All skills
microsoft avatar

/azure-diagnostics

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. WHEN: debug production issues, troubleshoot app service, app service high CPU, app service deployment failure, troubleshoot container apps, troubleshoot functions, troubleshoot AKS, VM RDP, Linux SSH, VM black screen, can't connect to VM, reset VM password, NSG or firewall blocking, kubectl cannot connect, kube-system/CoreDNS failures, pod pending, crashloop, node not ready, upgrade failures, analyze logs, KQL, insights, image pull failures, cold start issues, health probe failures, resource health, root cause of errors, troubleshoot event hubs, troubleshoot service bus, messaging SDK error, AMQP connection failure, message lock lost, service bus dead letter.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-diagnostics

This session only. Nothing lands on disk.

troubleshootingcomputereferencescannot-connect-to-vm.md

≈801 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Cannot Connect to VM

Router for Azure VM connectivity issues. Determine OS first: Windows usually means RDP/3389 and TermService; Linux means SSH/22 and sshd; other images usually use SSH but may need current docs.

Routing

Signal Category Reference
can't RDP, timeout, black screen, internal error RDP rdp-connectivity.md
can't SSH, refused, permission denied, publickey SSH ssh-connectivity.md
NSG, public IP, NIC, routes, effective rules Network network-connectivity.md
Windows Firewall, iptables, firewalld, UFW Guest firewall firewall-blocking.md
VM agent, Run Command timeout, Serial Console, boot diagnostics VM agent/tools vm-agent-not-responding.md
password, credentials, access denied, CredSSP, account expired Credential/auth credential-auth-errors.md
TermService, RDP disabled, changed port, TLS cert, NLA, licensing RDP service/config rdp-service-config.md

Workflow

  1. Pick the symptom category and open the linked reference.
  2. Match the user's symptom to a solution row and fetch current docs for that row.
  3. Before extension-backed operations, run pre-flight checks.
  4. Return evidence, likely cause, safe next command, remediation, and escalation.

Pre-Flight Safety Checks

Run before az vm user update, az vm user reset-ssh, az vm user reset-remote-desktop, az vm run-command invoke, or any extension-backed operation.

az vm get-instance-view --name <vm> -g <rg> \
  --query "instanceView.{power:[statuses[?starts_with(code,'PowerState/')]][0][0].code,prov:[statuses[?starts_with(code,'ProvisioningState/')]][0][0].code,agent:vmAgent.statuses[0].displayStatus}" -o json
az vm extension list --vm-name <vm> -g <rg> \
  --query "[].{name:name,state:provisioningState}" -o table
Check Safe Unsafe
Power PowerState/running other, missing, or query error
Provisioning ProvisioningState/succeeded creating/updating/deleting/failed, missing, or query error
VM agent Ready not ready, null, missing, or query error
Extensions all Succeeded or none creating/updating/deleting/failed

If unsafe: stop, name the failed check, and use non-agent options such as Serial Console, offline repair VM, or Portal actions. If transient, wait and rerun checks only.

Escalation

Check Resource Health, then offer restart or redeploy only with user approval. For broad docs, use Windows RDP, Linux SSH, Windows VM hub, or Linux VM hub.

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill is designed for Azure diagnostics and troubleshooting, providing a comprehensive set of guides and scripts that utilize standard tools like the Azure CLI and kubectl. It includes some security considerations, such as the ingestion of logs which provides a surface for indirect prompt injection, and the use of privileged debug pods for advanced diagnostics. These are used within the skill's intended functionality and are accompanied by appropriate guidance for user approval.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.2.6"
}

README badge

README badge for microsoft/skills/azure-diagnostics