All skills
microsoft avatar

/azure-enterprise-infra-planner

@5f24d7e official

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesconstraintsdata-relational.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Data (Relational) Pairing Constraints

SQL Server

Paired With Constraint
SQL Database Databases are child resources — must reference this server as parent.
Key Vault (TDE) Key Vault must have enablePurgeProtection: true. Must be in same Azure AD tenant. Server needs GET, WRAP KEY, UNWRAP KEY permissions on key. TDE protector setup fails if Key Vault soft-delete and purge-protection are not both enabled.
Virtual Network Use Microsoft.Sql/servers/virtualNetworkRules to restrict access to specific subnets. Subnets need Microsoft.Sql service endpoint.
Private Endpoint Set publicNetworkAccess: 'Disabled' when using private endpoints exclusively.
Elastic Pool Databases using elastic pools reference elasticPoolId — server must host both pool and databases. Hyperscale elastic pools cannot be created from non-Hyperscale pools.
Failover Group Both primary and secondary servers must exist. Databases to be replicated must belong to the primary server. Failover group from zone-redundant to non-zone-redundant Hyperscale elastic pool fails silently (geo-secondary shows "Seeding 0%").

SQL Database

Paired With Constraint
SQL Server Must be deployed as child of the parent SQL Server. Location must match.
Elastic Pool elasticPoolId must reference a pool on the same server. Cannot set sku when using elastic pool (it inherits pool SKU).
Zone Redundancy Only available in GeneralPurpose, BusinessCritical, and Hyperscale tiers. Not available in DTU tiers. General Purpose zone redundancy is only available in selected regions. Hyperscale zone redundancy can only be set at creation — cannot modify after provisioning; must recreate via copy/restore/geo-replica.
Serverless Only available in GeneralPurpose tier. SKU name uses GP_S_Gen5_* pattern.
Hyperscale Reverse migration from Hyperscale to General Purpose is supported within 45 days of the original migration. Databases originally created as Hyperscale cannot reverse migrate.
Hyperscale Elastic Pool Cannot be created from a non-Hyperscale pool. Cannot be converted to non-Hyperscale (one-way only). Named replicas cannot be added to Hyperscale elastic pools (UnsupportedReplicationOperation). Zone-redundant Hyperscale elastic pools require databases with ZRS/GZRS backup storage — cannot add LRS-backed databases.
Failover Group Failover group from zone-redundant to non-zone-redundant Hyperscale elastic pool fails silently (geo-secondary shows "Seeding 0%").
Backup Redundancy GeoZone only available in select regions. Local not available in all regions.

MySQL Flexible Server

Paired With Constraint
VNet (private access) Requires a dedicated subnet delegated to Microsoft.DBforMySQL/flexibleServers. Subnet must have no other resources.
Private DNS Zone For VNet-integrated (private access) servers, use the zone name {name}.mysql.database.azure.com (not privatelink.*). The privatelink.mysql.database.azure.com zone is used for Private Endpoint connectivity only. Provide privateDnsZoneResourceId and the DNS zone must be linked to the VNet.
High Availability ZoneRedundant HA requires GeneralPurpose or MemoryOptimized tier. Not available with Burstable.
Geo-Redundant Backup Must be enabled at server creation time. Cannot be changed after creation. Not available in all regions.
Storage Auto-Grow Storage can only grow, never shrink. Enabled by default.
Read Replicas Source server must have backup.backupRetentionDays > 1. Replica count limit: up to 10 replicas.
Key Vault (CMK) Customer-managed keys require user-assigned managed identity and Key Vault with purge protection enabled.

PostgreSQL Flexible Server

Paired With Constraint
VNet (private access) Requires a dedicated subnet delegated to Microsoft.DBforPostgreSQL/flexibleServers. Subnet must have no other resources.
Private DNS Zone For VNet-integrated (private access) servers, use the zone name {name}.postgres.database.azure.com (not privatelink.*). The privatelink.postgres.database.azure.com zone is used for Private Endpoint connectivity only. Provide privateDnsZoneArmResourceId and the DNS zone must be linked to the VNet.
High Availability ZoneRedundant HA requires GeneralPurpose or MemoryOptimized tier. Not available with Burstable.
Geo-Redundant Backup Not available in all regions. Cannot be enabled with VNet-integrated (private access) servers in some configurations.
Storage Auto-Grow Storage can only grow, never shrink. Minimum increase is based on current size.
Key Vault (CMK) Customer-managed keys require user-assigned managed identity and Key Vault with purge protection enabled.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure using Bicep and Terraform. It leverages official Microsoft documentation and Azure CLI tools to ensure architectural alignment with the Well-Architected Framework. The skill includes built-in security practices such as managed identity usage, RBAC enforcement, and secure parameter handling.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 5f24d7e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • Infrastructure
  • azure
  • bicep
  • terraform
  • networking
  • landing-zone
  • hub-spoke
  • identity
  • disaster-recovery
  • compliance

README badge

README badge for microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

Generates Bicep or Terraform code for enterprise Azure infrastructure from workload descriptions, covering networking, identity, security, and multi-region topologies aligned with Azure Well-Architected Framework. Targets cloud architects and platform engineers planning landing zones, hub-spoke networks, and subscription-scope deployments.

Generated from the current SKILL.md.

Does this skill generate Terraform or Bicep?
It generates both Bicep and Terraform directly. The skill targets subscription-scope and multi-resource-group deployments without using Azure Developer CLI (azd).
What Azure infrastructure patterns does this skill handle?
It covers enterprise patterns including landing zones, hub-spoke networks, multi-region disaster recovery, VNets, firewalls, private endpoints, VPN gateways, identity, RBAC, and compliance-driven topologies.
Should I use this skill for application-centric workflows?
No. The skill description explicitly recommends using azure-prepare instead for app-centric workflows. This skill is optimized for infrastructure and platform engineering.
Does this skill validate generated infrastructure code?
Yes. It includes validation for both Bicep (az bicep build) and Terraform (terraform validate) and checks for pairing constraint violations before deployment.
What MCP tools does this skill rely on?
It uses insights_get, get_azure_bestpractices_get, wellarchitectedframework_serviceguide_get, microsoft_docs_search, microsoft_docs_fetch, and bicepschema_get to fetch best practices, WAF guidance, and schema definitions.

Generated from the current SKILL.md. These answers refresh after source changes.