{
 "id": "azure-admin",
 "kind": "skill",
 "name": "Azure administration",
 "description": "Inspect and manage Azure: subscriptions, resource groups, networking, AKS, storage, SQL Managed Instance, Entra ID and RBAC, preferably through Terraform.",
 "version": "1.0.0",
 "author": "Hexa Hub",
 "files": {
  "SKILL.md": "---\nname: azure-admin\ndescription: Inspect and manage Azure: subscriptions, resource groups, networking, AKS, storage, SQL Managed Instance, Entra ID and RBAC, preferably through Terraform.\ntitle: Azure administration\nicon: tabler:brand-azure\ncategory: Cloud\ntriggers: azure, az cli, subscription, resource group, aks, entra, rbac, role assignment, key vault, storage account, managed instance, tenant, arm, bicep, log analytics\nmarkers: az\nrecipes: az.account-show, az.list, az.show, help.az, terraform.plan\nrelated: terraform, kubernetes-helm, sql-server-liquibase\n---\n\n# Azure administration\n\n## Always start here\n1. `az.account-show`: which tenant and **subscription** are active. Tell the user and continue only if it is the intended one. Production subscriptions: read only.\n2. Look before you change: `az.list` (group: `group`, `vm`, `aks`, `storage` + subgroup `account`, `sql` + subgroup `mi`, `network` + subgroup `vnet`, `keyvault`, ...) and `az.show` for one resource.\n3. Unsure how a command works for the installed CLI version? `help.az` with the group and command (for example group `sql`, command `mi`).\n\nExample: `run_recipe {\"recipe\":\"az.list\",\"args\":{\"group\":\"aks\",\"resource_group\":\"rg-shop-test\"}}`\n\n## Changes go through code\nCreate and change Azure resources with Terraform (the `terraform` skill), reviewed with `terraform.plan`, not with ad-hoc `az ... create/delete/update` commands: the code is the record of what exists. If the user wants a one-off change, tell them the exact `az` command and explain what it does and whether it can be undone; do not run mutating Azure commands yourself.\n\n## Reading the picture\n- **Resource groups** hold related resources and are the usual deletion and permission boundary. Names and tags show owner and environment.\n- **Networking:** a VNet has subnets; NSGs filter traffic by priority (lowest number first); private endpoints and DNS zones (`privatelink...`) are the usual cause of \"cannot connect\" to PaaS services from inside the network.\n- **AKS:** cluster, node pools (system and user), managed identity; use the `kubernetes-helm` skill for what runs inside. Credentials come from `az aks get-credentials` (the user runs it).\n- **Storage accounts:** public access, firewall rules and shared-key access are the settings to check first; prefer Entra ID authentication.\n- **SQL Managed Instance:** lives in its own subnet with a route table and NSG that Azure manages; connectivity problems are almost always networking or DNS. Use the `sql-server-liquibase` skill for queries.\n\n## Identity and access (Entra ID, RBAC)\n- Azure RBAC role assignments are scope + role + principal. To answer \"who can do what\": list role assignments at the scope (`az role assignment list --scope ...` is read only; ask the user to run it if no recipe covers it) and explain inherited assignments from management group, subscription and resource group.\n- Least privilege: use the narrowest built-in role at the narrowest scope; managed identities instead of service-principal secrets; no `Owner`/`Contributor` at subscription level for apps.\n- Never create, rotate or print secrets, keys or tokens. Key Vault values are read by the application's identity, not copied into code.\n\n## Costs and cleanup\nFor cost questions, list resources and sizes first (`az.list`, `az.show`) and reason from SKU, size and count; say that real spend is in Cost Management and that you only have the configuration. Never delete resources. Say what looks unused and let the user decide.\n\n## Report\nSay which subscription you looked at, what you found, and what you did not or could not check.\n"
 }
}
