All skills
lukemurraynz avatar

/azure-sre-agent

@2cc2455

Design, configure, review, and operate production-grade Azure SRE Agent capabilities: response plans, scheduled tasks, HTTP triggers, custom agents, autonomous and review workflows, approval guardrails, AMBA observability, source RCA, connectors, MCP, governance hooks, WAF reviews, AI Foundry posture, Digital Native governance, postmortem generation, and KT discipline.

Use this Skill: https://skilld.dev/gh/lukemurraynz/hve-agent-skills/azure-sre-agent

This session only. Nothing lands on disk.

referenceshttp-trigger-auth-bridges.md

≈791 tokens on demand. Your agent reads this file only when SKILL.md points to it.

HTTP trigger auth bridges

Use this reference when the calling system cannot present the Azure token that Azure SRE Agent expects directly.

Microsoft Learn currently points to three bridge patterns:

  • Azure Functions
  • Logic Apps
  • Azure API Management

Choose a bridge

Bridge Best for Why choose it
Azure Functions CI/CD handlers, custom logic, payload shaping Most flexible code-first bridge with managed identity support
Logic Apps Low-code webhook relay Fastest path when you want workflow-level orchestration
Azure API Management Central ingress and policy Strongest fit for shared ingress governance, throttling, and transformation

Safety defaults

  1. Keep the downstream HTTP trigger disabled until bridge auth, payload validation, and replay controls are tested.
  2. Treat the final SRE Agent token audience as [VERIFY] because the official docs still conflict.
  3. Require correlation and replay-control headers.
  4. Keep downstream SRE Agent workflows in Review until the bridge proves stable and bounded.
  5. Do not forward secrets or raw customer data in the payload body.

Current docs conflict

[VERIFY]
Claim = supported token audience for Azure SRE Agent HTTP trigger invocation
WhereToCheck = https://learn.microsoft.com/en-us/azure/sre-agent/http-triggers
Conflict = one section shows Azure Resource Manager bearer-token guidance, while troubleshooting says the audience must match the SRE Agent app ID instead of https://management.azure.com
Action = verify the current supported audience before shipping the bridge to production

What this bundle provides

  • bundles/http-trigger-auth-bridges/templates/azure-functions-managed-identity-relay.yaml
  • bundles/http-trigger-auth-bridges/templates/logic-app-managed-identity-relay.yaml
  • bundles/http-trigger-auth-bridges/templates/apim-front-door-relay.yaml
  • bundles/http-trigger-auth-bridges/checklists/http-trigger-auth-bridge.md

These are design templates, not import-ready Azure resources. Replace placeholders, validate current platform behavior, and test in non-production first.

Validate before cutover

  • bearer-token acquisition path works end to end
  • trigger stays disabled until auth is proven
  • 404 on disabled triggers is expected during test stages
  • 250-turn cap remains acceptable for the downstream workflow
  • replay and idempotency handling are documented
  • rollback path exists for the bridge and the downstream trigger

Sources

Primary source: references/source-map.md → Microsoft Learn http-triggers

Source: SKILL.md on GitHub

No alerts8d3 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The Azure SRE Agent skill provides a production-grade framework for managing Azure infrastructure using AI agents. It incorporates extensive safety documentation, approval-based hooks, and least-privilege role templates. The 'low' verdict is assigned due to the inherent risk of indirect prompt injection when the agent processes external incident data and source code, a necessary function for its SRE capabilities.

  • Socket8d

    No alerts

  • Snyk8d

    Risk: LOW · No issues

Signed by skilld at 2cc2455. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated last month
compatibility
Azure SRE Agent; GitHub Copilot agent skills; new projects only
Other metadata
metadata
{
  "last_verified": "2026-08-25",
  "version": "2.23.3",
  "risk": "critical",
  "last_updated": "2026-08-25"
}

README badge

README badge for lukemurraynz/hve-agent-skills/azure-sre-agent