set up a RAG architecture" (new design) - "Analyze my current Azure infrastructure", "Draw a diagram for rg-xxx" (existing analysis) - "Foundry is slow", "I want to reduce costs", "Strengthen security" (natural language modification) - Azure resource deployment, Bicep template generation, IaC code generation - Microsoft Foundry, AI Search, OpenAI, Fabric, ADLS Gen2, Databricks, and all Azure services

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/azure-architecture-autopilot

This session only. Nothing lands on disk.

referencesazure-common-patterns.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure Common Patterns (Stable)

This file contains only near-immutable patterns that are repeated across Azure services. Dynamic information such as API version, SKU, and region is not included here → See azure-dynamic-sources.md.


1. Network Isolation Patterns

Private Endpoint 3-Component Set

All services using PE must have the 3-component set configured:

  1. Private Endpoint — Placed in pe-subnet
  2. Private DNS Zone + VNet Link (registrationEnabled: false)
  3. DNS Zone Group — Linked to PE

If any one is missing, DNS resolution fails even with PE present, causing connection failure.

PE Subnet Required Settings

resource peSubnet 'Microsoft.Network/virtualNetworks/subnets' = {
  properties: {
    addressPrefix: peSubnetPrefix              // ← CIDR as parameter — prevent existing network conflicts
    privateEndpointNetworkPolicies: 'Disabled'  // ← Required. PE deployment fails without it
  }
}

publicNetworkAccess Pattern

Services using PE must include:

properties: {
  publicNetworkAccess: 'Disabled'
  networkAcls: {
    defaultAction: 'Deny'
  }
}

2. Security Patterns

Key Vault

properties: {
  enableRbacAuthorization: true    // Do not use Access Policy method
  enableSoftDelete: true
  softDeleteRetentionInDays: 90
  enablePurgeProtection: true
}

Managed Identity

When AI services access other resources:

identity: {
  type: 'SystemAssigned'  // or 'UserAssigned'
}

Sensitive Information

  • Use @secure() decorator
  • Do not store plaintext in .bicepparam files
  • Use Key Vault references

3. Naming Conventions (CAF-based)

rg-{project}-{env}          Resource Group
vnet-{project}-{env}        Virtual Network
st{project}{env}             Storage Account (no special characters, lowercase+numbers only)
kv-{project}-{env}           Key Vault
srch-{project}-{env}         AI Search
foundry-{project}-{env}      Cognitive Services (Foundry)

Name collision prevention: Recommend using uniqueString(resourceGroup().id)

param storageName string = 'st${uniqueString(resourceGroup().id)}'

4. Bicep Module Structure

<project>/
├── main.bicep              # Orchestration — module calls + parameter passing
├── main.bicepparam         # Environment-specific values (excluding sensitive info)
└── modules/
    ├── network.bicep           # VNet, Subnet
    ├── <service>.bicep         # Per-service modules
    ├── keyvault.bicep          # Key Vault
    └── private-endpoints.bicep # All PE + DNS Zone + VNet Link

Dependency Management

// ✅ Correct: Implicit dependency via resource reference
resource project '...' = {
  properties: {
    parentId: foundry.id  // foundry reference → automatically deploys foundry first
  }
}

// ❌ Avoid: Explicit dependsOn (use only when necessary)

5. PE Bicep Common Template

// ── Private Endpoint ──
resource pe 'Microsoft.Network/privateEndpoints@<fetch>' = {
  name: 'pe-${serviceName}'
  location: location
  properties: {
    subnet: { id: peSubnetId }
    privateLinkServiceConnections: [{
      name: 'pls-${serviceName}'
      properties: {
        privateLinkServiceId: serviceId
        groupIds: ['<groupId>']  // ← Varies by service. See service-gotchas.md
      }
    }]
  }
}

// ── Private DNS Zone ──
resource dnsZone 'Microsoft.Network/privateDnsZones@<fetch>' = {
  name: '<dnsZoneName>'  // ← Varies by service
  location: 'global'
}

// ── VNet Link ──
resource vnetLink 'Microsoft.Network/privateDnsZones/virtualNetworkLinks@<fetch>' = {
  parent: dnsZone
  name: '${dnsZone.name}-link'
  location: 'global'
  properties: {
    virtualNetwork: { id: vnetId }
    registrationEnabled: false  // ← Must be false
  }
}

// ── DNS Zone Group ──
resource dnsGroup 'Microsoft.Network/privateEndpoints/privateDnsZoneGroups@<fetch>' = {
  parent: pe
  name: 'default'
  properties: {
    privateDnsZoneConfigs: [{
      name: 'config'
      properties: { privateDnsZoneId: dnsZone.id }
    }]
  }
}

@<fetch>: Always verify the latest stable API version from MS Docs before deployment.

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill is a professional tool for Azure infrastructure management, providing design advice, architecture visualization, and Bicep-based deployment automation. It integrates with official Azure CLI tools and relies on trusted Microsoft documentation. The security analysis found no malicious patterns, with all operations being consistent with the skill's administrative purpose.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 4214189. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
  • azure
  • bicep
  • infrastructure-as-code
  • architecture-design
  • resource-analysis
  • diagram-generation
  • deployment
  • iac

README badge

README badge for github/awesome-copilot/azure-architecture-autopilot

Designs and deploys Azure infrastructure from natural language descriptions, or analyzes existing resources to generate architecture diagrams and Bicep IaC code. Includes an embedded diagram engine with 605+ Azure icons and supports modification workflows across Microsoft Foundry, Azure OpenAI, AI Search, and 200+ other Azure services.

Generated from the current SKILL.md.

Does this skill generate actual Bicep code for deployment?
Yes. After designing or analyzing an architecture, the skill generates Bicep templates and validates them before deployment via Phase 2 (bicep-generator.md) and Phase 3 (bicep-reviewer.md).
Can I use this to analyze my existing Azure infrastructure?
Yes. Path B (Phase 0) scans existing Azure resources, auto-generates a diagram, and then lets you modify the architecture through natural language conversation.
Do I need to install Python or other tools separately?
No. The diagram engine is embedded in the skill's scripts folder and runs without requiring pip install or network access.
What Azure services are supported?
All Azure services are supported. The skill includes optimized patterns for Microsoft Foundry, Azure OpenAI, AI Search, ADLS Gen2, Key Vault, Fabric, ADF, and VNet/Private Endpoint configurations.
What languages does this skill support?
The skill auto-detects your input language and responds in that same language for all interactions, prompts, and generated code.

Generated from the current SKILL.md. These answers refresh after source changes.