All skills
microsoft avatar

/azure-enterprise-infra-planner

@5f24d7e official

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesconstraintsnetworking-traffic.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Networking (Traffic) Pairing Constraints

Application Gateway

Paired With Constraint
Subnet Requires a dedicated subnet — no other resources allowed in the subnet (except other App Gateways). Cannot mix v1 and v2 SKUs on the same subnet — separate subnets required for each.
Public IP v2 SKU requires Standard SKU public IP with Static allocation.
NSG NSG on App Gateway subnet must allow GatewayManager service tag on ports 65200–65535 (v2) or 65503–65534 (v1).
WAF WAF configuration only available with WAF_v2 or WAF_Large/WAF_Medium SKUs. WAF v2 cannot disable request buffering — chunked file transfer requires path-rule workaround.
Zones v2 supports availability zones. Specify zones: ['1','2','3'] for zone-redundant deployment.
Key Vault For SSL certificates, use sslCertificates[].properties.keyVaultSecretId to reference Key Vault certificates. User-assigned managed identity required.
v1 Limitations v1 does not support: autoscaling, zone redundancy, Key Vault integration, mTLS, Private Link, WAF custom rules, or header rewrite. Must use v2 for these features. v1 SKUs are being retired April 2026.
Private-only (no public IP) Requires EnableApplicationGatewayNetworkIsolation feature registration. Only available with Standard_v2 or WAF_v2.
Global VNet Peering Backend via private endpoint across global VNet peering causes traffic to be dropped — results in unhealthy backend status.
kubenet (AKS) Kubenet is not supported by Application Gateway for Containers. Must use CNI or CNI Overlay.

Front Door

Paired With Constraint
Origins (backends) Origins are defined in child originGroups/origins. Supported origin types: App Service, Storage, Application Gateway, Public IP, custom hostname.
Private Link Origins Only available with Premium_AzureFrontDoor SKU. Enable private origin connections to App Service, Storage, Internal Load Balancer, etc.
WAF Policy WAF policies are separate Microsoft.Network/FrontDoorWebApplicationFirewallPolicies resources. Linked via security policy child resource on the profile.
Custom Domains Custom domains are child resources of the profile. Require DNS CNAME/TXT validation and certificate (managed or custom).
Application Gateway Front Door in front of App Gateway: use App Gateway public IP as origin. Set X-Azure-FDID header restriction on App Gateway to accept only Front Door traffic.
App Service Restrict App Service to Front Door traffic using access restrictions with AzureFrontDoor.Backend service tag and X-Azure-FDID header check.

Load Balancer

Paired With Constraint
Public IP Public IP SKU must match LB SKU. Basic LB requires Basic public IP; Standard LB requires Standard public IP. No cross-SKU mixing.
Standard SKU Backend pool VMs must be in the same VNet. No VMs from different VNets. Standard LB blocks outbound traffic by default — requires explicit outbound rules, NAT gateway, or instance-level public IPs. Standard LB requires an NSG (secure by default; inbound traffic blocked without NSG).
Basic SKU Backend pool VMs must be in the same availability set or VMSS.
Availability Zones Standard SKU is zone-redundant by default. Frontend IPs inherit zone from public IP.
VMs / VMSS VMs in backend pool cannot have both Basic and Standard LBs simultaneously.
Outbound Rules Only Standard SKU supports outbound rules. Basic SKU has implicit outbound.

API Management

Paired With Constraint
VNet (External) Only available with Developer, Premium, or Isolated SKU. Subnet must be dedicated with an NSG allowing APIM management traffic.
VNet (Internal) Same as External but no public gateway endpoint. Requires Private DNS or custom DNS for resolution.
Application Gateway Common pattern: App Gateway in front of Internal-mode APIM. App Gateway uses the APIM private IP as backend.
Key Vault Named values and certificates can reference Key Vault secrets. Requires managed identity with Key Vault Secrets User role.
Application Insights Set properties.customProperties with Microsoft.WindowsAzure.ApiManagement.Gateway.Protocols.Server.Http2 and logger resource for diagnostics.
NSG (VNet mode) Subnet NSG must allow: inbound on ports 3443 (management), 80/443 (client); outbound to Azure Storage, SQL, Event Hub, and other dependencies.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure using Bicep and Terraform. It leverages official Microsoft documentation and Azure CLI tools to ensure architectural alignment with the Well-Architected Framework. The skill includes built-in security practices such as managed identity usage, RBAC enforcement, and secure parameter handling.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 5f24d7e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • Infrastructure
  • azure
  • bicep
  • terraform
  • networking
  • landing-zone
  • hub-spoke
  • identity
  • disaster-recovery
  • compliance

README badge

README badge for microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

Generates Bicep or Terraform code for enterprise Azure infrastructure from workload descriptions, covering networking, identity, security, and multi-region topologies aligned with Azure Well-Architected Framework. Targets cloud architects and platform engineers planning landing zones, hub-spoke networks, and subscription-scope deployments.

Generated from the current SKILL.md.

Does this skill generate Terraform or Bicep?
It generates both Bicep and Terraform directly. The skill targets subscription-scope and multi-resource-group deployments without using Azure Developer CLI (azd).
What Azure infrastructure patterns does this skill handle?
It covers enterprise patterns including landing zones, hub-spoke networks, multi-region disaster recovery, VNets, firewalls, private endpoints, VPN gateways, identity, RBAC, and compliance-driven topologies.
Should I use this skill for application-centric workflows?
No. The skill description explicitly recommends using azure-prepare instead for app-centric workflows. This skill is optimized for infrastructure and platform engineering.
Does this skill validate generated infrastructure code?
Yes. It includes validation for both Bicep (az bicep build) and Terraform (terraform validate) and checks for pairing constraint violations before deployment.
What MCP tools does this skill rely on?
It uses insights_get, get_azure_bestpractices_get, wellarchitectedframework_serviceguide_get, microsoft_docs_search, microsoft_docs_fetch, and bicepschema_get to fetch best practices, WAF guidance, and schema definitions.

Generated from the current SKILL.md. These answers refresh after source changes.