All skills
microsoft avatar

/azure-diagnostics

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. WHEN: debug production issues, troubleshoot app service, app service high CPU, app service deployment failure, troubleshoot container apps, troubleshoot functions, troubleshoot AKS, VM RDP, Linux SSH, VM black screen, can't connect to VM, reset VM password, NSG or firewall blocking, kubectl cannot connect, kube-system/CoreDNS failures, pod pending, crashloop, node not ready, upgrade failures, analyze logs, KQL, insights, image pull failures, cold start issues, health probe failures, resource health, root cause of errors, troubleshoot event hubs, troubleshoot service bus, messaging SDK error, AMQP connection failure, message lock lost, service bus dead letter.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-diagnostics

This session only. Nothing lands on disk.

troubleshootingmessagingservice-troubleshooting.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Service-Level Troubleshooting

Covers connectivity, firewall, and network issues that apply regardless of SDK language.

Permanent Connectivity Issues

If the client cannot connect at all:

  1. Verify connection string — Get from Azure portal. For Event Hubs (Kafka endpoint) clients, also check producer.config / consumer.config.
  2. Check service outage — Azure status page
  3. Firewall / ports — Open AMQP 5671 and 5672, HTTPS 443. For Event Hubs (Kafka endpoint) only, also open Kafka 9093. Use WebSockets (port 443) as fallback.
  4. IP firewall — If enabled on namespace, ensure client IP is allowed.
  5. VNet / private endpoints — Confirm app runs in correct subnet. Check service endpoint and NSG rules.
  6. Proxy / SSL — Intercepting proxies can cause SSL handshake failures. Test with proxy disabled.

Quick Connectivity Test

Run the connectivity probe script. It resolves DNS, tests HTTPS reachability, and probes the messaging ports (AMQP 5671/5672, HTTPS 443), returning a normalized report instead of raw curl/nslookup output. Add --kafka / -Kafka to also probe the Event Hubs Kafka port 9093.

Scripts (paths below are relative to the skill root, plugins/azure-skills/skills/azure-diagnostics, so run them from there): scripts/test-messaging-connectivity.sh (bash) and scripts/test-messaging-connectivity.ps1 (PowerShell).

# from plugins/azure-skills/skills/azure-diagnostics
.\scripts\test-messaging-connectivity.ps1 -Namespace <namespace>
# from plugins/azure-skills/skills/azure-diagnostics
bash ./scripts/test-messaging-connectivity.sh <namespace>

The namespace may be a full FQDN or a bare name (.servicebus.windows.net is appended automatically).

Example (Event Hubs, including Kafka):

# from plugins/azure-skills/skills/azure-diagnostics
bash ./scripts/test-messaging-connectivity.sh contoso.servicebus.windows.net --kafka

Transient Connectivity Issues

If connectivity is intermittent:

  1. Upgrade SDK — Use latest version; transient issues may already be fixed.
  2. Check dropped packets — netstat -s (Linux) or netsh interface ipv4 show subinterface (Windows).
  3. Capture network traces — Use Wireshark or tcpdump filtered on namespace IP.
  4. Idle disconnect — Service disconnects idle AMQP connections. Clients auto-reconnect; this is expected.

WebSocket Configuration by Language

Language Setting
.NET EventHubsTransportType.AmqpWebSockets / ServiceBusTransportType.AmqpWebSockets
Java AmqpTransportType.AMQP_WEB_SOCKETS
Python transport_type=TransportType.AmqpOverWebsocket
JavaScript webSocketOptions in client constructor

Authentication Checklist

Issue Fix
Invalid connection string Re-copy from Azure portal
Expired SAS token Regenerate or increase validity
Missing RBAC role Assign the corresponding Azure Event Hubs Data Owner/Sender/Receiver or Azure Service Bus Data Owner/Sender/Receiver role
Managed Identity not configured Enable system/user-assigned identity, assign role on namespace

Sender Issues (All Languages)

  • Batch >1MB fails — Service rejects batches over 1MB even with Premium large message support. Send large messages individually.
  • Multiple partition keys in batch — Not allowed. Group messages by partitionKey (or sessionId) into separate batches.

Receiver Issues (All Languages)

  • Batch receive returns fewer messages — After the first message arrives, the receiver waits briefly (20ms–1s depending on SDK) for more. maxWaitTime only controls the wait for the first message.
  • Lock lost before expiry — Can occur on AMQP link detach (transient network or 10-min idle timeout), not only when processing exceeds lock duration.
  • Socket exhaustion — Treat clients as singletons. Each new client creates a new AMQP connection. Always close/dispose clients when done.

Further Reading

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill is designed for Azure diagnostics and troubleshooting, providing a comprehensive set of guides and scripts that utilize standard tools like the Azure CLI and kubectl. It includes some security considerations, such as the ingestion of logs which provides a surface for indirect prompt injection, and the use of privileged debug pods for advanced diagnostics. These are used within the skill's intended functionality and are accompanied by appropriate guidance for user approval.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.2.6"
}

README badge

README badge for microsoft/skills/azure-diagnostics