All skills
microsoft avatar

/azure-enterprise-infra-planner

@5f24d7e official

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesconstraintsnetworking-core.md

≈1.8k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Networking (Core) Pairing Constraints

Virtual Network

Paired With Constraint
Subnets Address prefixes of all subnets must fall within the VNet address space. Subnet CIDRs cannot overlap.
VNet Peering Peered VNets cannot have overlapping address spaces.
Azure Firewall Requires a subnet named exactly AzureFirewallSubnet with minimum /26 prefix.
Azure Bastion Requires a subnet named exactly AzureBastionSubnet with minimum /26 prefix (recommended /26).
VPN Gateway Requires a subnet named exactly GatewaySubnet with minimum /27 prefix (recommended /27).
Application Gateway Requires a dedicated subnet (no mandatory name, but must not contain other resource types).
AKS AKS subnet must have enough IP addresses for nodes + pods. With Azure CNI, each node reserves IPs for max pods.

Subnet

Paired With Constraint
NSG Cannot attach NSG to GatewaySubnet — NSGs are not supported for either VPN or ExpressRoute gateways. NSG on AzureBastionSubnet requires specific required rules.
Delegations A subnet can only be delegated to one service. Delegated subnets cannot host other resource types.
Service Endpoints Must match the service being accessed (e.g., Microsoft.Sql for SQL Server VNet rules).
Private Endpoints Set privateEndpointNetworkPolicies: 'Enabled' to apply NSG/route table to private endpoints (default is Disabled).
AKS AKS subnet needs enough IPs for all nodes + pods. Cannot be delegated or have conflicting service endpoints.
Application Gateway Dedicated subnet required — cannot coexist with other resources except other App Gateways. Cannot mix v1 and v2 App Gateway SKUs on the same subnet.
Azure Firewall Subnet must be named AzureFirewallSubnet, minimum /26. Cannot have other resources.
App Service VNet Integration Subnet must be delegated to Microsoft.Web/serverFarms. Minimum size /28 (or /26 for multi-plan subnet join). This subnet must be different from any subnet used for App Service Private Endpoints.
GatewaySubnet UDR Do not apply UDR with 0.0.0.0/0 next hop on GatewaySubnet. ExpressRoute gateways require management controller access. BGP route propagation must remain enabled on GatewaySubnet.

NSG

Paired With Constraint
GatewaySubnet NSGs are not supported on GatewaySubnet. Associating an NSG may cause VPN and ExpressRoute gateways to stop functioning.
AzureBastionSubnet NSG on Bastion subnet requires specific inbound/outbound rules (see Azure Bastion NSG).
Application Gateway NSG on App Gateway subnet must allow GatewayManager service tag on ports 65200–65535 (v2) and health probe traffic.
Load Balancer Must allow AzureLoadBalancer service tag for health probes. Standard LB requires NSG — it is secure by default and blocks inbound traffic without an NSG.
Virtual Network NSG is associated to subnets, not directly to VNets. Each subnet can have at most one NSG.

Route Table

Paired With Constraint
Subnet Route table is associated on the subnet side: set subnet.properties.routeTable.id to the route table resource ID. Each subnet can have at most one route table.
Azure Firewall For forced tunneling, create a default route (0.0.0.0/0) with nextHopType: 'VirtualAppliance' pointing to the firewall private IP.
VPN Gateway Set disableBgpRoutePropagation: true to prevent BGP routes from overriding UDRs on the subnet.
GatewaySubnet UDRs on GatewaySubnet have restrictions — cannot use 0.0.0.0/0 route pointing to a virtual appliance.
AKS AKS subnets with UDRs require careful route design. Must allow traffic to Azure management APIs. kubenet and Azure CNI have different routing requirements.
Virtual Appliance nextHopIpAddress must be a reachable private IP in the same VNet or a peered VNet. The appliance NIC must have enableIPForwarding: true.

Network Interface

Paired With Constraint
Virtual Machine Each VM requires at least one NIC. NIC must be in the same region and subscription as the VM.
Subnet NIC must reference a subnet. The subnet determines the VNet, NSG, and route table that apply.
NSG NSG can be associated at the NIC level or at the subnet level (or both). NIC-level NSG is evaluated after subnet-level NSG.
Public IP Public IP and NIC must be in the same region. When associated with a Load Balancer, Public IP SKU must match the LB SKU (Basic with Basic, Standard with Standard).
Load Balancer NIC IP configuration can reference loadBalancerBackendAddressPools and loadBalancerInboundNatRules. Load balancer and NIC must be in the same VNet.
Accelerated Networking Not all VM sizes support accelerated networking. Must verify VM size compatibility.
VM Scale Set NICs for VMSS instances are managed by the scale set — do not create standalone NICs for VMSS.
Application Gateway NIC IP configuration can reference applicationGatewayBackendAddressPools.

Public IP

Paired With Constraint
Standard SKU Must use Static allocation method. Dynamic only works with Basic SKU.
Load Balancer Public IP SKU must match Load Balancer SKU (Standard ↔ Standard, Basic ↔ Basic).
Application Gateway Standard_v2 App Gateway requires Standard SKU public IP with Static allocation.
Azure Bastion Requires Standard SKU with Static allocation.
VPN Gateway Basic VPN Gateway SKU requires Basic public IP. Standard+ gateway SKUs require Standard public IP.
Azure Firewall Requires Standard SKU with Static allocation.
Zones Standard SKU is zone-redundant by default. Specify zones only to pin to specific zone(s).

NAT Gateway

Paired With Constraint
Subnet NAT Gateway is associated on the subnet side: set subnet.properties.natGateway.id to the NAT Gateway resource ID. A subnet can have at most one NAT Gateway.
Public IP Public IP must use Standard SKU and Static allocation. Public IP and NAT Gateway must be in the same region.
Public IP Prefix Public IP prefix must use Standard SKU. Provides contiguous outbound IPs.
Availability Zones NAT Gateway can be zonal (pinned to one zone) or non-zonal. Public IPs must match the same zone or be zone-redundant.
Load Balancer NAT Gateway takes precedence over outbound rules of a Standard Load Balancer when both are on the same subnet.
VPN Gateway / ExpressRoute GatewaySubnet does not support NAT Gateway association.
Azure Firewall NAT Gateway can be associated with the AzureFirewallSubnet for deterministic outbound IPs in SNAT scenarios.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure using Bicep and Terraform. It leverages official Microsoft documentation and Azure CLI tools to ensure architectural alignment with the Well-Architected Framework. The skill includes built-in security practices such as managed identity usage, RBAC enforcement, and secure parameter handling.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 5f24d7e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • Infrastructure
  • azure
  • bicep
  • terraform
  • networking
  • landing-zone
  • hub-spoke
  • identity
  • disaster-recovery
  • compliance

README badge

README badge for microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

Generates Bicep or Terraform code for enterprise Azure infrastructure from workload descriptions, covering networking, identity, security, and multi-region topologies aligned with Azure Well-Architected Framework. Targets cloud architects and platform engineers planning landing zones, hub-spoke networks, and subscription-scope deployments.

Generated from the current SKILL.md.

Does this skill generate Terraform or Bicep?
It generates both Bicep and Terraform directly. The skill targets subscription-scope and multi-resource-group deployments without using Azure Developer CLI (azd).
What Azure infrastructure patterns does this skill handle?
It covers enterprise patterns including landing zones, hub-spoke networks, multi-region disaster recovery, VNets, firewalls, private endpoints, VPN gateways, identity, RBAC, and compliance-driven topologies.
Should I use this skill for application-centric workflows?
No. The skill description explicitly recommends using azure-prepare instead for app-centric workflows. This skill is optimized for infrastructure and platform engineering.
Does this skill validate generated infrastructure code?
Yes. It includes validation for both Bicep (az bicep build) and Terraform (terraform validate) and checks for pairing constraint violations before deployment.
What MCP tools does this skill rely on?
It uses insights_get, get_azure_bestpractices_get, wellarchitectedframework_serviceguide_get, microsoft_docs_search, microsoft_docs_fetch, and bicepschema_get to fetch best practices, WAF guidance, and schema definitions.

Generated from the current SKILL.md. These answers refresh after source changes.