Agentic InfraOps - Copilot Instructions
Azure infrastructure engineered by agents. Verified. Well-Architected. Deployable.
Quick Start
- Enable subagents:
"github.copilot.chat": { "customAgentInSubagent": { "enabled": true } }
- Open Chat (
Ctrl+Shift+I) → Select InfraOps Conductor → Describe your project
- The Conductor guides you through all 7 steps with approval gates
7-Step Workflow
| Step |
Agent |
Output |
Gate |
| 1 |
Requirements |
01-requirements.md |
Approval |
| 2 |
Architect |
02-architecture-assessment.md + cost estimate |
Approval |
| 3 |
Design (opt) |
03-des-*.{py,png,md} |
— |
| 4 |
Bicep Plan |
04-implementation-plan.md + governance + 04-dependency-diagram.py/.png + 04-runtime-diagram.py/.png |
Approval |
| 5 |
Bicep Code |
infra/bicep/{project}/ |
Validation |
| 6 |
Deploy |
06-deployment-summary.md |
Approval |
| 7 |
As-Built |
07-*.md documentation suite |
— |
All outputs → agent-output/{project}/. Context flows via artifact files + handoffs.
Skills (Auto-Invoked by Agents)
| Skill |
Purpose |
azure-defaults |
Regions, tags, naming, AVM, security, governance, pricing |
azure-artifacts |
Template H2 structures, styling, generation rules |
azure-bicep-patterns |
Reusable Bicep patterns (hub-spoke, PE, diagnostics) |
azure-troubleshooting |
KQL templates, health checks, remediation playbooks |
azure-diagrams |
Python architecture diagram generation |
azure-adr |
Architecture Decision Records |
github-operations |
GitHub issues, PRs, CLI, Actions, releases |
git-commit |
Commit message conventions |
docs-writer |
Documentation generation |
make-skill-template |
Scaffold new Agent Skills from templates |
microsoft-docs |
Query official Microsoft/Azure docs (requires Learn MCP) |
microsoft-code-reference |
Verify SDK methods and find working code samples (requires Learn MCP) |
microsoft-skill-creator |
Create hybrid skills for Microsoft technologies (requires Learn MCP) |
Agents read skills via: "Read .github/skills/{name}/SKILL.md" in their body.
Chat Triggers
- If a user message starts with
gh, treat it as a GitHub operation.
Examples: gh pr create ..., gh workflow run ..., gh api ....
- Automatically follow the
github-operations skill guidance (MCP-first, gh CLI fallback) from .github/skills/github-operations/SKILL.md.
GitHub MCP Priority (Mandatory)
- For issues and pull requests, always prefer GitHub MCP tools over
gh CLI.
- Only use
gh for operations that have no equivalent MCP write tool in the current environment.
- In devcontainers, do not run
gh auth commands unless the user explicitly asks for CLI authentication troubleshooting.
Key Conventions
- Default region:
swedencentral (exception: Static Web Apps → westeurope)
- Required tags:
Environment, ManagedBy, Project, Owner
- Unique suffix:
uniqueString(resourceGroup().id) — generate once, pass everywhere
- AVM-first: Always prefer Azure Verified Modules over raw Bicep
- Security baseline: TLS 1.2, HTTPS-only, managed identity, Azure AD-only SQL auth
Full details in .github/skills/azure-defaults/SKILL.md.
Key Files
| Path |
Purpose |
.github/agents/*.agent.md |
Agent definitions |
.github/skills/*/SKILL.md |
Reusable skill knowledge |
.github/instructions/ |
File-type rules (Bicep, Markdown, etc.) |
agent-output/{project}/ |
Agent-generated artifacts |
infra/bicep/{project}/ |
Bicep templates |
mcp/azure-pricing-mcp/ |
Azure Pricing MCP server |
.vscode/mcp.json |
MCP server configuration |
Validation
bicep build infra/bicep/{project}/main.bicep
bicep lint infra/bicep/{project}/main.bicep
npm run validate
npm run lint:md
1---2name: agentic-infraops-copilot-instructions-63description: All outputs → agent-output/{project}/. Context flows via artifact files + handoffs.4---5# Agentic InfraOps - Copilot Instructions67> Azure infrastructure engineered by agents. Verified. Well-Architected. Deployable.89## Quick Start10111. Enable subagents: `"github.copilot.chat": { "customAgentInSubagent": { "enabled": true } }`122. Open Chat (`Ctrl+Shift+I`) → Select **InfraOps Conductor** → Describe your project133. The Conductor guides you through all 7 steps with approval gates1415## 7-Step Workflow1617| Step | Agent | Output | Gate |18| ---- | ------------ | --------------------------------------------------------------------------------------------------------- | ---------- |19| 1 | Requirements | `01-requirements.md` | Approval |20| 2 | Architect | `02-architecture-assessment.md` + cost estimate | Approval |21| 3 | Design (opt) | `03-des-*.{py,png,md}` | — |22| 4 | Bicep Plan | `04-implementation-plan.md` + governance + `04-dependency-diagram.py/.png` + `04-runtime-diagram.py/.png` | Approval |23| 5 | Bicep Code | `infra/bicep/{project}/` | Validation |24| 6 | Deploy | `06-deployment-summary.md` | Approval |25| 7 | As-Built | `07-*.md` documentation suite | — |2627All outputs → `agent-output/{project}/`. Context flows via artifact files + handoffs.2829## Skills (Auto-Invoked by Agents)3031| Skill | Purpose |32| ------------------- | --------------------------------------------------------- |33| `azure-defaults` | Regions, tags, naming, AVM, security, governance, pricing |34| `azure-artifacts` | Template H2 structures, styling, generation rules |35| `azure-bicep-patterns` | Reusable Bicep patterns (hub-spoke, PE, diagnostics) |36| `azure-troubleshooting` | KQL templates, health checks, remediation playbooks |37| `azure-diagrams` | Python architecture diagram generation |38| `azure-adr` | Architecture Decision Records |39| `github-operations` | GitHub issues, PRs, CLI, Actions, releases |40| `git-commit` | Commit message conventions |41| `docs-writer` | Documentation generation |42| `make-skill-template` | Scaffold new Agent Skills from templates |43| `microsoft-docs` | Query official Microsoft/Azure docs (requires Learn MCP) |44| `microsoft-code-reference` | Verify SDK methods and find working code samples (requires Learn MCP) |45| `microsoft-skill-creator` | Create hybrid skills for Microsoft technologies (requires Learn MCP) |4647Agents read skills via: **"Read `.github/skills/{name}/SKILL.md`"** in their body.4849## Chat Triggers5051- If a user message starts with `gh`, treat it as a GitHub operation.52 Examples: `gh pr create ...`, `gh workflow run ...`, `gh api ...`.53- Automatically follow the `github-operations` skill guidance (MCP-first, `gh` CLI fallback) from `.github/skills/github-operations/SKILL.md`.5455### GitHub MCP Priority (Mandatory)5657- For issues and pull requests, always prefer GitHub MCP tools over `gh` CLI.58- Only use `gh` for operations that have no equivalent MCP write tool in the current environment.59- In devcontainers, do not run `gh auth` commands unless the user explicitly asks for CLI authentication troubleshooting.6061## Key Conventions6263- **Default region**: `swedencentral` (exception: Static Web Apps → `westeurope`)64- **Required tags**: `Environment`, `ManagedBy`, `Project`, `Owner`65- **Unique suffix**: `uniqueString(resourceGroup().id)` — generate once, pass everywhere66- **AVM-first**: Always prefer Azure Verified Modules over raw Bicep67- **Security baseline**: TLS 1.2, HTTPS-only, managed identity, Azure AD-only SQL auth6869Full details in `.github/skills/azure-defaults/SKILL.md`.7071## Key Files7273| Path | Purpose |74| --------------------------- | --------------------------------------- |75| `.github/agents/*.agent.md` | Agent definitions |76| `.github/skills/*/SKILL.md` | Reusable skill knowledge |77| `.github/instructions/` | File-type rules (Bicep, Markdown, etc.) |78| `agent-output/{project}/` | Agent-generated artifacts |79| `infra/bicep/{project}/` | Bicep templates |80| `mcp/azure-pricing-mcp/` | Azure Pricing MCP server |81| `.vscode/mcp.json` | MCP server configuration |8283## Validation8485```bash86bicep build infra/bicep/{project}/main.bicep87bicep lint infra/bicep/{project}/main.bicep88npm run validate89npm run lint:md90```