All skills
microsoft avatar

/azure-cloud-migrate

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Assess and migrate cross-cloud workloads to Azure with reports and code conversion. Supports Lambda→Functions, Beanstalk/Heroku/App Engine→App Service, Fargate/Kubernetes/Cloud Run/Spring Boot→Container Apps. WHEN: migrate Lambda to Functions, AWS to Azure, migrate Beanstalk, migrate Heroku, migrate App Engine, Cloud Run migration, Fargate to ACA, ECS/Kubernetes/GKE/EKS to Container Apps, Spring Boot to Container Apps, cross-cloud migration.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-cloud-migrate

This session only. Nothing lands on disk.

referencesservicesapp-servicebeanstalk-to-app-service.md

≈1.6k tokens on demand. Your agent reads this file only when SKILL.md points to it.

AWS Elastic Beanstalk to Azure App Service Migration

Detailed guidance for migrating AWS Elastic Beanstalk applications to Azure App Service.

Service Mapping

AWS Service Azure Equivalent
Elastic Beanstalk Azure App Service
Elastic Beanstalk Environment App Service + App Service Plan
Platform Presets Runtime Stacks
.ebextensions/ Bicep + App Settings
Procfile Startup Command
RDS (PostgreSQL) Azure Database for PostgreSQL Flexible Server
RDS (MySQL) Azure Database for MySQL Flexible Server
RDS (SQL Server) Azure SQL Database
ElastiCache (Redis) Azure Cache for Redis
ElastiCache (Memcached) Azure Cache for Redis
S3 Azure Blob Storage
ALB / ELB App Service built-in LB / Azure Front Door
Route 53 Azure DNS
ACM (Certificate Manager) App Service Managed Certificate
CloudWatch Application Insights / Azure Monitor
CloudWatch Alarms Azure Monitor Alerts
X-Ray Application Insights (distributed tracing)
IAM Roles Managed Identity + Azure RBAC
CodePipeline / CodeBuild GitHub Actions / Azure DevOps
CloudFormation Bicep / ARM Templates
Parameter Store Azure App Configuration
Secrets Manager Azure Key Vault
SQS Azure Service Bus / Storage Queue
SNS Azure Event Grid
Auto Scaling Group App Service Autoscale
VPC Azure VNet Integration
Security Groups NSG + App Service Access Restrictions

Platform Preset → Runtime Stack Mapping

Beanstalk Platform App Service Runtime Stack
Node.js 22 Node 22 LTS
Node.js 24 Node 24 LTS
Python 3.13 Python 3.13
Python 3.14 Python 3.14
Java 21 (Corretto) Java 21 (Microsoft Build of OpenJDK)
Java 24 (Corretto) Java 24 (Microsoft Build of OpenJDK)
.NET 10 on Linux .NET 10
Go (Docker) Custom Container (Go)
Ruby Custom Container (Ruby)
PHP 8.x PHP 8.x
Docker Azure App Service (Custom Container)

.ebextensions/ Migration

Beanstalk .ebextensions/ YAML configs map to Bicep and App Settings:

.ebextensions/ Feature Azure Equivalent Implementation
option_settings (env vars) App Settings Bicep siteConfig.appSettings
packages (yum/apt) Startup script or Dockerfile Custom container or startup command
files (config files) Deployment package or Blob Storage Include in app deployment
commands / container_commands Startup command or deployment script az webapp config set --startup-file
Resources (CloudFormation) Bicep modules Equivalent Azure resources
services (sysvinit) WebJobs (continuous) or Azure Functions Background processing — App Service "Always On" only prevents idle unload; it is NOT a replacement for sysvinit-style background services

Example: .ebextensions/ → Bicep

# .ebextensions/environment.config (AWS)
option_settings:
  aws:elasticbeanstalk:application:environment:
    NODE_ENV: production
    DB_HOST: mydb.xxx.rds.amazonaws.com
// Bicep equivalent
resource webApp 'Microsoft.Web/sites@2023-12-01' = {
  properties: {
    siteConfig: {
      appSettings: [
        { name: 'NODE_ENV', value: 'production' }
        { name: 'PGHOST', value: postgresServer.properties.fullyQualifiedDomainName }
      ]
    }
  }
}

RDS → Azure Database Migration

RDS Feature Azure Equivalent
Multi-AZ deployment Zone-redundant HA
Read replicas Read replicas
Automated backups Automated backups (up to 35 days)
Parameter groups Server parameters
Subnet groups VNet integration + private endpoints
IAM authentication Microsoft Entra authentication
RDS Proxy Azure Database for PostgreSQL Flexible Server (built-in PgBouncer)

💡 Tip: Use Azure Database Migration Service (DMS) for data migration from RDS.

Auto Scaling Migration

Beanstalk Scaling App Service Autoscale
MinSize / MaxSize Min/Max instance count
Trigger metric (CPU, Network) Autoscale rules (CPU, Memory, HTTP queue)
BreachDuration Time window + cool-down period
ScalingAdjustment Scale-out/in increment
Time-based scaling Schedule-based autoscale rules
resource autoscale 'Microsoft.Insights/autoscalesettings@2022-10-01' = {
  properties: {
    targetResourceUri: appServicePlan.id
    profiles: [{
      capacity: { minimum: '2', maximum: '10', default: '2' }
      rules: [{
        metricTrigger: {
          metricName: 'CpuPercentage'
          operator: 'GreaterThan'
          threshold: 70
          timeAggregation: 'Average'
          timeWindow: 'PT5M'
        }
        scaleAction: {
          direction: 'Increase'
          type: 'ChangeCount'
          value: '1'
          cooldown: 'PT5M'
        }
      }]
    }]
  }
}

ALB → App Service Load Balancing

ALB Feature Azure Equivalent
Path-based routing App Service path mappings or Front Door rules
Host-based routing Custom domains + Front Door
Health checks App Service Health Check feature
SSL termination Built-in TLS / Front Door
WAF Azure Front Door WAF or App Gateway WAF
Sticky sessions ARR Affinity (App Service)

For global load balancing with WAF, use Azure Front Door instead of App Service built-in LB.

Environment Variables Migration

Source Target Notes
option_settings (env vars) App Settings Non-sensitive config
option_settings (secrets) Key Vault references @Microsoft.KeyVault(SecretUri=...)
Parameter Store refs App Configuration Shared config across environments
Secrets Manager refs Key Vault Secrets with rotation
.env file App Settings + Key Vault Split by sensitivity

Reference Links

Source: SKILL.md on GitHub

No alerts15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill facilitates cloud workload migration to Azure with a focus on security best practices. It includes security considerations such as an attack surface for indirect prompt injection during source code analysis and the handling of sensitive credentials. While these warrant review, the skill provides robust patterns for secure secret management and identity-based access. See detailed analysis for context.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.3.2"
}

README badge

README badge for microsoft/skills/azure-cloud-migrate