All skills
microsoft avatar

/azure-diagnostics

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. WHEN: debug production issues, troubleshoot app service, app service high CPU, app service deployment failure, troubleshoot container apps, troubleshoot functions, troubleshoot AKS, VM RDP, Linux SSH, VM black screen, can't connect to VM, reset VM password, NSG or firewall blocking, kubectl cannot connect, kube-system/CoreDNS failures, pod pending, crashloop, node not ready, upgrade failures, analyze logs, KQL, insights, image pull failures, cold start issues, health probe failures, resource health, root cause of errors, troubleshoot event hubs, troubleshoot service bus, messaging SDK error, AMQP connection failure, message lock lost, service bus dead letter.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-diagnostics

This session only. Nothing lands on disk.

referencescontainer-appsREADME.md

≈740 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Container Apps Troubleshooting

Common Issues Matrix

Symptom Likely Cause Quick Fix
Image pull failure ACR credentials missing az containerapp registry set --identity system
ACR build fails ACR Tasks disabled (free sub) Build locally with Docker
Cold start timeout min-replicas=0 az containerapp update --min-replicas 1
Port mismatch Wrong target port Check Dockerfile EXPOSE matches ingress
App keeps restarting Health probe failing Verify /health endpoint

Image Pull Failures

Diagnose:

# Check registry configuration
az containerapp show --name APP -g RG --query "properties.configuration.registries"

# Check revision status
az containerapp revision list --name APP -g RG --output table

Fix:

az containerapp registry set \
  --name APP -g RG \
  --server ACR.azurecr.io \
  --identity system

ACR Tasks Disabled (Free Subscriptions)

Symptom: az acr build fails with "ACR Tasks is not supported"

Fix: Build locally instead:

docker build -t ACR.azurecr.io/myapp:v1 .
az acr login --name ACR
docker push ACR.azurecr.io/myapp:v1

Cold Start Issues

Symptom: First request very slow or times out

Fix:

az containerapp update --name APP -g RG --min-replicas 1

Health Probe Failures

Symptom: Container keeps restarting

Check:

# View health probe config
az containerapp show --name APP -g RG --query "properties.configuration.ingress"

# Check if /health endpoint responds
curl https://APP.REGION.azurecontainerapps.io/health

Fix: Ensure app has health endpoint returning 200:

app.get('/health', (req, res) => res.sendStatus(200));

Port Mismatch

Symptom: App starts but returns 502/503

Check:

az containerapp show --name APP -g RG --query "properties.configuration.ingress.targetPort"

Verify: App must listen on this exact port. Check:

  • Dockerfile EXPOSE statement
  • process.env.PORT or hardcoded port in app

View Logs

# Stream logs (wait for replicas if scale-to-zero)
az containerapp logs show --name APP -g RG --follow

# Recent logs
az containerapp logs show --name APP -g RG --tail 100

# System logs (startup issues)
az containerapp logs show --name APP -g RG --type system

Get All Diagnostic Info

Use the containerapp-diagnostics script (PowerShell) to collect everything in one call. It prints clearly labeled sections — revisions, registry config, ingress config, and recent logs — and a summary line describing what it collected. Interpreting the output remains your job.

..\..\scripts\containerapp-diagnostics.ps1 -Name <app> -ResourceGroup <rg>
../../scripts/containerapp-diagnostics.sh --name <app> --resource-group <rg>

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill is designed for Azure diagnostics and troubleshooting, providing a comprehensive set of guides and scripts that utilize standard tools like the Azure CLI and kubectl. It includes some security considerations, such as the ingestion of logs which provides a surface for indirect prompt injection, and the use of privileged debug pods for advanced diagnostics. These are used within the skill's intended functionality and are accompanied by appropriate guidance for user approval.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.2.6"
}

README badge

README badge for microsoft/skills/azure-diagnostics