All skills
microsoft avatar

/azure-enterprise-infra-planner

@d58859a
by microsoftmicrosoft/skills3.1k stars
351

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesdeployment.md

≈951 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Deployment Execution

Execute infrastructure deployment after plan approval and IaC generation.

Status Gate

Before executing any deployment command, verify:

meta.status === "approved"

If status is not approved, stop and inform the user. Do not manually change the status.

Pre-Deployment Checklist

  1. Plan approved — meta.status is approved
  2. IaC generated — Bicep or Terraform files exist in <project-root>/infra/
  3. Azure context confirmed — subscription and resource group selected
  4. User confirmation — explicit "yes, deploy" from the user
  5. Syntax validated — az bicep build or terraform validate passed

Bicep Deployment

Scope selection: use resource-group scope when your template deploys into an existing resource group. Use subscription scope when your template creates resource groups or other subscription-level resources (policies, role assignments, etc.).

# Validate first (applies to both scopes)
az bicep build --file infra/main.bicep

Choose the command based on the targetScope set in main.bicep (see bicep-generation.md Bicep Conventions):

targetScope When to use Command
resourceGroup (default) All resources in one resource group az deployment group create
subscription Resources span multiple resource groups, or includes subscription-level resources (policy, RBAC, resource group creation) az deployment sub create

Resource Group Scope

# What-if preview
az deployment group create \
  --resource-group <resource-group-name> \
  --template-file infra/main.bicep \
  --parameters infra/main.bicepparam \
  --what-if

# Deploy
az deployment group create \
  --resource-group <resource-group-name> \
  --template-file infra/main.bicep \
  --parameters infra/main.bicepparam \
  --name <deployment-name>

PowerShell:

az deployment group create `
  --resource-group <resource-group-name> `
  --template-file infra/main.bicep `
  --parameters infra/main.bicepparam `
  --name <deployment-name>

Subscription Scope

# What-if preview
az deployment sub create \
  --location <location> \
  --template-file infra/main.bicep \
  --parameters infra/main.bicepparam \
  --what-if

# Deploy
az deployment sub create \
  --location <location> \
  --template-file infra/main.bicep \
  --parameters infra/main.bicepparam \
  --name <deployment-name>

PowerShell:

az deployment sub create `
  --location <location> `
  --template-file infra/main.bicep `
  --parameters infra/main.bicepparam `
  --name <deployment-name>

Terraform Deployment

cd infra

# Initialize
terraform init

# Preview changes
terraform plan -var-file=prod.tfvars -out=tfplan

# Apply (requires confirmation)
terraform apply tfplan

PowerShell:

Set-Location infra
terraform init
terraform plan -var-file=prod.tfvars -out=tfplan
terraform apply tfplan

Post-Deployment

After successful deployment:

  1. Update status — set meta.status to deployed in <project-root>/.azure/infrastructure-plan.json
  2. Verify resources — list resources in the target resource group using Azure CLI: az resource list -g <resource-group-name> -o table
  3. Report to user — list deployed resources, endpoints, and any follow-up actions

Error Handling

Error Action
Authentication failure Run az login and retry
Quota exceeded Check limits with mcp_azure_mcp_quota, select different SKU or region
Name conflict Resource name already taken; append unique suffix or choose new name
Region unavailable Service not available in chosen region; select alternative
Validation failure Fix IaC syntax errors before retrying deployment

Source: SKILL.md on GitHub

No alerts15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure. It follows a rigorous 7-phase gated pipeline that incorporates multiple security checkpoints, including mandatory security scanning with Checkov, 'secure-by-default' infrastructure patterns, and explicit user-approval gates for deployment. No security issues were identified.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

Signed by skilld at d58859a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.4.1"
}

README badge

README badge for microsoft/skills/azure-enterprise-infra-planner