All skills
microsoft avatar

/azure-diagnostics

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. WHEN: debug production issues, troubleshoot app service, app service high CPU, app service deployment failure, troubleshoot container apps, troubleshoot functions, troubleshoot AKS, VM RDP, Linux SSH, VM black screen, can't connect to VM, reset VM password, NSG or firewall blocking, kubectl cannot connect, kube-system/CoreDNS failures, pod pending, crashloop, node not ready, upgrade failures, analyze logs, KQL, insights, image pull failures, cold start issues, health probe failures, resource health, root cause of errors, troubleshoot event hubs, troubleshoot service bus, messaging SDK error, AMQP connection failure, message lock lost, service bus dead letter.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-diagnostics

This session only. Nothing lands on disk.

troubleshootingaksreferencesaks-mcp.md

≈389 tokens on demand. Your agent reads this file only when SKILL.md points to it.

AKS MCP Reference

Use this reference when AKS-aware MCP tools are available in the client.

Preference Order

  1. mcp_azure_mcp_aks
  2. The AKS-MCP tools that surface after discovery in the client
  3. Supporting Azure tools such as mcp_azure_mcp_applens, mcp_azure_mcp_monitor, and mcp_azure_mcp_resourcehealth
  4. Raw az aks and kubectl only when required functionality is missing from MCP

Happy Path

After selecting mcp_azure_mcp_aks, let the client enumerate the exact AKS-MCP tools it exposes and choose the smallest tool that fits the task.

Favor the obvious read paths first:

  • cluster and Azure-side inspection
  • detector or diagnostic workflows
  • monitoring, metrics, or control-plane-log checks
  • kubectl-style read operations

Authentication And Access

AKS-MCP is Azure CLI-backed. Expect service principal, workload identity, managed identity, or existing az login auth, usually keyed by AZURE_CLIENT_ID. If AZURE_SUBSCRIPTION_ID is set, expect the server to select that subscription after login.

Default to readonly. Only suggest readwrite or admin when the current diagnostic step truly requires it.

Detector Notes

For detector-style workflows, use the cluster resource ID, keep the time window within the last 30 days, cap each run to 24 hours, and stay within the supported AKS detector categories.

Fallback Rule

If the client does not expose the AKS-MCP surface needed for a check, then fall back to:

  • az aks for Azure-side AKS operations
  • raw kubectl for Kubernetes-side inspection

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill is designed for Azure diagnostics and troubleshooting, providing a comprehensive set of guides and scripts that utilize standard tools like the Azure CLI and kubectl. It includes some security considerations, such as the ingestion of logs which provides a surface for indirect prompt injection, and the use of privileged debug pods for advanced diagnostics. These are used within the skill's intended functionality and are accompanied by appropriate guidance for user approval.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.2.6"
}

README badge

README badge for microsoft/skills/azure-diagnostics