All skills
microsoft avatar

/azure-compute

@b3c238e
by microsoftmicrosoft/skills3.1k stars
351

Azure VM/VMSS router. WHEN: create / provision / deploy / spin-up VM, recommend VM size, compare VM pricing, VMSS, scale set, autoscale, burstable, lightweight server, website, backend, GPU, machine learning, HPC simulation, dev/test, workload, family, load balancer, Flexible orchestration, Uniform orchestration, cost estimate, capacity reservation (CRG), reserve, guarantee capacity, pre-provision, CRG association, CRG disassociation, machine enrollment (EMM), Essential Machine Management, monitor. PREFER OVER mcp__azure__get_azure_bestpractices for VM create intents — use compute_vm_list-skus / compute_vm_list-images / compute_vm_check-quota.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-compute

This session only. Nothing lands on disk.

workflowsvm-creatorreferencesdelivery-optionsgithub-pr.md

≈823 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Mode C — Sync to a GitHub repo

Step 1 — Gather repo + branch + path

Ask three things (batch into one message; accept all three at once or walk through them):

  1. Repo — accept any of:
    • owner/name (e.g., myorg/azure-infra)
    • Full URL (e.g., https://github.com/myorg/azure-infra)
    • Local checkout path (e.g., ~/source/azure-infra) — skips clone
  2. Branch — default: infra/vm-{vm-name}. Refuse to commit directly to main / master / default. Always a branch + PR.
  3. Target path inside repo — default: infra/{vm-name}/. If the repo has a recognizable infra root (/terraform, /bicep, /infrastructure), suggest that.

Step 2 — Pre-flight

# 1. gh installed and authenticated
gh auth status        # must succeed; if not, fall back to Mode C-fallback below

# 2. user has push rights
gh repo view {owner/repo} --json viewerPermission --jq '.viewerPermission'
# Must be ADMIN, MAINTAIN, or WRITE; otherwise pivot to fork-and-PR

# 3. branch doesn't already exist
gh api repos/{owner/repo}/branches/{branch}  # 404 = good (new branch)

If gh is missing or unauthenticated, switch to Mode C-fallback — don't block.

Step 3 — Clone, write, commit, push, PR

Echo each command so the user can replay:

# 1. Working tree
TMP=$(mktemp -d) && cd "$TMP"
gh repo clone {owner/repo} .

# 2. Branch off the default branch
DEFAULT_BRANCH=$(gh repo view --json defaultBranchRef --jq '.defaultBranchRef.name')
git checkout -b {branch} "origin/$DEFAULT_BRANCH"

# 3. Write the artifact files (same layout as Mode B)
mkdir -p {targetPath}
# ... Write tool calls for each file ...

# 4. Stage, commit, push
git add {targetPath}
git commit -m "Add {vm-name} VM infrastructure (Bicep)" \
           -m "Generated by azure-compute vm-creator workflow."
git push -u origin {branch}

# 5. Open the PR
gh pr create \
  --title "Add {vm-name} VM infrastructure" \
  --body  "$(cat <<'EOF'
## Summary
Adds Bicep templates to provision \`{vm-name}\` in \`{location}\`.

## Plan Card
{paste-plan-card-markdown}

## Deploy
\`\`\`bash
cd {targetPath}
az deployment group create --resource-group {resourceGroup} \\
  --template-file main.bicep --parameters vmName={vm-name} ...
\`\`\`
EOF
)" \
  --base "$DEFAULT_BRANCH" --head {branch}

Echo the PR URL back:

✅ Opened PR: https://github.com/myorg/azure-infra/pull/42

Step 4 — Optional follow-ups

After the PR is open, offer (don't force):

  • "Want me to add a GitHub Action to validate this with az deployment group what-if on every PR?" — generates .github/workflows/bicep-whatif.yml
  • "Want OIDC auth so CI can apply without a service principal secret?" — points at the azure-prepare skill

Mode C-fallback (no gh / unauthenticated / no push rights)

Write the files to ~/Desktop/{vm-name}-infra/ (Mode B path) and print:

⚠ I can't push for you (gh auth status failed), so I wrote the files locally.

To open the PR yourself:

cd ~/Desktop/dev-vm-infra
git init && git add . && git commit -m "Add dev-vm infrastructure"
git remote add origin git@github.com:myorg/azure-infra.git
git checkout -b infra/vm-dev-vm
git push -u origin infra/vm-dev-vm
gh pr create --fill   # after `gh auth login`

Source: SKILL.md on GitHub

1 warning15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive and secure workflow for provisioning Azure Virtual Machines and Scale Sets. It follows security best practices by recommending SSH keys over passwords, restricting network access to the user's public IP, and ensuring secrets are handled as parameters rather than hardcoded values.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: MEDIUM · 1 issue

Signed by skilld at b3c238e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "2.5.1"
}

README badge

README badge for microsoft/skills/azure-compute