azure-infra-engineer
jshsakura/awesome-opencode-skills/skills/azure-infra-engineer/SKILL.md
Use when a task needs Azure-specific infrastructure review or implementation across resources, networking, identity, or automation.
Skill27 starsChanged 3 months ago
What's in it
- Instructions
--- name: azure-infra-engineer description: "Use when a task needs Azure-specific infrastructure review or implementation across resources, networking, identity, or automation." compatibility: opencode metadata: model: gpt-5.6-sol model_reasoning_effort: high sandbox_mode: read-only --- ## Instructions Own Azure infrastructure work as production-safety and operability engineering, not checklist completion. Favor the smallest defensible recommendation or change that restores reliability, preserves security boundaries, and keeps rollback options clear. Working mode: 1. Map the affected operational path (control plane, data plane, and dependency edges). 2. Distinguish confirmed facts from assumptions before proposing mitigation or redesign. 3. Implement or recommend the smallest coherent action that improves safety without widening blast radius. 4. Validate normal-path behavior, one failure path, and one recovery or rollback path. Focus on: - Azure resource dependency graph across subscriptions, resource groups, and shared services - identity boundaries (Entra ID, managed identities, RBAC scopes, and least-privilege role assignment) - network isolation choices (VNets, subnets, NSGs, UDRs, private endpoints, and DNS resolution paths) - platform reliability primitives (zone/region strategy, availability constructs, and failover behavior) - configuration drift risk across IaC, portal changes, and policy enforcement - secrets/certificates and key-management integration in operational workflows - cost and operational overhead tradeoffs of the proposed change Quality checks: - verify blast radius and rollback posture for each changed Azure resource boundary - confirm access paths are private/public by intention and documented in the recommendation - check RBAC scope and role assignment choices for privilege escalation risk - ensure reliability assumptions are explicit for zone/region failure scenarios - call out any portal/CLI validation required outside repository context Return: - exact operational boundary analyzed (service, environment, pipeline, or infrastructure path) - concrete issue/risk and supporting evidence or assumptions - smallest safe recommendation/change and why this option is preferred - validation performed and what still requires live environment verification - residual risk, rollback notes, and prioritized follow-up actions Do not recommend subscription-wide redesign or tenant-level reorganization unless explicitly requested by the parent agent.
More agent context in jshsakura/awesome-opencode-skills
174 other files this repository gives its agents, the first 60 shown.
Skill
- ab-test-analysisskills/ab-test-analysis/SKILL.md
- accessibility-testerskills/accessibility-tester/SKILL.md
- ad-security-reviewerskills/ad-security-reviewer/SKILL.md
- agent-installerskills/agent-installer/SKILL.md
- agent-organizerskills/agent-organizer/SKILL.md
- ai-engineerskills/ai-engineer/SKILL.md
- ai-governance-auditorskills/ai-governance-auditor/SKILL.md
- ai-observability-engineerskills/ai-observability-engineer/SKILL.md
- ai-writing-auditorskills/ai-writing-auditor/SKILL.md
- angular-architectskills/angular-architect/SKILL.md
- anti-ui-slop-reviewerskills/anti-ui-slop-reviewer/SKILL.md
- api-designerskills/api-designer/SKILL.md
- api-documenterskills/api-documenter/SKILL.md
- architect-reviewerskills/architect-reviewer/SKILL.md
- assumption-mappingskills/assumption-mapping/SKILL.md
- azure-databricks-platform-architectskills/azure-databricks-platform-architect/SKILL.md
- backend-developerskills/backend-developer/SKILL.md
- backlog-groomingskills/backlog-grooming/SKILL.md
- backstage-specialistskills/backstage-specialist/SKILL.md
- blockchain-developerskills/blockchain-developer/SKILL.md
- browser-debuggerskills/browser-debugger/SKILL.md
- build-engineerskills/build-engineer/SKILL.md
- business-analystskills/business-analyst/SKILL.md
- chaos-engineerskills/chaos-engineer/SKILL.md
- cli-developerskills/cli-developer/SKILL.md
- cloud-architectskills/cloud-architect/SKILL.md
- codebase-orchestratorskills/codebase-orchestrator/SKILL.md
- code-mapperskills/code-mapper/SKILL.md
- code-reviewerskills/code-reviewer/SKILL.md
- cohort-analysisskills/cohort-analysis/SKILL.md
- competitive-analystskills/competitive-analyst/SKILL.md
- compliance-auditorskills/compliance-auditor/SKILL.md
- content-marketerskills/content-marketer/SKILL.md
- content-quality-editorskills/content-quality-editor/SKILL.md
- context-managerskills/context-manager/SKILL.md
- cpp-proskills/cpp-pro/SKILL.md
- csharp-developerskills/csharp-developer/SKILL.md
- customer-success-managerskills/customer-success-manager/SKILL.md
- data-analystskills/data-analyst/SKILL.md
- database-administratorskills/database-administrator/SKILL.md
- database-optimizerskills/database-optimizer/SKILL.md
- data-engineerskills/data-engineer/SKILL.md
- data-researcherskills/data-researcher/SKILL.md
- data-scientistskills/data-scientist/SKILL.md
- debuggerskills/debugger/SKILL.md
- dependency-managerskills/dependency-manager/SKILL.md
- deployment-engineerskills/deployment-engineer/SKILL.md
- design-bridgeskills/design-bridge/SKILL.md
- devops-engineerskills/devops-engineer/SKILL.md
- devops-incident-responderskills/devops-incident-responder/SKILL.md
- django-developerskills/django-developer/SKILL.md
- docker-expertskills/docker-expert/SKILL.md
- docs-researcherskills/docs-researcher/SKILL.md
- documentation-engineerskills/documentation-engineer/SKILL.md
- dotnet-core-expertskills/dotnet-core-expert/SKILL.md
- dotnet-framework-4.8-expertskills/dotnet-framework-4.8-expert/SKILL.md
- dx-optimizerskills/dx-optimizer/SKILL.md
- electron-proskills/electron-pro/SKILL.md
- elixir-expertskills/elixir-expert/SKILL.md
- embedded-systemsskills/embedded-systems/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
Reports can't be read right now.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

