All skills
microsoft avatar

/azure-enterprise-infra-planner

@5f24d7e official

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesconstraintsnetworking-connectivity.md

≈1.6k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Networking (Connectivity) Pairing Constraints

Azure Bastion

Paired With Constraint
VNet Requires a subnet named exactly AzureBastionSubnet with minimum /26 prefix.
Developer SKU Does NOT require AzureBastionSubnet or public IP. Deploys as shared infrastructure. Only connects to VMs in the same VNet.
Public IP Requires Standard SKU public IP with Static allocation.
NSG NSG on AzureBastionSubnet requires mandatory inbound (HTTPS 443 from Internet, GatewayManager 443) and outbound rules (see Bastion NSG docs).
VMs Target VMs must be in the same VNet as Bastion (or peered VNets with Standard/Premium SKU).

Azure Firewall

Paired With Constraint
VNet Requires a subnet named exactly AzureFirewallSubnet with minimum /26 prefix.
Basic Tier Additionally requires AzureFirewallManagementSubnet with /26 minimum and its own public IP.
Public IP Requires Standard SKU public IP with Static allocation.
Firewall Policy Cannot use both firewallPolicy.id and classic rule collections simultaneously. Policy tier must match or exceed firewall tier.
Zones In zone-redundant mode, all associated public IPs must also be zone-redundant (Standard SKU).
Virtual WAN AZFW_Hub SKU name must reference virtualHub.id instead of ipConfigurations.

VPN Gateway

Paired With Constraint
VNet Requires a subnet named exactly GatewaySubnet with minimum /27 prefix. Use /26+ for 16 ExpressRoute circuits or for ExpressRoute/VPN coexistence.
Public IP Basic VPN SKU requires Basic public IP. VpnGw1+ requires Standard public IP.
Active-Active Requires 2 public IPs and 2 IP configurations. Only supported with VpnGw1+.
Zone-Redundant Must use AZ SKU variant (e.g., VpnGw1AZ). Requires Standard SKU public IPs. AZ SKU cannot be downgraded to non-AZ (one-way migration only).
ExpressRoute Can coexist with VPN gateway on the same GatewaySubnet (requires /27 or larger). Not supported with Basic SKU. Route-based VPN required.
PolicyBased Limited to 1 S2S tunnel, no P2S, no VNet-to-VNet. Use RouteBased for most scenarios.
Basic SKU Basic VPN Gateway does not support BGP, IPv6, RADIUS authentication, IKEv2 P2S, or ExpressRoute coexistence. Max 10 S2S tunnels.
GatewaySubnet UDR Do not apply UDR with 0.0.0.0/0 next hop on GatewaySubnet. ExpressRoute gateways require management controller access — this route breaks it.
GatewaySubnet BGP BGP route propagation must remain enabled on GatewaySubnet. Disabling causes the gateway to become non-functional.
DNS Private Resolver DNS Private Resolver in a VNet with an ExpressRoute gateway and wildcard forwarding rules can cause management connectivity problems.

DNS Zone

Paired With Constraint
Domain Registrar NS records from properties.nameServers must be configured at your domain registrar to delegate the domain to Azure DNS.
App Service Create a CNAME record pointing to {app-name}.azurewebsites.net for custom domains. Add a TXT verification record.
Front Door Create a CNAME record pointing to the Front Door endpoint. Add a _dnsauth TXT record for domain validation.
Application Gateway Create an A record pointing to the Application Gateway public IP, or a CNAME to the public IP DNS name.
Traffic Manager Create a CNAME record pointing to the Traffic Manager profile {name}.trafficmanager.net.
Child Zones Delegate subdomains by creating NS records in the parent zone pointing to the child zone's Azure name servers.

Private DNS Zone

Paired With Constraint
Virtual Network Must create a virtualNetworkLinks child resource to link the DNS zone to each VNet that needs resolution.
Private Endpoint Use a privateDnsZoneGroups child on the Private Endpoint to auto-register A records, or manually create A record sets. One DNS record per DNS name — multiple private endpoints in different regions need separate Private DNS Zones.
VNet Link (auto-registration) Only one Private DNS Zone with registrationEnabled: true can be linked per VNet. Auto-registration creates DNS records for VMs in the VNet.
Hub-Spoke VNet Link the Private DNS Zone to the hub VNet. Spoke VNets resolve via hub DNS forwarder or VNet link.
PostgreSQL Flexible Server For Private Endpoint access, zone name is privatelink.postgres.database.azure.com. For VNet-integrated (private access) servers, the zone name is {name}.postgres.database.azure.com (not privatelink.*). Referenced via properties.network.privateDnsZoneArmResourceId.
MySQL Flexible Server For Private Endpoint access, zone name is privatelink.mysql.database.azure.com. For VNet-integrated (private access) servers, the zone name is {name}.mysql.database.azure.com (not privatelink.*). Referenced via properties.network.privateDnsZoneResourceId.

Private Endpoint

Paired With Constraint
Subnet The subnet must not have NSG rules that block private endpoint traffic. Subnet must have privateEndpointNetworkPolicies set to Disabled (default) for network policies to be bypassed.
Private DNS Zone Create a Microsoft.Network/privateDnsZones/virtualNetworkLinks to link the DNS zone to the VNet. Create an A record or use a private DNS zone group to auto-register DNS.
Private DNS Zone Group Use privateEndpoint/privateDnsZoneGroups child resource to auto-register DNS records in the Private DNS Zone.
Key Vault Group ID: vault. DNS zone: privatelink.vaultcore.azure.net.
Storage Account Group IDs: blob, file, queue, table, web, dfs. Each requires its own PE and DNS zone.
SQL Server Group ID: sqlServer. DNS zone: privatelink.database.windows.net.
Container Registry Group ID: registry. DNS zone: privatelink.azurecr.io.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure using Bicep and Terraform. It leverages official Microsoft documentation and Azure CLI tools to ensure architectural alignment with the Well-Architected Framework. The skill includes built-in security practices such as managed identity usage, RBAC enforcement, and secure parameter handling.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 5f24d7e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • Infrastructure
  • azure
  • bicep
  • terraform
  • networking
  • landing-zone
  • hub-spoke
  • identity
  • disaster-recovery
  • compliance

README badge

README badge for microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

Generates Bicep or Terraform code for enterprise Azure infrastructure from workload descriptions, covering networking, identity, security, and multi-region topologies aligned with Azure Well-Architected Framework. Targets cloud architects and platform engineers planning landing zones, hub-spoke networks, and subscription-scope deployments.

Generated from the current SKILL.md.

Does this skill generate Terraform or Bicep?
It generates both Bicep and Terraform directly. The skill targets subscription-scope and multi-resource-group deployments without using Azure Developer CLI (azd).
What Azure infrastructure patterns does this skill handle?
It covers enterprise patterns including landing zones, hub-spoke networks, multi-region disaster recovery, VNets, firewalls, private endpoints, VPN gateways, identity, RBAC, and compliance-driven topologies.
Should I use this skill for application-centric workflows?
No. The skill description explicitly recommends using azure-prepare instead for app-centric workflows. This skill is optimized for infrastructure and platform engineering.
Does this skill validate generated infrastructure code?
Yes. It includes validation for both Bicep (az bicep build) and Terraform (terraform validate) and checks for pairing constraint violations before deployment.
What MCP tools does this skill rely on?
It uses insights_get, get_azure_bestpractices_get, wellarchitectedframework_serviceguide_get, microsoft_docs_search, microsoft_docs_fetch, and bicepschema_get to fetch best practices, WAF guidance, and schema definitions.

Generated from the current SKILL.md. These answers refresh after source changes.