All skills
microsoft avatar

/azure-diagnostics

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. WHEN: debug production issues, troubleshoot app service, app service high CPU, app service deployment failure, troubleshoot container apps, troubleshoot functions, troubleshoot AKS, VM RDP, Linux SSH, VM black screen, can't connect to VM, reset VM password, NSG or firewall blocking, kubectl cannot connect, kube-system/CoreDNS failures, pod pending, crashloop, node not ready, upgrade failures, analyze logs, KQL, insights, image pull failures, cold start issues, health probe failures, resource health, root cause of errors, troubleshoot event hubs, troubleshoot service bus, messaging SDK error, AMQP connection failure, message lock lost, service bus dead letter.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-diagnostics

This session only. Nothing lands on disk.

troubleshootingaksload-balancer-and-ingress.md

≈922 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Load Balancer And Ingress Troubleshooting

Use this guide when AKS networking symptoms point at Azure load balancer provisioning, ingress controller behavior, or backend routing.

Load Balancer Stuck In Pending

Diagnostics:

kubectl describe svc <svc> -n <ns>
# Events section reveals the actual Azure error

kubectl logs -n kube-system -l component=cloud-controller-manager --tail=100

Error decision table:

Error in Events / CCM Logs Cause Fix
InsufficientFreeAddresses Subnet has no free IPs Expand subnet CIDR; use Azure CNI Overlay; use NAT gateway instead
ensure(default/svc): failed... PublicIPAddress quota Public IP quota exhausted Request quota increase for Public IP Addresses in the region
cannot find NSG NSG name changed or detached Re-associate NSG to the AKS subnet; check az aks show for NSG name
reconciling NSG rules: failed NSG is locked or has conflicting rules Remove resource lock; check for deny-all rules above AKS-managed rules
subnet not found Wrong subnet name in annotation Verify subnet name: az network vnet subnet list -g <rg> --vnet-name <vnet>
No events, stuck Pending CCM can't authenticate to Azure Check cluster managed identity access on the VNet resource group

Ingress Not Routing Traffic

Diagnostics:

# Confirm controller is running
kubectl get pods -n <ingress-ns> -l 'app.kubernetes.io/name in (ingress-nginx,nginx-ingress)'
kubectl logs -n <ingress-ns> -l app.kubernetes.io/name=ingress-nginx --tail=100

# Check the ingress resource state
kubectl describe ingress <name> -n <ns>
kubectl get ingress <name> -n <ns>

# Check backend
kubectl get endpoints <backend-svc> -n <ns>

Ingress failure patterns:

Symptom Cause Fix
ADDRESS empty LB not provisioned or wrong ingressClassName Check controller service; set correct ingressClassName
404 for all paths No matching host rule Check host field; pathType: Prefix vs Exact
404 for some paths Trailing slash mismatch Prefix /api matches /api/foo not /api - add both
502 Bad Gateway Backend pods unhealthy or wrong port Verify Endpoints has IPs; confirm targetPort and readiness
503 Service Unavailable All backend pods down Check pod restarts and readiness probe
TLS handshake fail cert-manager not issuing Check certificate status and ACME challenge
Works for host-a, 404 for host-b DNS not pointing to ingress IP Verify nslookup <host> resolves to the ingress address

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill is designed for Azure diagnostics and troubleshooting, providing a comprehensive set of guides and scripts that utilize standard tools like the Azure CLI and kubectl. It includes some security considerations, such as the ingestion of logs which provides a surface for indirect prompt injection, and the use of privileged debug pods for advanced diagnostics. These are used within the skill's intended functionality and are accompanied by appropriate guidance for user approval.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.2.6"
}

README badge

README badge for microsoft/skills/azure-diagnostics