Skip to content
Back to skills

Azure Enterprise Infra Planner

ASecurity

Architect and provision enterprise Azure infrastructure from workload descriptions for cloud architects and platform engineers, covering networking, identity, security, compliance, and multi-resource topologies with Well-Architected alignment, and generating Bicep or Terraform directly without azd. Use when the user asks to plan Azure infrastructure, architect a landing zone, design a hub-spoke network, plan a multi-region disaster recovery topology, set up virtual networks, firewalls, and pr...

  • 2 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 4, 2026
ai-agentsazureterraformgitapisecuritydocumentation

Works with

  • cli
  • api
  • mcp

Security analysis

A100/100

Pro scans all 20 files and shows the line behind each finding

Scanned September 4, 2026

npx -y skills add paulasilvatech/awesome-harness-primitives --skill azure-enterprise-infra-planner --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Azure Enterprise Infra Planner?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Azure Enterprise Infra Planner
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/paulasilvatech-azure-enterprise-infra-planner/badge)](https://www.skillsdirectory.com/skills/paulasilvatech-azure-enterprise-infra-planner)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: azure-enterprise-infra-planner
description: >-
  Architect and provision enterprise Azure infrastructure from workload descriptions for cloud
  architects and platform engineers, covering networking, identity, security, compliance, and
  multi-resource topologies with Well-Architected alignment, and generating Bicep or Terraform
  directly without azd. Use when the user asks to plan Azure infrastructure, architect a landing
  zone, design a hub-spoke network, plan a multi-region disaster recovery topology, set up virtual
  networks, firewalls, and private endpoints, run a subscription-scope Bicep deployment, or
  configure Azure Backup for VM workloads.
license: MIT
metadata:
  author: Microsoft
  version: 1.4.1
---

<!-- Generated from harness/github-copilot/plugins/azure-cloud-development/skills/azure-enterprise-infra-planner/SKILL.md by harness/claude-code/scripts/convert_from_copilot.py. Edit the source, not this file. -->

# Azure Enterprise Infra Planner

## When to invoke

Activate this skill when user wants to:
- Plan enterprise Azure infrastructure from a workload or architecture description
- Architect a landing zone, hub-spoke network, or multi-region topology
- Design networking infrastructure: VNets, subnets, firewalls, private endpoints, VPN gateways
- Plan identity, RBAC, and compliance-driven infrastructure
- Generate Bicep or Terraform for subscription-scope or multi-resource-group deployments
- Plan disaster recovery, failover, or cross-region high-availability topologies

## Quick Reference

| Property | Details |
|---|---|
| MCP tools | `insights_get`, `get_azure_bestpractices_get`, `wellarchitectedframework_serviceguide_get`, `microsoft_docs_fetch`, `microsoft_docs_search`, `bicepschema_get` |
| CLI commands | `az deployment group create`, `az bicep build`, `az resource list`, `terraform init`, `terraform plan`, `terraform validate`, `terraform apply`, `checkov` |
| Output schema | [schema.md](references/schema.md) |
| Key references | [workflow.md](references/workflow.md), [waf-checklist.md](references/waf-checklist.md), [resources/](references/resources/README.md), [constraints/](references/constraints/README.md) |

## Workflow (Start Here)

Follow the step-by-step instructions in [workflow.md](references/workflow.md) to execute the 7 phases of infrastructure planning and provisioning.

## Architecture

The skill runs a **7-phase, gated pipeline**. Input is triaged into one of two flows:

- **Greenfield** — only new requirements; run the phases straight through.
- **Referenced (brownfield)** — the user supplies something that already exists (a live resource /
  resource group / subscription, IaC or an infra plan, or a requirements doc). The same phases run, plus
  [referenced-workload.md](references/referenced-workload.md): existing resources are inventoried and
  referenced (never recreated), the new workload is wired into them, and **Phase 7 deploys additively**
  (incremental only — never modifying or destroying the referenced resources).

Every phase advances only after its gate passes. Phase 5 requires explicit user approval; **Phase 6 is a
hardened, self-verifying gate** — the generated IaC must be secure-by-default, pass local validation
(`az bicep build` / `terraform validate`) with zero errors, pass a `checkov` security scan with no
unresolved high/critical findings, and the skill must **show the command output** and emit a completion
self-check before advancing; Phase 7 requires an explicit, risk-acknowledged deploy confirmation.

```mermaid
flowchart TD
    IN([Input]) --> TRIAGE{Existing infra<br/>referenced?}
    TRIAGE -- "No (greenfield)" --> P1
    TRIAGE -- "Yes (referenced)" --> RW[/referenced-workload.md:<br/>inventory + assign roles<br/>reference, never recreate/]
    RW --> P1

    subgraph PIPE [7-phase gated pipeline]
        direction TB
        P1[Phase 1 · Extract insights] --> P2[Phase 2 · Research best practices]
        P2 --> P3[Phase 3 · Research resources]
        P3 --> P4[Phase 4 · Generate plan]
        P4 --> P5{Phase 5 · Verify<br/>user approves?}
        P5 -- "no" --> P4
        P5 -- "approved" --> P6[Phase 6 · Generate IaC]
        P6 --> VAL{Validate<br/>az bicep build /<br/>terraform validate}
        VAL -- "errors" --> P6
        VAL -- "clean" --> P7{Phase 7 · Deploy<br/>risk-ack confirm?}
    end

    P7 -- "greenfield" --> DEP[az deployment / terraform apply]
    P7 -- "referenced" --> DEPADD[Additive deploy · incremental only<br/>what-if preview · no destroy of<br/>referenced resources]
    DEP --> OUT([Deployed])
    DEPADD --> OUT

    classDef gate fill:#fff3cd,stroke:#d39e00,color:#000;
    classDef ref fill:#e2f0d9,stroke:#548235,color:#000;
    class P5,VAL,P7,TRIAGE gate;
    class RW,DEPADD ref;
```

**Artifacts** (written under `<project-root>/`): `.azure/insights.json` (Phase 1),
`.azure/infrastructure-plan.json` (Phase 4, status `draft`→`approved`→`deployed`), and
`infra/main.bicep` + `infra/modules/*` or `infra/main.tf` + `infra/modules/**` (Phase 6).

## MCP Tools

| Tool | Purpose |
|------|---------|
| `insights_get` | Retrieve insights about the user's existing Azure environment to guide planning decisions |
| `get_azure_bestpractices_get` | Azure best practices for code generation, operations, and deployment |
| `wellarchitectedframework_serviceguide_get` | WAF service guide for a specific Azure service |
| `microsoft_docs_search` | Search Microsoft Learn for relevant documentation chunks |
| `microsoft_docs_fetch` | Fetch full content of a Microsoft Learn page by URL |
| `bicepschema_get` | Bicep schema definition for any Azure resource type (latest API version) |

## Error Handling

| Error | Cause | Fix |
|---|---|---|
| MCP tool error or not available | Tool call timeout, connection error, or tool doesn't exist | Retry once; fall back to reference files and notify user if unresolved |
| Plan approval missing | `meta.status` is not `approved` | Stop and prompt user for approval before IaC generation or deployment |
| IaC validation failure | `az bicep build` or `terraform validate` returns errors | Fix the generated code and re-validate; notify user if unresolved |
| Pairing constraint violation | Incompatible SKU or resource combination | Fix in plan before proceeding to IaC generation |
| Infra plan or IaC files not found | Files written to wrong location or not created | Verify files exist at `<project-root>/.azure/` and `<project-root>/infra/`; if missing, re-create the files by following [workflow.md](references/workflow.md) exactly |

## Output template

```markdown
## Infrastructure plan result

**Status:** planned | generated | blocked
**Summary:** <one sentence covering scope and outcome>

### Details
Topology, identity and network design, and generated Bicep or Terraform.

### Validation
- <check performed>: <result and evidence>
```

## Quality gate

- [ ] The design states its Well-Architected trade-offs.
- [ ] Generated infrastructure code passes a lint or validation pass.
- [ ] The output follows `## Output template` exactly.
- [ ] Every reported check was performed and its evidence is shown.
- [ ] Irreversible Azure actions were confirmed with the user first.

Files in this skill

  • SKILL.md7.1 KB
  • references/bicep-generation.md5.1 KB
  • references/constraints/README.md1.2 KB
  • references/constraints/ai-ml.md3.2 KB
  • references/constraints/compute-apps.md7.8 KB
  • references/constraints/compute-infra.md4.5 KB
  • references/constraints/data-analytics.md6.3 KB
  • references/constraints/data-relational.md4.9 KB
  • references/constraints/messaging.md2.5 KB
  • references/constraints/monitoring.md1.7 KB
  • references/constraints/networking-connectivity.md6.1 KB
  • references/constraints/networking-core.md7 KB
  • references/constraints/networking-traffic.md4.6 KB
  • references/constraints/security.md2.4 KB
  • references/deployment.md3.7 KB
  • references/pairing-checks.md3.7 KB
  • references/phases/1-extract-insights.md2.6 KB
  • references/phases/2-research-best-practices.md2.8 KB
  • references/phases/3-research-resources.md3.3 KB
  • references/phases/4-generate-plan.md792 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…