All skills
microsoft avatar

/azure-upgrade

@36a90f7 official

Assess and upgrade Azure workloads between plans, tiers, or SKUs, or modernize Azure SDK dependencies in source code. WHEN: upgrade Consumption to Flex Consumption, upgrade Azure Functions plan, change hosting plan, function app SKU, migrate App Service to Container Apps, modernize legacy Azure Java SDKs (com.microsoft.azure to com.azure), migrate Azure Cache for Redis (ACR/ACRE) to Azure Managed Redis (AMR).

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-upgrade

This session only. Nothing lands on disk.

referencesglobal-rules.md

≈523 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Global Rules

These rules apply to ALL phases of the azure-upgrade skill.

Destructive Action Policy

⛔ NEVER perform destructive actions without explicit user confirmation via ask_user:

  • Deleting apps, services, or resource groups
  • Stopping or disabling the original app/service
  • Overwriting app settings or configuration in the new app
  • Removing the original hosting plan or service tier
  • Modifying DNS or custom domain bindings

User Confirmation Required

Always use ask_user before:

  • Selecting target Azure subscription
  • Selecting target Azure region/location
  • Creating new Azure resources
  • Stopping or deleting the original app/service
  • Modifying custom domains or network restrictions
  • Any irreversible configuration change

Best Practices

  • Always use mcp_azure_mcp_get_azure_bestpractices tool before generating upgrade commands
  • Prefer managed identity over connection strings — upgrades are a good time to improve security
  • Always target the latest supported runtime version — check Azure docs for the newest GA version
  • Keep the original app/service running until the upgraded one is fully validated
  • Use the same resource group for the new resource to maintain access to existing dependencies
  • Follow Azure naming conventions for all new resources

Identity-First Authentication (Zero API Keys)

Enterprise subscriptions commonly enforce policies that block local auth. Always design for identity-based access from the start.

  • Prefer managed identity connections over connection strings/keys
  • Use DefaultAzureCredential in code — works locally and in Azure
  • When using User Assigned Managed Identity, always pass managedIdentityClientId explicitly
  • See service-specific identity configuration in the scenario reference files

Rollback Policy

  • Always document rollback steps before executing upgrade
  • Keep the original app intact and running until upgrade is validated
  • If upgrade fails, guide the user to restart the original app
  • Never delete the original app automatically — always require ask_user

Source: SKILL.md on GitHub

2 warnings4mo5 checks · Risk SAFE
  • Gen Agent Trust Hub4mo

    This skill facilitates Azure workload upgrades and Java SDK modernization. It includes security considerations such as command execution and fetching data from remote sources, which are within the skill's intended purpose of automating cloud and code migrations.

  • Socket4mo

    No alerts

  • Snyk4mo

    Risk: MEDIUM · 2 issues

  • Runlayer6mo

    3/6 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 36a90f7. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 5 months ago
compatibility
python3.10+
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • Infrastructure
  • azure
  • azure-functions
  • azure-app-service
  • azure-redis
  • java-sdk
  • migrations
  • sku-upgrades
  • consumption-plan
  • flex-consumption

README badge

README badge for microsoft/github-copilot-for-azure/azure-upgrade

Assesses and automates Azure workload upgrades across plans, tiers, and SKUs—such as Functions Consumption to Flex Consumption, App Service to Container Apps, or Redis migrations to Azure Managed Redis. Also modernizes legacy Azure Java SDK dependencies (com.microsoft.azure to com.azure) in source code. Includes readiness checks, configuration migration, and validation steps.

Generated from the current SKILL.md.

Does this skill handle cross-cloud migration?
No. This skill is for Azure-to-Azure upgrades only (plan changes, SKU swaps, service migrations within Azure). For cross-cloud migration, use the `azure-cloud-migrate` skill.
What Azure upgrades does this skill cover?
It handles Azure Functions plan upgrades (Consumption to Flex Consumption), hosting tier changes, App Service to Container Apps migration, Redis cache upgrades (ACR/ACRE to Azure Managed Redis), and legacy Azure Java SDK modernization (com.microsoft.azure to com.azure).
Will this skill delete my existing app without asking?
No. The skill requires explicit user confirmation before stopping or deleting the original app. All destructive actions trigger a confirmation prompt.
Does this skill support Java SDK modernization?
Yes. It handles source-code modernization from legacy Azure Java SDKs (com.microsoft.azure.*) to modern ones (com.azure.*).
What happens after the upgrade is complete?
The skill asks whether you want to verify performance, clean up the old app, or update your infrastructure-as-code. You can then hand off to `azure-validate` for deep validation or `azure-deploy` for CI/CD setup.

Generated from the current SKILL.md. These answers refresh after source changes.