All skills
github avatar

/azure-architecture-autopilot

@4214189 official
by githubgithub/awesome-copilot40k stars
5,040

Design Azure infrastructure using natural language, or analyze existing Azure resources to auto-generate architecture diagrams, refine them through conversation, and deploy with Bicep. When to use this skill: - "Create X on Azure", "Set up a RAG architecture" (new design) - "Analyze my current Azure infrastructure", "Draw a diagram for rg-xxx" (existing analysis) - "Foundry is slow", "I want to reduce costs", "Strengthen security" (natural language modification) - Azure resource deployment, Bicep template generation, IaC code generation - Microsoft Foundry, AI Search, OpenAI, Fabric, ADLS Gen2, Databricks, and all Azure services

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/azure-architecture-autopilot

This session only. Nothing lands on disk.

referencesazure-dynamic-sources.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure Dynamic Sources Registry

This file manages only the sources (URLs) for frequently changing information. Actual values (API version, SKU, region, etc.) are not recorded here. Always fetch the URLs below to verify the latest information before generating Bicep.


1. Bicep API Version (Always Must Fetch)

Per-service MS Docs Bicep reference. Verify the latest stable apiVersion from these URLs before use.

Service MS Docs URL
CognitiveServices (Foundry/OpenAI) https://learn.microsoft.com/en-us/azure/templates/microsoft.cognitiveservices/accounts
AI Search https://learn.microsoft.com/en-us/azure/templates/microsoft.search/searchservices
Storage Account https://learn.microsoft.com/en-us/azure/templates/microsoft.storage/storageaccounts
Key Vault https://learn.microsoft.com/en-us/azure/templates/microsoft.keyvault/vaults
Virtual Network https://learn.microsoft.com/en-us/azure/templates/microsoft.network/virtualnetworks
Private Endpoints https://learn.microsoft.com/en-us/azure/templates/microsoft.network/privateendpoints
Private DNS Zones https://learn.microsoft.com/en-us/azure/templates/microsoft.network/privatednszones
Fabric https://learn.microsoft.com/en-us/azure/templates/microsoft.fabric/capacities
Data Factory https://learn.microsoft.com/en-us/azure/templates/microsoft.datafactory/factories
Application Insights https://learn.microsoft.com/en-us/azure/templates/microsoft.insights/components
ML Workspace (Hub) https://learn.microsoft.com/en-us/azure/templates/microsoft.machinelearningservices/workspaces

Always verify child resources as well: Child resources such as accounts/projects, accounts/deployments, privateDnsZones/virtualNetworkLinks may have different API versions from their parent. Follow child resource links from the parent page to verify.

Services Not in the Table Above

The table above includes only v1 scope services. For other services, construct the URL in this format and fetch:

https://learn.microsoft.com/en-us/azure/templates/microsoft.{provider}/{resourceType}

2. Model Availability (Required When Using Foundry/OpenAI Models)

Verify whether the model name is deployable in the target region. Do not rely on static knowledge.

Verification Method URL / Command
MS Docs model availability https://learn.microsoft.com/en-us/azure/ai-services/openai/concepts/models
Azure CLI (existing resources) az cognitiveservices account list-models --name "<NAME>" --resource-group "<RG>" -o table

If the model is unavailable in the target region → Notify the user and suggest available regions/alternative models. Do not substitute without user approval.


3. Private Endpoint Mapping (When Adding New Services)

PE groupId and DNS Zone mappings can be changed by Azure. When adding new services or verification is needed:

Verification Method URL
PE DNS integration official docs https://learn.microsoft.com/en-us/azure/private-link/private-endpoint-dns

Key service mappings in service-gotchas.md are stable, but always re-verify from the URL above when adding new services.


4. Service Region Availability

Verify whether a specific service is available in a specific region:

Verification Method URL
Azure service-by-region availability https://azure.microsoft.com/en-us/explore/global-infrastructure/products-by-region/

5. Azure Updates (Secondary Awareness)

The sources below are for reference only. The primary source is always MS Docs official documentation.

Source URL Purpose
Azure Updates https://azure.microsoft.com/en-us/updates/ Service change awareness
What's New in Azure Per-service What's New pages in Docs Feature change verification

Decision Rule: When to Fetch?

Information Type Must Fetch? Rationale
API version Always fetch Changes frequently; incorrect values cause deployment failure
Model availability (name, region) Always fetch Varies by region and changes frequently
SKU list Always fetch Can change per service
Region availability Always fetch Per-service region support changes frequently. Always verify that the user-specified region is available for the service
PE groupId & DNS Zone Can reference service-gotchas.md for v1 key services; must fetch for new services or complex configurations (Monitor, etc.) Key service mappings are stable, but new/complex services are risky
Required property patterns Reference files first Near-immutable (isHnsEnabled, etc.)

Source: SKILL.md on GitHub

1 warning16d4 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill is a professional tool for Azure infrastructure management, providing design advice, architecture visualization, and Bicep-based deployment automation. It integrates with official Azure CLI tools and relies on trusted Microsoft documentation. The security analysis found no malicious patterns, with all operations being consistent with the skill's administrative purpose.

  • Socket16d

    1 alert: gptAnomaly

  • Snyk16d

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 4214189. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
  • azure
  • bicep
  • infrastructure-as-code
  • architecture-design
  • resource-analysis
  • diagram-generation
  • deployment
  • iac

README badge

README badge for github/awesome-copilot/azure-architecture-autopilot

Designs and deploys Azure infrastructure from natural language descriptions, or analyzes existing resources to generate architecture diagrams and Bicep IaC code. Includes an embedded diagram engine with 605+ Azure icons and supports modification workflows across Microsoft Foundry, Azure OpenAI, AI Search, and 200+ other Azure services.

Generated from the current SKILL.md.

Does this skill generate actual Bicep code for deployment?
Yes. After designing or analyzing an architecture, the skill generates Bicep templates and validates them before deployment via Phase 2 (bicep-generator.md) and Phase 3 (bicep-reviewer.md).
Can I use this to analyze my existing Azure infrastructure?
Yes. Path B (Phase 0) scans existing Azure resources, auto-generates a diagram, and then lets you modify the architecture through natural language conversation.
Do I need to install Python or other tools separately?
No. The diagram engine is embedded in the skill's scripts folder and runs without requiring pip install or network access.
What Azure services are supported?
All Azure services are supported. The skill includes optimized patterns for Microsoft Foundry, Azure OpenAI, AI Search, ADLS Gen2, Key Vault, Fabric, ADF, and VNet/Private Endpoint configurations.
What languages does this skill support?
The skill auto-detects your input language and responds in that same language for all interactions, prompts, and generated code.

Generated from the current SKILL.md. These answers refresh after source changes.