All skills
microsoft avatar

/azure-cloud-migrate

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Assess and migrate cross-cloud workloads to Azure with reports and code conversion. Supports Lambda→Functions, Beanstalk/Heroku/App Engine→App Service, Fargate/Kubernetes/Cloud Run/Spring Boot→Container Apps. WHEN: migrate Lambda to Functions, AWS to Azure, migrate Beanstalk, migrate Heroku, migrate App Engine, Cloud Run migration, Fargate to ACA, ECS/Kubernetes/GKE/EKS to Container Apps, Spring Boot to Container Apps, cross-cloud migration.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-cloud-migrate

This session only. Nothing lands on disk.

referencesservicescontainer-appscloudrun-assessment-guide.md

≈639 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Assessment: Cloud Run to Container Apps

Checklist

1. Service Configuration

  • CPU/Memory: Cloud Run (1–4 vCPU, 128 MiB–32 GiB) → Container Apps (0.25–4 vCPU, 0.5–8 Gi)
  • Images: Registry location (GCR or Artifact Registry), image size, base image
  • Port: Exposed port (Cloud Run default 8080)
  • Environment Variables: Static values, secret references, service URLs

2. Request Handling

  • Concurrency: Per instance (default 80, max 1000) → Container Apps (1–300)
  • Min/Max Instances: 0–1000 → Container Apps 0–300 per revision
  • Timeout: Max 60 min → Container Apps max 30 min (1800s)
  • CPU Allocation: Request-based vs always → Container Apps always allocated
  • HTTP/2, WebSockets, gRPC: Document if used

3. Networking

  • Ingress: Public, internal (VPC), or internal + load balancing
  • Custom Domains: List domains and SSL certificates
  • VPC Connector: Region, IP range, connected VPC
  • Dependencies: Cloud SQL, Firestore, Cloud Storage, Pub/Sub, Redis, external APIs

4. IAM & Security

  • Service Account: Default or custom
  • IAM Roles: Storage, Firestore, Pub/Sub, Secret Manager, Cloud SQL permissions
  • Task role policies → Managed Identity + Azure RBAC
  • Secret Manager access → Key Vault RBAC (recommended) or access policies for vaults still using access-policy mode

5. Observability

  • Logging: Destinations, structured logs (JSON)
  • Monitoring: Request metrics, CPU/memory, instance count
  • Tracing: Cloud Trace → Application Insights

6. Event-Driven

  • Eventarc: Pub/Sub triggers, Cloud Storage triggers
  • Cloud Scheduler: Schedule (cron), target endpoint

7. Cost Analysis

  • Cloud Run: Request charges, CPU/memory time
  • Data transfer egress charges
  • Container Registry storage

Resource Mapping

Cloud Run Config Container Apps Equivalent
--concurrency 80 --scale-rule-http-concurrency 80
--min-instances 0 --min-replicas 0
--max-instances 10 --max-replicas 10
--cpu 1 --cpu 1.0
--memory 512Mi --memory 1Gi
--port 8080 --target-port 8080
--timeout 300 ingress timeout 300s

Complexity Rating

  • Low: Single container, public ingress, standard env vars, no VPC
  • Medium: Internal ingress, Pub/Sub triggers, custom service account, Cloud Scheduler
  • High: Complex traffic management, VPC networking, multiple Eventarc triggers, long-running requests (>30 min)

Source: SKILL.md on GitHub

No alerts15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill facilitates cloud workload migration to Azure with a focus on security best practices. It includes security considerations such as an attack surface for indirect prompt injection during source code analysis and the handling of sensitive credentials. While these warrant review, the skill provides robust patterns for secure secret management and identity-based access. See detailed analysis for context.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.3.2"
}

README badge

README badge for microsoft/skills/azure-cloud-migrate