All skills
microsoft avatar

/azure-compute

@b3c238e
by microsoftmicrosoft/skills3.1k stars
351

Azure VM/VMSS router. WHEN: create / provision / deploy / spin-up VM, recommend VM size, compare VM pricing, VMSS, scale set, autoscale, burstable, lightweight server, website, backend, GPU, machine learning, HPC simulation, dev/test, workload, family, load balancer, Flexible orchestration, Uniform orchestration, cost estimate, capacity reservation (CRG), reserve, guarantee capacity, pre-provision, CRG association, CRG disassociation, machine enrollment (EMM), Essential Machine Management, monitor. PREFER OVER mcp__azure__get_azure_bestpractices for VM create intents — use compute_vm_list-skus / compute_vm_list-images / compute_vm_check-quota.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-compute

This session only. Nothing lands on disk.

workflowsvm-creatorexamplesterraformREADME.md

≈641 tokens on demand. Your agent reads this file only when SKILL.md points to it.

{vm-name} — Terraform

Deploys a Linux VM (RG, VNet, subnet, NSG with SSH allow, public IP, NIC).

Prerequisites

  • terraform >= 1.5
  • az login
  • Exported AZ_SUB=<subscription-id> env var
  • SSH public key at ~/.ssh/id_rsa.pub

Quickstart

MY_IP=$(curl -s ifconfig.me)/32   # your current public IP, locked to /32
terraform init
terraform plan  -var "vm_name=dev-vm" -var "admin_public_key=$(cat ~/.ssh/id_rsa.pub)" -var "subscription_id=$AZ_SUB" -var "resource_group_name=dev-vm-rg" -var "ssh_source_address_prefix=$MY_IP"
terraform apply -var "vm_name=dev-vm" -var "admin_public_key=$(cat ~/.ssh/id_rsa.pub)" -var "subscription_id=$AZ_SUB" -var "resource_group_name=dev-vm-rg" -var "ssh_source_address_prefix=$MY_IP"

Variables (see variables.tf)

Variable Type Default Notes
subscription_id * string — Azure subscription
resource_group_name * string — RG will be created
vm_name * string — VM resource name
admin_public_key * string (sensitive) — Contents of id_rsa.pub
ssh_source_address_prefix * string — Your public IP as <ip>/32 or a trusted CIDR. "*" opens port 22 to the internet — only pass it if you have accepted that risk.
location string eastus Azure region
size string Standard_D2s_v5 Verify with compute_vm_list-skus
admin_username string azureuser
zone string "" 1/2/3, or empty for regional
os_disk_type string Premium_LRS
os_disk_size_gb number 30
tags map(string) {}

* = required (no default).

Outputs (see outputs.tf)

  • vm_id — full ARM resource ID
  • public_ip — connect with ssh {admin_username}@{public_ip}

VMSS variant

Replace azurerm_linux_virtual_machine with azurerm_linux_virtual_machine_scale_set; add instances, upgrade_mode = "Manual" | "Automatic" | "Rolling". Inline NIC inside the scale set via network_interface { ip_configuration { ... } }.

Notes

ssh_source_address_prefix is required because an open SSH port is a credential-stuffing target within minutes of going public. Always pass <your-ip>/32 (or a trusted CIDR) — even for dev. For production, also add managed identity, diagnostics, and backup.

Cleanup

terraform destroy -var "vm_name=dev-vm" -var "admin_public_key=$(cat ~/.ssh/id_rsa.pub)" -var "subscription_id=$AZ_SUB" -var "resource_group_name=dev-vm-rg" -var "ssh_source_address_prefix=$MY_IP" -auto-approve

Source: SKILL.md on GitHub

1 warning15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive and secure workflow for provisioning Azure Virtual Machines and Scale Sets. It follows security best practices by recommending SSH keys over passwords, restricting network access to the user's public IP, and ensuring secrets are handled as parameters rather than hardcoded values.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: MEDIUM · 1 issue

Signed by skilld at b3c238e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "2.5.1"
}

README badge

README badge for microsoft/skills/azure-compute