All skills
microsoft avatar

/azure-enterprise-infra-planner

@d58859a
by microsoftmicrosoft/skills3.1k stars
351

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesconstraintsai-ml.md

≈832 tokens on demand. Your agent reads this file only when SKILL.md points to it.

AI & ML Pairing Constraints

AI Search

Paired With Constraint
Cognitive Services (AI Enrichment) For AI enrichment pipelines (skillsets), attach a Cognitive Services account. Must be kind: 'CognitiveServices' or kind: 'AIServices' and in the same region as the search service.
Storage Account (Indexers) Indexer data sources support Blob, Table, and File storage. Storage must be accessible (same VNet or public). For managed identity access, assign Storage Blob Data Reader role.
Cosmos DB (Indexers) Indexer data source for Cosmos DB. Requires connection string or managed identity with Cosmos DB Account Reader Role.
SQL Database (Indexers) Indexer data source. Requires change tracking enabled on the source table.
Private Endpoints When publicNetworkAccess: 'Disabled', create shared private link resources for outbound connections to data sources.
Managed Identity Assign system or user-assigned identity for secure connections to data sources. Use RBAC instead of connection strings.
Semantic Search Requires semanticSearch property set to free or standard. Available on basic and above SKUs.

Cognitive Services

Paired With Constraint
Azure OpenAI Deployments When kind: 'OpenAI' or kind: 'AIServices', create model deployments as child resource accounts/deployments.
Microsoft Entra ID Auth Requires customSubDomainName to be set. Without it, only API key auth works.
Private Endpoint Requires customSubDomainName. Set publicNetworkAccess: 'Disabled' and configure private DNS zone.
Key Vault (CMK) When using customer-managed keys, Key Vault must have soft-delete and purge protection enabled. Set encryption.keySource: 'Microsoft.KeyVault'.
Storage Account When using userOwnedStorage, the storage account must be in the same region. Required for certain features (e.g., batch translation).
AI Foundry Hub When kind: 'AIServices' with allowProjectManagement: true, can manage Foundry projects as child resources (accounts/projects).
VNet Integration Configure networkAcls with defaultAction: 'Deny' and add virtual network rules. Set bypass: 'AzureServices' to allow trusted Azure services.

ML Workspace

Paired With Constraint
Storage Account Must be linked via properties.storageAccount. Cannot change after creation. Use StorageV2 kind with standard SKU.
Key Vault Must be linked via properties.keyVault. Cannot change after creation. Requires soft-delete enabled.
Application Insights Linked via properties.applicationInsights. Should use workspace-based App Insights (backed by Log Analytics).
Container Registry Optional but recommended for custom environments. Linked via properties.containerRegistry.
Hub workspace (kind=Project) Must set properties.hubResourceId to the parent Hub's ARM resource ID. The Project inherits the Hub's linked resources.
VNet Integration When managedNetwork.isolationMode is AllowOnlyApprovedOutbound, must configure outbound rules for all dependent services.

Source: SKILL.md on GitHub

No alerts15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure. It follows a rigorous 7-phase gated pipeline that incorporates multiple security checkpoints, including mandatory security scanning with Checkov, 'secure-by-default' infrastructure patterns, and explicit user-approval gates for deployment. No security issues were identified.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

Signed by skilld at d58859a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.4.1"
}

README badge

README badge for microsoft/skills/azure-enterprise-infra-planner