---
title: "Luke Murray (@lukemurraynz) skills · skilld"
canonical_url: "https://skilld.dev/gh/lukemurraynz"
meta:
  description: "9 agent skills written by Luke Murray on skilld."
  "og:description": "9 agent skills written by Luke Murray."
  "og:title": "Luke Murray on skilld"
---

`

![Avatar for Luke Murray](https://skilld.dev/_img/avatar?url=https%3A%2F%2Fgithub.com%2Flukemurraynz.png)

# **Luke Murray**

[@lukemurraynz](https://github.com/lukemurraynz)person

Client Advisor Architect, Azure Solutions Architect Expert, Microsoft Azure MVP & Technologist.

9 skills 1 Hamilton, New Zealand Synced 1 month ago

[GitHub](https://github.com/lukemurraynz) [Website](https://linktr.ee/lukemurray)

## Skills

### [lukemurraynz/hve-agent-skills](https://skilld.dev/gh/lukemurraynz/hve-agent-skills)

Production-hardened AI coding-agent skills for Azure platform work

9 skills 1

`npx skilld add lukemurraynz/hve-agent-skills`

- [

  **/aks-cluster-architecture**1

  AKS cluster architecture decisions for new Azure Kubernetes Service projects: AKS Automatic vs Standard, networking topology, dual-stack (IPv4/IPv6), Kubernetes version and OS currency, node pool strategy, identity, production NetworkPolicy, namespaces, autoscaling, ingress and Gateway API, observability, operations, resilience, GPU and AI workloads, GPU partitioning (MIG, time-slicing, MPS), batch scheduling (Kueue), AKS on bare metal, AI Runway and KAITO model serving, AKS MCP server access, kars (Agent Reference Stack for Kubernetes) for agent isolation, Kata MicroVM pod sandboxing, Azure Kubernetes Fleet Manager, multi-cluster governance, update orchestration, resource placement, cross-cluster networking, and cost. WHEN: designing new AKS clusters, reviewing production readiness, choosing CNI or outbound connectivity, planning node pools, defining namespace, network and security controls, evaluating Fleet Manager, deploying AI agent runtimes on AKS, or making hard-to-reverse infrastructure decisions. /aks-cluster-architecture by lukemurraynz](https://skilld.dev/gh/lukemurraynz/hve-agent-skills/aks-cluster-architecture)
- [

  **/azure-sre-agent**1

  Design, configure, review, and operate production-grade Azure SRE Agent capabilities: response plans, scheduled tasks, HTTP triggers, custom agents, autonomous and review workflows, approval guardrails, AMBA observability, source RCA, connectors, MCP, governance hooks, WAF reviews, AI Foundry posture, Digital Native governance, postmortem generation, and KT discipline. /azure-sre-agent by lukemurraynz](https://skilld.dev/gh/lukemurraynz/hve-agent-skills/azure-sre-agent)
- [

  **/container-supply-chain**1

  Production implementation guide for new container image supply-chain security: OCI image signing, digest-first builds, GitHub artifact attestations, Cosign keyless signing, optional Notation/ACR signing, Rekor audit lookup, SBOM generation and attestation, vulnerability scanning, waiver governance, SLSA Build track evidence, deployment admission gates, and artifact-leakage prevention. USE FOR: implementing build-sign-attest-scan-verify pipelines, hardening GHCR or ACR container release workflows, verifying image provenance, configuring Kubernetes/AKS deployment gates, preventing Docker/package artifact leakage, and producing auditable supply-chain records. /container-supply-chain by lukemurraynz](https://skilld.dev/gh/lukemurraynz/hve-agent-skills/container-supply-chain)
- [

  **/dependabot-configuration**1

  Create, review, and harden GitHub Dependabot configuration for new or existing repositories. Use for .github/dependabot.yml, Dependabot version updates, Dependabot security updates, grouped updates, multi-ecosystem groups, private registries, Dependabot secrets, GitHub Actions updates, Dependabot automation workflows, and zizmor validation of Dependabot and workflow supply-chain hygiene. /dependabot-configuration by lukemurraynz](https://skilld.dev/gh/lukemurraynz/hve-agent-skills/dependabot-configuration)
- [

  **/drasi**1

  USE FOR: Drasi continuous-query solutions - real-time queries, change detection, reactive events, data-trigger pipelines on Drasi Server, Drasi for Kubernetes, or drasi-lib. Router: load bundle guides as needed. DO NOT USE for non-Drasi messaging (event-driven-messaging) or pure AKS/ACA hosting (aks-cluster-architecture, azure-container-apps). /drasi by lukemurraynz](https://skilld.dev/gh/lukemurraynz/hve-agent-skills/drasi)
- [

  **/hitl-design-patterns**1

  Design human-in-the-loop (HITL) approval gates for AI agent workflows. Use when you need to decide "where do I put a human approval gate", "should this agent action need confirmation", "classify this action's reversibility", "design the confirmation UX", "set a timeout and fallback policy", "define an escalation path", or "wire HITL into MCP / MAF / CopilotKit / Copilot Studio". Covers maker-checker / four-eyes approval, confirmation dialogs, fail-closed timeouts, and audit. Do not use for general security review, runtime policy enforcement (use agent-governance-toolkit instead), or fully automated loops with no human decision point. Pairs with owasp-agentic for the threat-model perspective (ASI09). /hitl-design-patterns by lukemurraynz](https://skilld.dev/gh/lukemurraynz/hve-agent-skills/hitl-design-patterns)
- [

  **/identity-managed-identity**1

  Azure service-to-service (workload) identity: managed identity, user-assigned identity, Azure RBAC, passwordless Azure SDK connections, AKS workload identity, Azure DevOps Workload Identity Federation, GitHub Actions OIDC to Azure, and federated credential troubleshooting. Use when the user says "use managed identity", "passwordless Azure auth", "remove connection strings or keys", "federated credential", "workload identity federation", "GitHub Actions OIDC to Azure", "AKS workload identity", or "DefaultAzureCredential". Do NOT use for human sign-in, MFA, Conditional Access, or B2C / External ID consumer login ; use a human-identity (Entra) skill instead. /identity-managed-identity by lukemurraynz](https://skilld.dev/gh/lukemurraynz/hve-agent-skills/identity-managed-identity)
- [

  **/rust-patterns**1

  USE FOR: Rust implementation recipes for new Rust 2024 services, libraries, CLIs, and workspace scaffolds - Cargo setup, error types, async patterns, serde/config, gRPC/Protobuf, HTTP/axum, OpenTelemetry/tracing, testing, quality gates, API design, production readiness, and security/supply-chain checks. Pairs with \`rust.instructions.md\` and \`rust-tests.instructions.md\`. Load this skill when Copilot needs working Rust code patterns or configuration guidance. /rust-patterns by lukemurraynz](https://skilld.dev/gh/lukemurraynz/hve-agent-skills/rust-patterns)
- [

  **/typespec-api-design**1

  Design new API-first, contract-first contracts with TypeSpec, OpenAPI/swagger output, Azure data-plane and ARM patterns, versioning, pagination, LROs, CI validation, and agent-ready API boundaries. WHEN: create API spec, API-first design, contract-first, scaffold TypeSpec project, generate OpenAPI or swagger, define REST contract, add API versioning, define LRO, migrate OpenAPI to TypeSpec, Azure API review, SpecKit API. /typespec-api-design by lukemurraynz](https://skilld.dev/gh/lukemurraynz/hve-agent-skills/typespec-api-design)

Curated skills from @lukemurraynz. Checked GitHub just now