Skip to content
Back to skills

Apex Azure Defaults

ASecurity

**UTILITY SKILL** — Applies canonical Azure defaults through an IaC workflow covering governance precedence, CAF naming, AVM-first composition, unique suffixes, cost monitoring, VNet planning, and lifecycle checks. WHEN: "Azure naming convention", "CAF naming", "resource tags", "AVM module", "security baseline", "region default". DO NOT USE FOR: artifact templates or pricing lookups.

  • 216 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentsgobashazureterraformgitsecurity

Works with

  • claude code
  • cli

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add jonathan-vella/apex --skill apex-azure-defaults --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Apex Azure Defaults?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Apex Azure Defaults
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jonathan-vella-apex-azure-defaults/badge)](https://www.skillsdirectory.com/skills/jonathan-vella-apex-azure-defaults)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: apex-azure-defaults
user-invocable: false
disable-model-invocation: false
description: '**UTILITY SKILL** — Applies canonical Azure defaults through an IaC workflow covering governance precedence, CAF naming, AVM-first composition, unique suffixes, cost monitoring, VNet planning, and lifecycle checks. WHEN: "Azure naming convention", "CAF naming", "resource tags", "AVM module", "security baseline", "region default". DO NOT USE FOR: artifact templates or pricing lookups.'
compatibility: Works with Claude Code, GitHub Copilot, VS Code, and any Agent Skills compatible tool.
license: MIT
metadata:
  author: jonathan-vella
  version: "3.0"
  category: azure-infrastructure
---

# Azure Defaults

Apply the canonical defaults from
[`.github/copilot-instructions.md`](../../copilot-instructions.md#azure-defaults-canonical)
without duplicating them here. Live governance discovered for the target scope
always overrides repository defaults.

## Prerequisites

- Reuse the canonical Azure Defaults section while current and available;
  reload missing required guidance after edits, compaction or a new chat.
- Read `04-governance-constraints.json` when it exists.
- Read `sku-manifest.json` for creative SKU decisions; do not derive SKUs from
  artifact prose.
- Load only the reference needed for the current decision.

## IaC Workflow

1. **Resolve governance precedence** — apply live policy constraints before
   fallback regions, tags, networking, cost, or security defaults.
2. **Generate one stable suffix** — derive it once from deployment scope and
   pass it to every globally unique resource name.
3. **Apply CAF naming** — use resource-specific abbreviations and length limits;
   load [naming examples](references/naming-full-examples.md) when constraints
   differ by service.
4. **Resolve AVM modules live** — prefer AVM, pin the latest stable version at
   plan time, and record justified stale-pin exceptions in the IaC contract.
5. **Apply canonical security defaults** — load the
  [networking and security baseline](../../instructions/references/iac-security-baseline.md)
  before security elicitation or design; do not offer baseline opt-outs. Load
   [AVM pitfalls](references/security-baseline-full.md) only when module
   parameters or lifecycle constraints require detail.
6. **Run conditional planning gates** — apply VNet and cost-monitoring workflows
   when their triggers hold; governance remains authoritative.
7. **Check service lifecycle** — use the latest supported GA LTS runtime and
   reject retired, classic, preview, or short-lifecycle choices for durable
   production workloads unless explicitly approved.
8. **Validate the output** — run the stack validator and the security, AVM pin,
   SKU coverage, and governance checks relevant to the produced IaC.

## IaC-Specific Invariants

- **Unique suffix**: generate one deterministic suffix per deployment scope and
  pass it into modules rather than recomputing it independently.
- **AVM-first**: do not hand-roll a resource with an applicable stable AVM module.
- **Live pins**: resolve module versions at plan time; training-data pins are not
  evidence of currency.
- **Governance wins**: discovered policy overrides every fallback in the
  canonical defaults and this workflow.
- **Security is a floor**: missing policy does not relax the baseline. Conflicting
  policy/security requirements block the affected design for human resolution.
- **VNet planning is interactive**: confirm CIDRs when a workload requires VNet
  integration, private endpoints, or a VNet-attached service. Production cannot
  defer the gate.
- **Cost monitoring is explicit**: production requires the governed budget,
  notification, and anomaly-monitoring contract; non-production exceptions must
  use a documented mode.
- **Lifecycle is verified live**: selectable engine and runtime versions require
  current support-policy evidence.

## Validation

```bash
npm run validate:region-canonical
npm run validate:iac-security-baseline
npm run validate:avm-versions:freeze
npm run validate:sku-iac-coverage
```

Then run `bicep build` and `bicep lint`, or `terraform fmt -check` and
`terraform validate`, for the selected stack.

## Reference Index

Load references progressively; do not read the directory wholesale.

| Decision area | References |
| --- | --- |
| Naming and tags | [Naming examples](references/naming-full-examples.md), [tag strategy](references/tag-strategy.md) |
| AVM and security | [AVM modules](references/avm-modules.md), [security and AVM pitfalls](references/security-baseline-full.md) |
| Networking | [VNet planning](references/vnet-planning.md), [identity resolution](references/identity-resolution.md) |
| Cost and sizing | [Cost baseline](references/cost-alerts-baseline.md), [Bicep](references/cost-alerts-bicep.md), [Terraform](references/cost-alerts-terraform.md), [pricing](references/pricing-guidance.md), [service matrices](references/service-matrices.md) |
| Governance and lifecycle | [Governance discovery](references/governance-discovery.md), [policy effects](references/policy-effect-decision-tree.md), [deprecated services](references/deprecated-services.md), [workflow gates](references/workflow-gates.md) |
| Architecture and review | [WAF criteria](references/waf-criteria.md), [research workflow](references/research-workflow.md), [review protocol](references/adversarial-review-protocol.md), [deep review](references/adversarial-review-deep.md) |
| IaC implementation | [Terraform conventions](references/terraform-conventions.md), [plan decisions](references/plan-design-decisions.md), [Azure CLI auth](references/azure-cli-auth-validation.md) |
| Artifact integration | [Artifact categories](references/artifact-type-categories.md), [cost delegation](references/cost-estimate-parent-contract.md), [service class menu](references/service-class-menu.md) |

Files in this skill

  • SKILL.md5.8 KB
  • references/adversarial-checklists.md22.9 KB
  • references/adversarial-review-deep.md4.4 KB
  • references/adversarial-review-protocol.md34.2 KB
  • references/artifact-type-categories.md2.2 KB
  • references/avm-modules.md4.8 KB
  • references/azure-cli-auth-validation.md2.3 KB
  • references/cost-alerts-baseline.md8.5 KB
  • references/cost-alerts-bicep.md9.6 KB
  • references/cost-alerts-terraform.md6.3 KB
  • references/cost-estimate-parent-contract.md9.1 KB
  • references/deprecated-services.md1.8 KB
  • references/governance-discovery.md4 KB
  • references/identity-resolution.md9 KB
  • references/naming-full-examples.md1.9 KB
  • references/plan-design-decisions.md5.3 KB
  • references/policy-effect-decision-tree.md2 KB
  • references/pricing-guidance.md20.3 KB
  • references/research-workflow.md4.6 KB
  • references/security-baseline-full.md5.3 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…