All skills
microsoft avatar

/azure-enterprise-infra-planner

@d58859a
by microsoftmicrosoft/skills3.1k stars
351

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesconstraintsmonitoring.md

≈450 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Monitoring Pairing Constraints

Application Insights

Paired With Constraint
Log Analytics Workspace-based App Insights (recommended) requires WorkspaceResourceId. Classic (standalone) is being phased out.
Function App Set APPLICATIONINSIGHTS_CONNECTION_STRING or APPINSIGHTS_INSTRUMENTATIONKEY in function app settings.
App Service Set APPLICATIONINSIGHTS_CONNECTION_STRING in app settings. Enable auto-instrumentation for supported runtimes.
AKS Use Container Insights (different from App Insights) for cluster-level monitoring. App Insights used for application-level telemetry.
Private Link Use Azure Monitor Private Link Scope (AMPLS) to restrict ingestion/query to private networks.
Retention If workspace-based, retention is governed by the Log Analytics workspace. Component-level retention acts as an override.

Log Analytics

Paired With Constraint
Application Insights App Insights WorkspaceResourceId must reference this workspace. Both should be in the same region for optimal performance.
AKS (Container Insights) AKS omsagent addon references workspace via logAnalyticsWorkspaceResourceID.
Diagnostic Settings Multiple resources can send diagnostics to the same workspace. Configure via Microsoft.Insights/diagnosticSettings on each resource.
Retention Free tier is limited to 7-day retention. PerGB2018 supports 30–730 days. Archive tier available for longer retention.
Private Link Use Azure Monitor Private Link Scope (AMPLS) for private ingestion/query. A workspace can be linked to up to 100 AMPLS resources (a VNet can connect to only one AMPLS).

Source: SKILL.md on GitHub

No alerts15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure. It follows a rigorous 7-phase gated pipeline that incorporates multiple security checkpoints, including mandatory security scanning with Checkov, 'secure-by-default' infrastructure patterns, and explicit user-approval gates for deployment. No security issues were identified.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

Signed by skilld at d58859a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.4.1"
}

README badge

README badge for microsoft/skills/azure-enterprise-infra-planner