All skills
microsoft avatar

/azure-enterprise-infra-planner

@d58859a
by microsoftmicrosoft/skills3.1k stars
351

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesconstraintsdata-relational.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Data (Relational) Pairing Constraints

SQL Server

Paired With Constraint
SQL Database Databases are child resources — must reference this server as parent.
Key Vault (TDE) Key Vault must have enablePurgeProtection: true. Must be in same Azure AD tenant. Server needs GET, WRAP KEY, UNWRAP KEY permissions on key. TDE protector setup fails if Key Vault soft-delete and purge-protection are not both enabled.
Virtual Network Use Microsoft.Sql/servers/virtualNetworkRules to restrict access to specific subnets. Subnets need Microsoft.Sql service endpoint.
Private Endpoint Set publicNetworkAccess: 'Disabled' when using private endpoints exclusively.
Elastic Pool Databases using elastic pools reference elasticPoolId — server must host both pool and databases. Hyperscale elastic pools cannot be created from non-Hyperscale pools.
Failover Group Both primary and secondary servers must exist. Databases to be replicated must belong to the primary server. Failover group from zone-redundant to non-zone-redundant Hyperscale elastic pool fails silently (geo-secondary shows "Seeding 0%").

SQL Database

Paired With Constraint
SQL Server Must be deployed as child of the parent SQL Server. Location must match.
Elastic Pool elasticPoolId must reference a pool on the same server. Cannot set sku when using elastic pool (it inherits pool SKU).
Zone Redundancy Only available in GeneralPurpose, BusinessCritical, and Hyperscale tiers. Not available in DTU tiers. General Purpose zone redundancy is only available in selected regions. Hyperscale zone redundancy can only be set at creation — cannot modify after provisioning; must recreate via copy/restore/geo-replica.
Serverless Only available in GeneralPurpose tier. SKU name uses GP_S_Gen5_* pattern.
Hyperscale Reverse migration from Hyperscale to General Purpose is supported within 45 days of the original migration. Databases originally created as Hyperscale cannot reverse migrate.
Hyperscale Elastic Pool Cannot be created from a non-Hyperscale pool. Cannot be converted to non-Hyperscale (one-way only). Named replicas cannot be added to Hyperscale elastic pools (UnsupportedReplicationOperation). Zone-redundant Hyperscale elastic pools require databases with ZRS/GZRS backup storage — cannot add LRS-backed databases.
Failover Group Failover group from zone-redundant to non-zone-redundant Hyperscale elastic pool fails silently (geo-secondary shows "Seeding 0%").
Backup Redundancy GeoZone only available in select regions. Local not available in all regions.

MySQL Flexible Server

Paired With Constraint
VNet (private access) Requires a dedicated subnet delegated to Microsoft.DBforMySQL/flexibleServers. Subnet must have no other resources.
Private DNS Zone For VNet-integrated (private access) servers, use the zone name {name}.mysql.database.azure.com (not privatelink.*). The privatelink.mysql.database.azure.com zone is used for Private Endpoint connectivity only. Provide privateDnsZoneResourceId and the DNS zone must be linked to the VNet.
High Availability ZoneRedundant HA requires GeneralPurpose or MemoryOptimized tier. Not available with Burstable.
Geo-Redundant Backup Must be enabled at server creation time. Cannot be changed after creation. Not available in all regions.
Storage Auto-Grow Storage can only grow, never shrink. Enabled by default.
Read Replicas Source server must have backup.backupRetentionDays > 1. Replica count limit: up to 10 replicas.
Key Vault (CMK) Customer-managed keys require user-assigned managed identity and Key Vault with purge protection enabled.

PostgreSQL Flexible Server

Paired With Constraint
VNet (private access) Requires a dedicated subnet delegated to Microsoft.DBforPostgreSQL/flexibleServers. Subnet must have no other resources.
Private DNS Zone For VNet-integrated (private access) servers, use the zone name {name}.postgres.database.azure.com (not privatelink.*). The privatelink.postgres.database.azure.com zone is used for Private Endpoint connectivity only. Provide privateDnsZoneArmResourceId and the DNS zone must be linked to the VNet.
High Availability ZoneRedundant HA requires GeneralPurpose or MemoryOptimized tier. Not available with Burstable.
Geo-Redundant Backup Not available in all regions. Cannot be enabled with VNet-integrated (private access) servers in some configurations.
Storage Auto-Grow Storage can only grow, never shrink. Minimum increase is based on current size.
Key Vault (CMK) Customer-managed keys require user-assigned managed identity and Key Vault with purge protection enabled.

Source: SKILL.md on GitHub

No alerts15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure. It follows a rigorous 7-phase gated pipeline that incorporates multiple security checkpoints, including mandatory security scanning with Checkov, 'secure-by-default' infrastructure patterns, and explicit user-approval gates for deployment. No security issues were identified.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

Signed by skilld at d58859a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.4.1"
}

README badge

README badge for microsoft/skills/azure-enterprise-infra-planner