All skills
microsoft avatar

/azure-diagnostics

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. WHEN: debug production issues, troubleshoot app service, app service high CPU, app service deployment failure, troubleshoot container apps, troubleshoot functions, troubleshoot AKS, VM RDP, Linux SSH, VM black screen, can't connect to VM, reset VM password, NSG or firewall blocking, kubectl cannot connect, kube-system/CoreDNS failures, pod pending, crashloop, node not ready, upgrade failures, analyze logs, KQL, insights, image pull failures, cold start issues, health probe failures, resource health, root cause of errors, troubleshoot event hubs, troubleshoot service bus, messaging SDK error, AMQP connection failure, message lock lost, service bus dead letter.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-diagnostics

This session only. Nothing lands on disk.

troubleshootingmessagingazure-eventhubs-py.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure Event Hubs SDK — Python

Package: azure-eventhub | README | Full Troubleshooting Guide

Common Errors

Exception Cause Fix
EventHubError Base exception wrapping AMQP errors Check message, error, details fields
ConnectionLostError Idle connection disconnected Auto-recovers on next operation; no action needed
AuthenticationError Bad credentials or expired SAS Regenerate key, check RBAC roles, verify connection string
OperationTimeoutError Network or throttling Check firewall, try WebSockets (port 443), increase timeout

Retry Configuration

Auth: DefaultAzureCredential is for local development. See auth-best-practices.md for production patterns.

from azure.eventhub import EventHubProducerClient
from azure.identity import DefaultAzureCredential

client = EventHubProducerClient(
    fully_qualified_namespace="<your-namespace>.servicebus.windows.net",
    eventhub_name="<your-eventhub>",
    credential=DefaultAzureCredential(),
    retry_total=3,
    retry_backoff_factor=0.8,
    retry_backoff_max=120,
    retry_mode='exponential'
)

Consumer Client Retry Configuration

Auth: DefaultAzureCredential is for local development. See auth-best-practices.md for production patterns.

Under heavy load, tune the retry policy on EventHubConsumerClient to reduce timeouts:

Parameter Default Description
retry_total 3 Max retry attempts per operation
retry_backoff_factor 0.8 Backoff multiplier between retries (seconds)
retry_backoff_max 120 Max backoff interval (seconds)
retry_mode exponential fixed or exponential
from azure.eventhub import EventHubConsumerClient
from azure.eventhub.extensions.checkpointstoreblob import BlobCheckpointStore
from azure.identity import DefaultAzureCredential

credential = DefaultAzureCredential()
checkpoint_store = BlobCheckpointStore(
    blob_account_url="https://<storage-account>.blob.core.windows.net",
    container_name="<checkpoint-container>",
    credential=credential
)

client = EventHubConsumerClient(
    fully_qualified_namespace="<your-namespace>.servicebus.windows.net",
    eventhub_name="<your-eventhub>",
    consumer_group="$Default",
    credential=credential,
    checkpoint_store=checkpoint_store,
    retry_total=5,
    retry_backoff_factor=1.0,
    retry_backoff_max=120,
    retry_mode='exponential'
)

Enable Logging

import logging, sys

handler = logging.StreamHandler(stream=sys.stdout)
handler.setFormatter(logging.Formatter("%(asctime)s | %(threadName)s | %(levelname)s | %(name)s | %(message)s"))
logger = logging.getLogger('azure.eventhub')
logger.setLevel(logging.DEBUG)
logger.addHandler(handler)

# Enable AMQP frame tracing
client = EventHubProducerClient(..., logging_enable=True)

Key Issues

  • Buffered producer not sending: Ensure enough ThreadPoolExecutor workers (one per partition). Use buffer_concurrency kwarg.
  • Blocking calls in async: Run CPU-bound code in an executor; blocking the event loop impacts load balancing and checkpointing.
  • Consumer disconnected: Expected during load balancing. If persistent with no scaling, file an issue.
  • Soft delete on checkpoint store: Disable "soft delete" and "blob versioning" on the storage account used for checkpointing.
  • Always close clients: Use with statement or call close() to avoid socket/connection leaks.

Checkpointing (BlobCheckpointStore)

Package: azure-eventhub-checkpointstoreblob (sync) / azure-eventhub-checkpointstoreblob-aio (async)

See the Consumer Client Retry Configuration section above for a full EventHubConsumerClient example with BlobCheckpointStore.

Common issues:

  • Soft delete / blob versioning: Disable both on the storage account — they cause large delays during load balancing.
  • HTTP 412/409 from storage: Normal during partition ownership negotiation; not an error.
  • Checkpoint frequency: Checkpoint after processing each batch, not each event, to avoid storage throttling.

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill is designed for Azure diagnostics and troubleshooting, providing a comprehensive set of guides and scripts that utilize standard tools like the Azure CLI and kubectl. It includes some security considerations, such as the ingestion of logs which provides a surface for indirect prompt injection, and the use of privileged debug pods for advanced diagnostics. These are used within the skill's intended functionality and are accompanied by appropriate guidance for user approval.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.2.6"
}

README badge

README badge for microsoft/skills/azure-diagnostics