All skills
microsoft avatar

/azure-cloud-migrate

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Assess and migrate cross-cloud workloads to Azure with reports and code conversion. Supports Lambda→Functions, Beanstalk/Heroku/App Engine→App Service, Fargate/Kubernetes/Cloud Run/Spring Boot→Container Apps. WHEN: migrate Lambda to Functions, AWS to Azure, migrate Beanstalk, migrate Heroku, migrate App Engine, Cloud Run migration, Fargate to ACA, ECS/Kubernetes/GKE/EKS to Container Apps, Spring Boot to Container Apps, cross-cloud migration.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-cloud-migrate

This session only. Nothing lands on disk.

referencesservicescontainer-appsfargate-assessment-guide.md

≈614 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Assessment: Fargate to Container Apps

Checklist

1. Container Configuration

  • CPU/Memory: Extract from task definition and verify the requested CPU/memory fits within Azure Container Apps limits for the target environment/region
  • Container Images: Registry location (ECR), image size, base image
  • Port Mappings: Exposed ports and protocols

2. Environment & Secrets

  • Static configuration values (env vars)
  • Secret references: Secrets Manager ARNs → Key Vault URLs with managed identity
  • Parameter Store references → App Configuration or Key Vault
  • Service discovery endpoints

3. Networking

  • VPC subnets (public vs private) → VNet integration
  • Security groups → NSG rules
  • Load balancer type (ALB/NLB) → Container Apps ingress (built-in HTTPS)
  • Health check configuration and SSL/TLS certificates

4. IAM & Security

  • Task role policies → Managed Identity + Azure RBAC
  • ECR pull permissions → ACR role assignment (AcrPull)
  • Secrets Manager access → Key Vault RBAC (recommended) or access policies for vaults still using access-policy mode

5. Dependencies

  • Databases: RDS → Azure Database for PostgreSQL/MySQL/SQL
  • Cache: ElastiCache → Azure Cache for Redis
  • Storage: S3 → Azure Blob Storage (SDK: boto3 → azure-storage-blob)
  • Messaging: SQS/SNS → Service Bus / Event Grid
  • Monitoring: CloudWatch → Azure Monitor / Log Analytics (requires Log Analytics workspace on Container Apps environment)

6. Scaling & Performance

  • Auto scaling policies (target tracking, min/max tasks)
  • Request rate and latency requirements
  • Actual CPU/memory usage vs allocation

Resource Mapping

ECS Task Definition Container Apps Equivalent
cpu: "512" (0.5 vCPU) cpu: 0.5
memory: "1024" (MB) memory: 1Gi
containerPort ingress.targetPort
environment env array
secrets (Secrets Manager ARN) secrets with keyVaultUrl + identity
logConfiguration (awslogs) Log Analytics (requires workspace on environment)
Service Auto Scaling scale.rules (HTTP/CPU/memory/custom)

Complexity Rating

  • Low: Single container, no VPC, standard env vars, public ingress
  • Medium: Multiple containers, VPC with private connectivity, secrets, custom IAM
  • High: Multi-service dependencies, VPN/Direct Connect, cross-account IAM, stateful workloads

Source: SKILL.md on GitHub

No alerts15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill facilitates cloud workload migration to Azure with a focus on security best practices. It includes security considerations such as an attack surface for indirect prompt injection during source code analysis and the handling of sensitive credentials. While these warrant review, the skill provides robust patterns for secure secret management and identity-based access. See detailed analysis for context.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.3.2"
}

README badge

README badge for microsoft/skills/azure-cloud-migrate