All skills
microsoft avatar

/azure-enterprise-infra-planner

@5f24d7e official

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesworkflow.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Workflow

Mandatory Rules

  • You must execute the seven phases in sequential order. Follow the instructions precisely as defined. Do not continue to the next phase until the current phase is complete.
  • You must stop on all "gate" conditions and only continue when the conditions have been met.
  • Destructive actions require explicit user confirmation.
  • Confirmation gate vs. answer-first. Always present a plain-language summary of your understanding plus an explicit "confirm before I proceed" checkpoint before deploying (Phase 7). In referenced mode you still generate the plan and IaC in the same turn (answer-first) — the gate governs deployment, not whether you produce the artifacts. Never end a turn with only a question, and never deploy without an explicit, risk-acknowledged go-ahead.
  • Never claim a gate passed without proof. When a phase gate depends on a command (validation, security scan), run it and show its actual output/exit status; do not assert success from memory.
  • You must read each phase's reference file in full before executing it.
  • Never assume knowledge and cut corners or skip research steps.

Overview

Starting from Phase 1, execute all phases in sequential order. Do not advance to the next phase until the current phase is complete and all of its gate conditions have been met.

Phase 6 — hardened generation gate (apply inline)

The detailed generation reference files may not be loaded in every environment, so the Phase 6 gate is restated here and is mandatory. After generating the IaC, and before offering it or advancing to deploy:

  1. Secure-by-default. Every resource: private endpoints + public network access disabled on data/PaaS services; managed identity + RBAC (never keys/connection strings); no secrets in code; storage shared-key access disabled; Key Vault soft-delete + purge protection; AKS managed identity with local accounts disabled; TLS 1.2 minimum.
  2. Validate + security-scan, fix until clean. Bicep: az bicep build --file infra/main.bicep. Terraform: terraform init -backend=false then terraform validate. Then checkov -d infra/. Fix in-place and re-run until every command passes. Paste the actual command output / exit status into your response — never claim the gate passed without showing it. If a tool is genuinely unavailable, say so and self-review against the secure-by-default list.
  3. Completion self-check. End Phase 6 with a checklist, each line marked pass/fail: validation clean (output shown); checkov no unresolved high/critical; secure-by-default applied; referenced resources wired and none recreated (referenced mode); files under infra/ with original sources untouched.

Referenced workload? If the user supplies something existing to reference or integrate with — a live Azure resource/resource group/subscription, a Bicep/Terraform/ARM file or infra plan, or a general doc of requirements/context — also read referenced-workload.md and apply it alongside these phases. If not, run greenfield exactly as below.

Phase Action Reference Key Gate
1 Extract insights 1-extract-insights.md Insights written to <project-root>/.azure/insights.json
2 Research best practices 2-research-best-practices.md All MCP tool calls complete and WAF guides summarized
3 Research resources 3-research-resources.md All resources have ARM type, naming rules, and pairing constraints; user approves resource list
4 Generate plan 4-generate-plan.md Plan JSON written to disk
5 Verify plan 5-verify.md All checks pass, user approves
6 Generate IaC 6-generate-iac.md All IaC files generated and saved to disk
7 Deploy to Azure 7-deploy.md User confirms destructive actions

Plan Status Lifecycle

draft → approved → deployed

  • draft — set by Phase 4 when the plan is written.
  • approved — set by Phase 5 only after the user explicitly approves. Required before Phase 6 and Phase 7.
  • deployed — set by Phase 7 after a successful az deployment ... create or terraform apply.

Outputs

Artifact Location
Insights <project-root>/.azure/insights.json
Infrastructure Plan <project-root>/.azure/infrastructure-plan.json
Bicep files <project-root>/infra/main.bicep, <project-root>/infra/modules/*.bicep
Terraform files <project-root>/infra/main.tf, <project-root>/infra/modules/**/*.tf

Before writing any .bicep or .tf files in Phase 6:

  1. Create the infra/ directory at <project-root>/infra/.
  2. Create infra/modules/ for child modules.
  3. Write main.bicep (or main.tf) inside infra/, not in the project root or .azure/.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub5mo

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure using Bicep and Terraform. It leverages official Microsoft documentation and Azure CLI tools to ensure architectural alignment with the Well-Architected Framework. The skill includes built-in security practices such as managed identity usage, RBAC enforcement, and secure parameter handling.

  • Socket5mo

    No alerts

  • Snyk5mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 5f24d7e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • Infrastructure
  • azure
  • bicep
  • terraform
  • networking
  • landing-zone
  • hub-spoke
  • identity
  • disaster-recovery
  • compliance

README badge

README badge for microsoft/github-copilot-for-azure/azure-enterprise-infra-planner

Generates Bicep or Terraform code for enterprise Azure infrastructure from workload descriptions, covering networking, identity, security, and multi-region topologies aligned with Azure Well-Architected Framework. Targets cloud architects and platform engineers planning landing zones, hub-spoke networks, and subscription-scope deployments.

Generated from the current SKILL.md.

Does this skill generate Terraform or Bicep?
It generates both Bicep and Terraform directly. The skill targets subscription-scope and multi-resource-group deployments without using Azure Developer CLI (azd).
What Azure infrastructure patterns does this skill handle?
It covers enterprise patterns including landing zones, hub-spoke networks, multi-region disaster recovery, VNets, firewalls, private endpoints, VPN gateways, identity, RBAC, and compliance-driven topologies.
Should I use this skill for application-centric workflows?
No. The skill description explicitly recommends using azure-prepare instead for app-centric workflows. This skill is optimized for infrastructure and platform engineering.
Does this skill validate generated infrastructure code?
Yes. It includes validation for both Bicep (az bicep build) and Terraform (terraform validate) and checks for pairing constraint violations before deployment.
What MCP tools does this skill rely on?
It uses insights_get, get_azure_bestpractices_get, wellarchitectedframework_serviceguide_get, microsoft_docs_search, microsoft_docs_fetch, and bicepschema_get to fetch best practices, WAF guidance, and schema definitions.

Generated from the current SKILL.md. These answers refresh after source changes.