Systematic diagnosis and remediation for Azure production issues using AppLens, Monitor, and resource health. Covers Container Apps, Function Apps, and AKS troubleshooting with service-specific guides for image pulls, cold starts, health probes, invocation failures, and node/pod issues Integrates AppLens (MCP) for AI-powered root cause analysis and Azure Monitor (MCP) for KQL-based log and metric queries Provides a five-step diagnostic flow: identify symptoms, check resource health, review logs, analyze metrics, and investigate recent changes Includes quick reference commands for activity logs, container logs, and App Insights queries, plus routing guidance for AKS-specific incidents
Pre-deployment validation for Azure readiness with configuration, infrastructure, RBAC, and identity checks. Runs recipe-specific validation commands including Bicep builds, Terraform validation, and Azure CLI preflight checks Verifies RBAC role assignments in infrastructure code and managed identity permissions before deployment Requires .azure/deployment-plan.md from azure-prepare skill; records validation proof and updates plan status to Validated only after all checks pass Integrates into the three-step workflow: azure-prepare → azure-validate → azure-deploy
Microsoft Entra ID app registration, OAuth 2.0 configuration, and MSAL integration for secure application authentication. Covers app registration setup, authentication configuration, API permissions, and client credential management across web apps, SPAs, mobile apps, and daemon services Includes step-by-step workflows for first-time registration, console application authentication, and service-to-service credential flows Provides Azure CLI commands, MSAL library examples for .NET, JavaScript, Python, and Java, plus security best practices for secret rotation and token validation Distinguishes scope clearly: handles identity and authentication setup but excludes Azure RBAC, Key Vault secrets management, and resource security
Guidance and reference material for instrumenting webapps with Azure Application Insights. Covers SDK setup, telemetry patterns, and configuration for ASP.NET Core and Node.js applications hosted in Azure Distinguishes between this skill (reference and guidance) and azure-prepare (actual implementation); invoke azure-prepare when the user wants to add instrumentation to their project Provides auto-instrumentation guidance for C# ASP.NET Core apps in Azure App Service, plus manual instrumentation paths for creating App Insights resources via Bicep templates or Azure CLI Includes language-specific code modification guides for ASP.NET Core, Node.js, and Python, plus quick references for OpenTelemetry SDKs and exporters
Fast discovery and inventory of Azure resources across subscriptions using Resource Graph queries. Queries any Azure resource type (VMs, storage accounts, web apps, container apps, Key Vaults, etc.) across subscriptions and resource groups in a single command Supports cross-cutting searches for orphaned resources, missing tags, unhealthy states, and resource inventory counts Routes single-resource-type queries to dedicated MCP tools when available; falls back to Azure Resource Graph for broader or unsupported resource types Uses KQL (Kusto Query Language) for flexible filtering, with built-in error handling for authorization, syntax, and scope issues
Transform Azure resource groups into detailed architecture diagrams showing resource relationships and configurations. Discovers all resources within a resource group and analyzes their configurations, dependencies, and interconnections Generates Mermaid diagrams organized by logical layers (Network, Compute, Data, Security, Monitoring) with SKU details and connection labels Maps relationships including network connections, data flows, identity bindings, and configuration dependencies across resources Creates comprehensive markdown documentation with resource inventory tables, architecture diagrams, and relationship explanations
Diagnose and resolve Azure Event Hubs and Service Bus SDK issues with structured troubleshooting workflows. Covers connection failures, authentication errors, AMQP link issues, message lock timeouts, and event processor stalls across Python, Java, JavaScript, and .NET SDKs Includes language-specific troubleshooting guides for Event Hubs and Service Bus, plus connectivity diagnostics for ports, WebSocket fallback, IP firewalls, and private endpoints Provides MCP tools to query resource health, list namespaces/hubs/queues/topics, and search Microsoft Learn documentation for error resolution Structured diagnosis workflow: identify SDK version, check resource health, match error messages, look up docs, verify configuration, and apply fixes
Assess and migrate cloud workloads from AWS, GCP, and other providers to Azure services. Supports Lambda-to-Azure Functions migration with dedicated scenario reference and best practices Generates assessment reports mapping source services to Azure equivalents before any code conversion Converts source code to target Azure runtime models, with output isolated in a separate <source-folder>-azure/ directory Requires sequential phase execution: assessment first, then migration, with user confirmation before destructive actions Hands off to azure-prepare skill for infrastructure provisioning, local testing, and deployment workflows
Assess and automate upgrades of Azure workloads across plans, tiers, and SKUs. Handles plan migrations (Consumption to Flex Consumption), tier upgrades, and cross-service moves (App Service to Container Apps) with sequential assessment before any changes Generates pre-upgrade readiness reports, collects existing app settings and configurations, then executes automated upgrade steps with idempotent scripts Requires explicit user confirmation for destructive actions and target plan/SKU selection before proceeding Validates upgrades by testing app reachability and monitoring, then hands off to azure-validate or azure-deploy for deeper validation or CI/CD setup
Deploy ADK agents to Agent Runtime, Cloud Run, or GKE with managed infrastructure and CI/CD pipelines. Choose deployment target based on language support, scaling model, networking, and cost: Agent Runtime (managed, Python-only), Cloud Run (custom infra, event-driven), or GKE (full Kubernetes control) Deploy via agents-cli deploy with flags for secrets, environment variables, service accounts, and networking (VPC, PSC, DNS peering for Agent Runtime) Set up production CI/CD pipelines with Workfront Identity Federation (WIF) authentication, cross-project service accounts, and automated staging-to-production promotion Manage infrastructure as code in Terraform; define custom resources (Cloud SQL, Pub/Sub, BigQuery, Eventarc) in version control, never manually via gcloud Rollback via git-based redeployment or Cloud Run traffic shifting; troubleshoot via Cloud Logging and IAM permission checks on service accounts
Evaluate ADK agents with metrics, evalsets, and the iterative eval-fix loop. Run evaluations with agents-cli eval run using configurable criteria (tool trajectory, response matching, rubric-based scoring, hallucination detection, safety checks) and match types (EXACT, IN_ORDER, ANY_ORDER) Build evalsets with multi-turn conversation cases, expected tool trajectories, intermediate responses, and session state overrides Iterate through 5-10+ eval-fix cycles: diagnose failures, fix agent instructions or tool logic, rerun, and track progress with task lists Avoid common pitfalls: don't lower thresholds to hide failures, handle extra tool calls with IN_ORDER matching, ensure app name matches directory, and initialize state with callbacks to prevent KeyError crashes
Project scaffolding, deployment configuration, and CI/CD setup for Google ADK agents. Covers three main commands: scaffold create for new projects, scaffold enhance to add deployment and CI/CD to existing projects, and scaffold upgrade to apply version updates while preserving customizations Supports three agent templates (standard ADK, agent-to-agent A2A, and agentic RAG) with deployment targets including Agent Runtime, Cloud Run, and GKE Enforces a prototype-first workflow: start with --prototype to skip infrastructure, iterate on agent code, then add deployment later via enhance Requires clarifying user requirements before scaffolding; project names must be 26 characters or less with lowercase letters, numbers, and hyphens only
Plan and configure production-ready Azure Kubernetes Service clusters with Day-0 and Day-1 best practices. Distinguishes Day-0 decisions (networking, API server access, pod IP model) that are hard to change later from Day-1 features (observability, upgrades, autoscaling) that can be enabled post-creation Covers AKS Automatic vs Standard SKU selection, Azure CNI Overlay networking, security (Microsoft Entra ID, Azure Policy, Secrets Store CSI), and observability with Managed Prometheus and Container Insights Provides guidance on node pools, compute optimization (ephemeral OS disks, Azure Linux, latest-generation SKUs), reliability patterns (3 Availability Zones, PodDisruptionBudgets), and cost controls (Spot nodes, Reserved Instances) Includes deep-dive references for pod rightsizing, Vertical Pod Autoscaler, cluster autoscaler configuration, and Spot node pool setup
Postgres performance optimization rules across 8 priority categories, from query tuning to advanced features. Organized into 8 rule categories prioritized by impact: query performance and connection management (critical), security and RLS, schema design, concurrency, data access patterns, monitoring, and advanced features Each rule includes detailed explanations, incorrect vs. correct SQL examples, EXPLAIN output analysis, and performance metrics to guide optimization decisions Covers query indexing, connection pooling, Row-Level Security configuration, schema design patterns, locking behavior, and Postgres-specific tuning Designed for use during SQL writing, schema design, performance reviews, and database scaling decisions
Step-by-step configuration guides for Prisma ORM across PostgreSQL, MySQL, SQLite, MongoDB, SQL Server, CockroachDB, and Prisma Postgres. Covers datasource configuration, driver adapter selection, and Prisma Client instantiation for seven database providers Prisma v7 requires explicit driver adapters (e.g., @prisma/adapter-pg for PostgreSQL) and a prisma.config.ts file for connection URLs Includes quick-reference schema blocks and prerequisite checks (Node.js 20.19.0+, TypeScript 5.4.0+) MongoDB support limited to Prisma v6; v7 users must upgrade or use an alternative provider Provides troubleshooting guidance for connection strings, environment variables, and database-specific feature setup