All skills
microsoft avatar

/azure-enterprise-infra-planner

@d58859a
by microsoftmicrosoft/skills3.1k stars
351

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-enterprise-infra-planner

This session only. Nothing lands on disk.

referenceswaf-checklist.md

≈487 tokens on demand. Your agent reads this file only when SKILL.md points to it.

WAF Cross-Cutting Checklist

Walk through every row and decide if resources or properties are needed.

Concern Question Resources / Properties to Add
Identity How do services authenticate to each other? Managed identity, RBAC role assignments
Secrets Are there connection strings, API keys, credentials? Key Vault with RBAC authorization, soft-delete, and purge protection enabled
Monitoring How will operators observe the system? Application Insights for compute, Log Analytics workspace, diagnostic settings on data resources
Network Should resources have public endpoints? Prefer private connectivity (VNet integration, private endpoints, publicNetworkAccess: "Disabled"). Only expose endpoints publicly when the workload requires it, and document the decision as a tradeoff.
Encryption Is data encrypted at rest and in transit? HTTPS-only, modern minimum TLS, Key Vault for customer-managed keys
Resilience Single points of failure? Zone-redundant SKUs where supported; compute distributed across ≥2 zones for production. Document deviations as tradeoffs.
Auth hardening Can local/key-based auth be disabled? Disable local auth on services that support it (e.g. Event Grid, Service Bus, Storage)
Tagging Resources tagged for cost tracking? Tags on every resource

Common Additions

Most workloads should include these unless sub-goals justify omission:

  • Key Vault — secrets, certificates, customer-managed keys
  • Managed Identity — prefer over keys for service-to-service auth
  • Application Insights — for App Service, Functions, Container Apps, AKS
  • Log Analytics — centralized log aggregation
  • Diagnostic Settings — wire data resources to Log Analytics

If you intentionally skip a concern (e.g., no VNet for cost reasons), document it in overallReasoning.tradeoffs and inputs.subGoals.

Source: SKILL.md on GitHub

No alerts15d3 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a comprehensive framework for planning and deploying Azure infrastructure. It follows a rigorous 7-phase gated pipeline that incorporates multiple security checkpoints, including mandatory security scanning with Checkov, 'secure-by-default' infrastructure patterns, and explicit user-approval gates for deployment. No security issues were identified.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

Signed by skilld at d58859a. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.4.1"
}

README badge

README badge for microsoft/skills/azure-enterprise-infra-planner