All skills
microsoft avatar

/azure-prepare

@b8a1c66
by microsoftmicrosoft/skills3.1k stars
351

Prepare azd-based Azure projects for deployment: generates azure.yaml, infrastructure (Bicep/Terraform), and Dockerfiles for the Azure Developer CLI (azd) workflow. USE ONLY when the user explicitly wants to use azd as the deployment tool, or the project already has an azure.yaml file. DO NOT USE FOR: non-azd deployments, Python App Service code-only deploys (use python-appservice-deploy), or cross-cloud migration (use azure-cloud-migrate). WHEN: prepare app for azd, create azure.yaml, set up azd infrastructure, modernize app for Azure with azd, deploy with azd, function app, timer trigger, service bus trigger, event-driven function, managed identity, generate Bicep, generate Terraform, create and deploy to Azure.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-prepare

This session only. Nothing lands on disk.

referencesresearch.md

≈2.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Research Components

After architecture planning, research each selected component to gather best practices before generating artifacts.

Process

  1. Identify Components — List all Azure services from architecture plan
  2. Load Service References — For each service, load services/<service>/README.md first, then specific references as needed
  3. Check Resource Naming Rules — For each resource type, check resource naming rules for valid characters, length limits, and uniqueness scopes
  4. Load Recipe References — Load the selected recipe's guide (e.g., AZD) and its IAC rules, MCP best practices, and schema tools listed in its "Before Generation" table
  5. Check Region Availability — Verify all selected services are available in the target region per region-availability.md
  6. Check Provisioning Limits — Invoke azure-quotas skill to validate that the selected subscription and region have sufficient quota/capacity for all planned resources. Complete Step 6 of the plan template in two phases: (1) prepare resource inventory with deployment quantities, (2) fetch quotas and validate capacity using azure-quotas skill
  7. Load Runtime References — For containerized apps, load language-specific production settings (e.g., Node.js)
  8. Invoke Related Skills — For deeper guidance, invoke mapped skills from the table below
  9. Document Findings — Record key insights in .azure/deployment-plan.md

Service-to-Reference Mapping

Azure Service Reference Related Skills
Hosting
Container Apps Container Apps azure-diagnostics, azure-observability, azure-nodejs-production
App Service App Service azure-diagnostics, azure-observability, azure-nodejs-production
Azure Functions Functions —
Static Web Apps Static Web Apps —
AKS AKS azure-networking
Data
Azure SQL SQL Database —
Cosmos DB Cosmos DB —
PostgreSQL — —
Storage (Blob/Files) Storage azure-storage
Messaging
Service Bus Service Bus —
Event Grid Event Grid —
Event Hubs — —
Integration
API Management APIM azure-aigateway (invoke for AI Gateway policies)
Logic Apps Logic Apps —
Workflow & Orchestration
Durable Functions Durable Functions, Durable Task Scheduler —
Durable Task Scheduler Durable Task Scheduler —
Security & Identity
Key Vault Key Vault azure-keyvault-expiration-audit
Managed Identity — entra-app-registration
Observability
Application Insights App Insights appinsights-instrumentation (invoke for instrumentation)
Log Analytics — azure-observability, azure-kusto
AI Services
Azure OpenAI Foundry microsoft-foundry (invoke for AI patterns and model guidance)
AI Search — azure-ai (invoke for search configuration)

Research Instructions

Step 1: Load Internal References (Progressive Loading)

For each selected service, load the README.md first, then load specific files as needed:

Selected: Container Apps, Cosmos DB, Key Vault

→ Load: services/container-apps/README.md (overview)
  → If need Bicep: services/container-apps/bicep.md
  → If need Terraform: services/container-apps/terraform.md
  → If need scaling: services/container-apps/scaling.md
  → If need health probes: services/container-apps/health-probes.md

→ Load: services/cosmos-db/README.md (overview)
  → If need partitioning: services/cosmos-db/partitioning.md
  → If need SDK: services/cosmos-db/sdk.md

→ Load: services/key-vault/README.md (overview)
  → If need SDK: services/key-vault/sdk.md

Step 2: Invoke Related Skills (When Deeper Guidance Needed)

Invoke related skills for specialized scenarios:

Scenario Action
Using Azure Functions Stay in azure-prepare — load selection.md → Follow composition.md algorithm
PostgreSQL with passwordless auth Handle directly without a separate skill
Need detailed security hardening Handle directly with service-specific security guidance and platform best practices
Setting up App Insights instrumentation appinsights-instrumentation
Building AI applications microsoft-foundry
Estimate a planned deployment's cost cost-estimation from the separately installed azure-cost plugin

Skill/Reference Invocation Pattern:

For Azure Functions:

  1. Load: selection.md (decision tree)
  2. Follow: composition.md (algorithm)
  3. Result: Base template + recipe composition (never synthesize IaC)

For PostgreSQL:

  1. Handle passwordless auth patterns directly without a separate skill

Step 3: Document in Plan

Add research findings to .azure/deployment-plan.md under a ## Research Summary section with source references and key insights per component.

Common Research Patterns

Web Application + API + Database (Cosmos DB)

  1. Load: services/container-apps/README.md → bicep.md or terraform.md, scaling.md
  2. Load: services/cosmos-db/README.md → partitioning.md
  3. Load: services/key-vault/README.md
  4. Invoke: azure-observability (monitoring setup)
  5. Review service-specific security guidance directly before generation

Container Apps + API + SQL Database

  1. Load: services/container-apps/README.md → bicep.md or terraform.md, scaling.md
  2. Load: services/sql-database/README.md → bicep.md, auth.md
  3. Load: services/key-vault/README.md
  4. Review auth.md directly for Entra-only auth configuration

App Service + API + SQL Database

  1. Load: services/app-service/README.md → bicep.md
  2. Load: services/sql-database/README.md → bicep.md, auth.md
  3. Load: services/key-vault/README.md
  4. Review auth.md directly for Entra-only auth configuration

Serverless Event-Driven

  1. Load: services/functions/README.md (contains mandatory composition workflow)
  2. Load: services/event-grid/README.md or services/service-bus/README.md (if using messaging)
  3. Load: services/storage/README.md (if using queues/blobs)
  4. Invoke: azure-observability (distributed tracing)

AI Application

  1. Invoke: microsoft-foundry (AI patterns and best practices)
  2. Load: services/container-apps/README.md → bicep.md or terraform.md
  3. Load: services/cosmos-db/README.md → partitioning.md (vector storage)
  4. Review Key Vault and Foundry references directly for API key management

After Research

Proceed to Generate Artifacts step with research findings applied.

Source: SKILL.md on GitHub

2 warnings3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill includes security considerations related to the processing of untrusted project files and the retrieval of external development templates. While these operations are essential for modernizing and preparing Azure applications, they represent a surface area for indirect prompt injection and depend on the integrity of external template repositories.

  • Socket3d

    5 alerts: gptAnomaly, gptSecurity

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    86/87 files flagged

Signed by skilld at b8a1c66. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "1.3.4"
}

README badge

README badge for microsoft/skills/azure-prepare