All skills
microsoft avatar

/azure-enterprise-infra-planner

@5f24d7e official

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesconstraintsmessaging.md

≈653 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Messaging Pairing Constraints

Event Grid Topic

Paired With Constraint
Event Subscriptions Subscriptions are child resources. Delivery endpoints include: Webhook, Azure Function, Event Hub, Service Bus Queue/Topic, Storage Queue, Hybrid Connection.
Private Endpoint Only available with Premium SKU. Set publicNetworkAccess: 'Disabled' when using private endpoints exclusively.
Managed Identity Required for dead-letter destinations and delivery to Azure resources that require authentication (Event Hub, Service Bus, Storage).
Function App Use Event Grid trigger binding. Subscription endpoint type is AzureFunction. Function must have Event Grid extension registered.
Event Hub Subscription endpoint type is EventHub. Provide the Event Hub resource ID. Requires managed identity or connection string.
Storage Queue Subscription endpoint type is StorageQueue. Provide storage account ID and queue name.
Dead Letter Dead-letter destination must be a Storage blob container. Requires managed identity or storage key for access.

Event Hub

Paired With Constraint
VNet Standard, Premium, and Dedicated SKUs support VNet service endpoints and private endpoints.
Zone Redundancy Available in Standard (with ≥4 TU recommended) and Premium.
Kafka Kafka protocol support available in Standard and Premium only (not Basic).
Capture Event capture to Storage/Data Lake available in Standard and Premium only.
Consumer Groups Basic: 1 consumer group. Standard: 20. Premium: 100. Dedicated: 1,000.
Retention Basic: 1 day. Standard: 1–7 days. Premium: up to 90 days.
Function App Event Hub trigger uses connection string or managed identity. Set EventHubConnection in app settings.

Service Bus

Paired With Constraint
Topics Only Standard and Premium SKUs support topics and subscriptions. Basic supports queues only.
VNet Only Premium SKU supports VNet service endpoints and private endpoints.
Zone Redundancy Only Premium SKU supports zone redundancy.
Partitioning Premium messaging partitions cannot be changed after creation.
Message Size Basic/Standard: max 256 KB. Premium: max 100 MB. Plan accordingly for large payloads.
Function App Service Bus trigger uses connection string or managed identity. Set ServiceBusConnection in app settings.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure using Bicep and Terraform. It leverages official Microsoft documentation and Azure CLI tools to ensure architectural alignment with the Well-Architected Framework. The skill includes built-in security practices such as managed identity usage, RBAC enforcement, and secure parameter handling.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 5f24d7e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • Infrastructure
  • azure
  • bicep
  • terraform
  • networking
  • landing-zone
  • hub-spoke
  • identity
  • disaster-recovery
  • compliance

README badge

README badge for microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

Generates Bicep or Terraform code for enterprise Azure infrastructure from workload descriptions, covering networking, identity, security, and multi-region topologies aligned with Azure Well-Architected Framework. Targets cloud architects and platform engineers planning landing zones, hub-spoke networks, and subscription-scope deployments.

Generated from the current SKILL.md.

Does this skill generate Terraform or Bicep?
It generates both Bicep and Terraform directly. The skill targets subscription-scope and multi-resource-group deployments without using Azure Developer CLI (azd).
What Azure infrastructure patterns does this skill handle?
It covers enterprise patterns including landing zones, hub-spoke networks, multi-region disaster recovery, VNets, firewalls, private endpoints, VPN gateways, identity, RBAC, and compliance-driven topologies.
Should I use this skill for application-centric workflows?
No. The skill description explicitly recommends using azure-prepare instead for app-centric workflows. This skill is optimized for infrastructure and platform engineering.
Does this skill validate generated infrastructure code?
Yes. It includes validation for both Bicep (az bicep build) and Terraform (terraform validate) and checks for pairing constraint violations before deployment.
What MCP tools does this skill rely on?
It uses insights_get, get_azure_bestpractices_get, wellarchitectedframework_serviceguide_get, microsoft_docs_search, microsoft_docs_fetch, and bicepschema_get to fetch best practices, WAF guidance, and schema definitions.

Generated from the current SKILL.md. These answers refresh after source changes.