All skills
microsoft avatar

/azure-resource-manager-sql-dotnet

@073741f
by microsoftmicrosoft/skills3.1k stars
351

Azure Resource Manager SDK for Azure SQL in .NET. Use for MANAGEMENT PLANE operations: creating/managing SQL servers, databases, elastic pools, firewall rules, and failover groups via Azure Resource Manager. NOT for data plane operations (executing queries) - use Microsoft.Data.SqlClient for that. Triggers: "SQL server", "create SQL database", "manage SQL resources", "ARM SQL", "SqlServerResource", "provision Azure SQL", "elastic pool", "firewall rule".

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-resource-manager-sql-dotnet

This session only. Nothing lands on disk.

referencesserver-management.md

≈1.3k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Server Management

Advanced server operations for Azure SQL.

Create Server with Azure AD Authentication

using Azure.ResourceManager.Sql;
using Azure.ResourceManager.Sql.Models;

var serverData = new SqlServerData(AzureLocation.EastUS)
{
    // SQL authentication (optional, can be disabled)
    AdministratorLogin = "sqladmin",
    AdministratorLoginPassword = "YourSecurePassword123!",
    
    // Azure AD authentication
    Administrators = new ServerExternalAdministrator
    {
        AdministratorType = SqlAdministratorType.ActiveDirectory,
        Login = "admin@contoso.com",
        Sid = Guid.Parse("<azure-ad-user-object-id>"),
        TenantId = Guid.Parse("<azure-ad-tenant-id>"),
        AzureADOnlyAuthentication = false // Set true to disable SQL auth
    },
    
    Version = "12.0",
    MinimalTlsVersion = SqlMinimalTlsVersion.Tls1_2
};

var operation = await serverCollection.CreateOrUpdateAsync(
    WaitUntil.Completed,
    "my-sql-server",
    serverData);

Update Server Administrator Password

// Get existing server
var server = await serverCollection.GetAsync("my-sql-server");

// Update password (requires full server data)
var updateData = server.Value.Data;
// Note: Password cannot be read, only set
// You need to create new SqlServerData with the new password

var newServerData = new SqlServerData(server.Value.Data.Location)
{
    AdministratorLogin = server.Value.Data.AdministratorLogin,
    AdministratorLoginPassword = "NewSecurePassword456!"
};

await serverCollection.CreateOrUpdateAsync(
    WaitUntil.Completed,
    "my-sql-server",
    newServerData);

Configure Public Network Access

var serverData = new SqlServerData(AzureLocation.EastUS)
{
    AdministratorLogin = "sqladmin",
    AdministratorLoginPassword = "YourSecurePassword123!",
    
    // Disable public access (use private endpoints only)
    PublicNetworkAccess = ServerNetworkAccessFlag.Disabled,
    
    // Or enable with restrictions
    // PublicNetworkAccess = ServerNetworkAccessFlag.Enabled,
    // RestrictOutboundNetworkAccess = ServerNetworkAccessFlag.Enabled
};

Get Server by Resource ID

var resourceId = SqlServerResource.CreateResourceIdentifier(
    subscriptionId,
    "my-resource-group",
    "my-sql-server");

var server = armClient.GetSqlServerResource(resourceId);
var serverData = await server.GetAsync();

Delete Server

var server = await serverCollection.GetAsync("my-sql-server");
await server.Value.DeleteAsync(WaitUntil.Completed);

Check Server Name Availability

var checkRequest = new SqlNameAvailabilityContent
{
    Name = "proposed-server-name",
    ResourceType = "Microsoft.Sql/servers"
};

var result = await subscription.CheckSqlNameAvailabilityAsync(checkRequest);

if (result.Value.IsAvailable == true)
{
    Console.WriteLine("Name is available");
}
else
{
    Console.WriteLine($"Name unavailable: {result.Value.Reason}");
}

Virtual Network Rules

// Allow access from a specific subnet
var vnetRuleData = new SqlServerVirtualNetworkRuleData
{
    VirtualNetworkSubnetId = new ResourceIdentifier(
        "/subscriptions/{sub}/resourceGroups/{rg}/providers/" +
        "Microsoft.Network/virtualNetworks/{vnet}/subnets/{subnet}"),
    IgnoreMissingVnetServiceEndpoint = false
};

var vnetRuleCollection = server.GetSqlServerVirtualNetworkRules();
await vnetRuleCollection.CreateOrUpdateAsync(
    WaitUntil.Completed,
    "allow-app-subnet",
    vnetRuleData);

Private Endpoints

// Private endpoints are created via Microsoft.Network, not SQL SDK
// The SQL server just needs PublicNetworkAccess = Disabled

// After creating private endpoint, approve the connection:
var privateEndpointConnections = server.GetSqlServerPrivateEndpointConnections();

await foreach (var connection in privateEndpointConnections)
{
    if (connection.Data.PrivateLinkServiceConnectionState.Status == "Pending")
    {
        // Approve the connection
        var approvalData = connection.Data;
        approvalData.PrivateLinkServiceConnectionState.Status = "Approved";
        approvalData.PrivateLinkServiceConnectionState.Description = "Approved by admin";
        
        await privateEndpointConnections.CreateOrUpdateAsync(
            WaitUntil.Completed,
            connection.Data.Name,
            approvalData);
    }
}

Server Auditing

var auditingData = new SqlServerBlobAuditingPolicyData
{
    State = BlobAuditingPolicyState.Enabled,
    StorageEndpoint = "https://mystorageaccount.blob.core.windows.net",
    StorageAccountAccessKey = "<storage-account-key>",
    RetentionDays = 90,
    IsStorageSecondaryKeyInUse = false,
    IsAzureMonitorTargetEnabled = true
};

var auditingPolicy = server.GetSqlServerBlobAuditingPolicy();
await auditingPolicy.CreateOrUpdateAsync(WaitUntil.Completed, auditingData);

Transparent Data Encryption (Server-Level Key)

// Configure customer-managed key for TDE
var protectorData = new EncryptionProtectorData
{
    ServerKeyType = SqlServerKeyType.AzureKeyVault,
    ServerKeyName = "mykeyvault_mykey_abc123",
    AutoRotationEnabled = true
};

var protector = server.GetEncryptionProtector();
await protector.CreateOrUpdateAsync(WaitUntil.Completed, protectorData);

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a standard set of instructions and code examples for managing Azure SQL resources using the official Microsoft .NET SDK. It correctly identifies the distinction between management and data plane operations and emphasizes security best practices like using managed identities for authentication.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    5/5 files flagged

Signed by skilld at 073741f. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 5 months ago
Other metadata
metadata
{
  "author": "Microsoft",
  "version": "1.0.0",
  "package": "Azure.ResourceManager.Sql"
}

README badge

README badge for microsoft/skills/azure-resource-manager-sql-dotnet