Overview
Azure operations covering VMs, App Service, Functions, AKS, Cosmos DB, and Azure AD for identity management.
Capabilities
- Virtual Machine management
- App Service web hosting
- Azure Functions serverless
- AKS Kubernetes clusters
- Cosmos DB multi-model
- Azure AD identity
- ARM/Bicep templates
When to Use
Trigger phrases:
"azure ops"
"Azure operations — Virtual Machines, App Service, Azure Functions, AKS, Cosmos D"
Azure cloud management
Enterprise identity with Azure AD
.NET application hosting
Hybrid cloud scenarios
When NOT to Use
- Task is outside your authorization scope
- You need to implement controls (use implementing-* skills)
- Task is about analysis, not action (use analyzing-* skills)
- You don't have access to target systems
- Task requires compliance expertise (consult professionals)
- Task is about defense, not offense (use defensive skills)
Pseudo Code
The azure-ops workflow follows a standard pipeline pattern.
Core flow:
# azure-ops primary flow
input = prepare(raw_data)
result = process(input, config={azure, cosmos, functions, machines, operations})
validate(result)
deliver(result)
Error handling:
on error:
log(error_details)
retry_with_backoff(max=3)
if still_failing: alert_and_escalate()
Azure CLI Deploy
az webapp create -g MyRG -p MyPlan -n MyApp --runtime "NODE:18-lts"
az functionapp create -g MyRG -p MyPlan -n MyFunc --runtime node
Common Patterns
- Managed identities over secrets
- Azure Policy for compliance
- Resource locks for production
- Reserved instances for savings
How to Use
- Define infrastructure as code (Terraform, CloudFormation, Pulumi)
- Review changes through PR process before applying
- Configure monitoring and alerting for critical paths
- Set up secrets management (Vault, AWS Secrets Manager, etc.)
- Document runbooks for deployment, rollback, and incident response
- Test disaster recovery procedures regularly
Red Flags
- Infrastructure changes without review: Unreviewed changes cause outages — use PRs for infra code
- No rollback strategy: Every deployment needs a tested rollback plan before it runs
- Secrets in configuration files: Secrets in YAML/JSON get committed to version control
- Missing monitoring and alerting: Without monitoring, outages go undetected until users report them
- No documentation for runbooks: Without runbooks, on-call engineers waste time re-discovering procedures
Verification
Process
- Analyze the task requirements
- Apply domain expertise
- Verify output quality
Anti-Rationalization Table
| Rationalization |
Reality |
| "Manual deployments are fine" |
Manual deployments are error-prone and不可 repeatable. Automate. |
| "We do not need monitoring" |
Without monitoring, you are flying blind. Add observability from day one. |
| "Infrastructure as code is overkill" |
IaC enables reproducibility, version control, and disaster recovery. |
1---2name: azure-ops3description: Manages Azure operations including Virtual Machines, App Service, Azure Functions, AKS, Cosmos DB, and Azure AD identity, with guidance on infrastructure as code and operational best practices.4license: Apache-2.05---6789## Overview1011Azure operations covering VMs, App Service, Functions, AKS, Cosmos DB, and Azure AD for identity management.1213## Capabilities1415- Virtual Machine management16- App Service web hosting17- Azure Functions serverless18- AKS Kubernetes clusters19- Cosmos DB multi-model20- Azure AD identity21- ARM/Bicep templates2223## When to Use24**Trigger phrases:**25- "azure ops"26- "Azure operations — Virtual Machines, App Service, Azure Functions, AKS, Cosmos D"272829- Azure cloud management30- Enterprise identity with Azure AD31- .NET application hosting32- Hybrid cloud scenarios3334## When NOT to Use3536- Task is outside your authorization scope37- You need to implement controls (use implementing-* skills)38- Task is about analysis, not action (use analyzing-* skills)39- You don't have access to target systems40- Task requires compliance expertise (consult professionals)41- Task is about defense, not offense (use defensive skills)424344## Pseudo Code4546The azure-ops workflow follows a standard pipeline pattern.4748Core flow:49```50# azure-ops primary flow51input = prepare(raw_data)52result = process(input, config={azure, cosmos, functions, machines, operations})53validate(result)54deliver(result)55```5657Error handling:58```59on error:60 log(error_details)61 retry_with_backoff(max=3)62 if still_failing: alert_and_escalate()63```646566### Azure CLI Deploy67```bash68az webapp create -g MyRG -p MyPlan -n MyApp --runtime "NODE:18-lts"69az functionapp create -g MyRG -p MyPlan -n MyFunc --runtime node70```7172## Common Patterns7374- Managed identities over secrets75- Azure Policy for compliance76- Resource locks for production77- Reserved instances for savings7879## How to Use80811. Define infrastructure as code (Terraform, CloudFormation, Pulumi)822. Review changes through PR process before applying833. Configure monitoring and alerting for critical paths844. Set up secrets management (Vault, AWS Secrets Manager, etc.)855. Document runbooks for deployment, rollback, and incident response866. Test disaster recovery procedures regularly8788## Red Flags8990- **Infrastructure changes without review**: Unreviewed changes cause outages — use PRs for infra code91- **No rollback strategy**: Every deployment needs a tested rollback plan before it runs92- **Secrets in configuration files**: Secrets in YAML/JSON get committed to version control93- **Missing monitoring and alerting**: Without monitoring, outages go undetected until users report them94- **No documentation for runbooks**: Without runbooks, on-call engineers waste time re-discovering procedures9596## Verification9798- [ ] Skill output matches expected behavior99100## Process1011021. Analyze the task requirements1032. Apply domain expertise1043. Verify output quality105106## Anti-Rationalization Table107108| Rationalization | Reality |109|---|---|110| "Manual deployments are fine" | Manual deployments are error-prone and不可 repeatable. Automate. |111| "We do not need monitoring" | Without monitoring, you are flying blind. Add observability from day one. |112| "Infrastructure as code is overkill" | IaC enables reproducibility, version control, and disaster recovery. |