All skills
microsoft avatar

/azure-enterprise-infra-planner

@d58859a
by microsoftmicrosoft/skills3.1k stars
351

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referencesphases1-extract-insights.md

≈664 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Phase 1: Extract Insights

The goal of this phase is to extract insights from the user's existing Azure environment. These insights will be used to guide the planning process in later phases.

  1. Check whether insights already exist at <project-root>/.azure/insights.json. If they do, reuse the existing entries and skip the scan in steps 2–6. In referenced mode, still execute step 7 before completing the gate; in greenfield mode, proceed to the gate.
  2. If no insights file exists, check whether the insights_get tool is available. If it is not, initialize the file with [], then continue to step 7 in referenced mode or proceed to the gate in greenfield mode.
  3. Ask the user which scope to use for generating insights. Present these three options: a. "Subscription-scoped (default subscription)" — use this as the default if the user does not respond. b. "Subscription-scoped (choose a subscription)" — if selected, ask the user to provide a subscription name or ID. c. "Tenant-scoped (slower)"
  4. Ask the user whether there are specific areas they want the insights to focus on. Present these options: a. "General" — use this as the default if the user does not respond. b. "Cost" c. "Reliability" d. "Security" e. "Performance" f. "Other" — this should be a custom input field.
  5. Run the insights_get tool using a general-purpose subagent. Pass a one-line summary via the --query option that describes the user's infrastructure and the types of insights to prioritise. Do not pass the --nocache flag unless the user has explicitly asked for it. Begin Phase 2 while this tool runs.
  6. Once the tool finishes, save the resulting JSON to <project-root>/.azure/insights.json. Do not include tool call metadata. If the tool errors or returns no insights, write an empty array [] to the file instead.
  7. In referenced mode, merge one insight entry for every existing resource into the current insights array. Set existingResource.id, type, name, role, must_not_recreate: true, and integrationPoints using the normalized inventory. Preserve full ARM IDs for actual-state resources and do not duplicate an entry already identified by the same resource ID. Do this even when the resource produces no broader insight.

Gate

  • insights.json must exist and match the Insights Schema defined in schema.md. If the tool errored or returned no insights, the file should contain an empty array [].
  • In referenced mode, every inventoried existing resource has an existingResource entry with must_not_recreate: true; actual-state entries preserve their full ARM IDs.

Source: SKILL.md on GitHub

No alerts15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure. It follows a rigorous 7-phase gated pipeline that incorporates multiple security checkpoints, including mandatory security scanning with Checkov, 'secure-by-default' infrastructure patterns, and explicit user-approval gates for deployment. No security issues were identified.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

Signed by skilld at d58859a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.4.1"
}

README badge

README badge for microsoft/skills/azure-enterprise-infra-planner