- Avm Tf ClassificationsUse this skill whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module / GitHub repo / Terraform Registry entry. Covers the three module classes, the criteria that separate them ("single resource only" vs "opinionated multi-resource solution" vs "shared logic"), the naming conventions per class (`avm-res-`, `avm-ptn-`, `avm-utl-`), and the corresponding GitHub repo name (`terraform-azAzure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf CodestyleUse for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf CodestyleUse for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Avm Tf ConftestUse whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory. Covers current policy identifiers, example-local exception placement, package names, and managed policy validation. Trigger on "conftest", "rego", "APRL", "AVMSEC", "policy failure", "policy exception", "deny_", and "avm check policy".Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Avm Tf ConftestUse whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory. Covers current policy identifiers, example-local exception placement, package names, and managed policy validation. Trigger on "conftest", "rego", "APRL", "AVMSEC", "policy failure", "policy exception", "deny_", and "avm check policy".Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf DocumentationUse for AVM Terraform generated README content, _header.md, _footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Avm Tf DocumentationUse for AVM Terraform generated README content, _header.md, _footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf InterfacesUse for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Avm Tf InterfacesUse for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf LifecycleUse this skill whenever an Azure Verified Module (AVM) is being proposed, approved, published, handed over to a new owner, orphaned, or deprecated — and whenever a contributor is choosing a version number for a Terraform AVM module release. Covers the four lifecycle stages (Proposed, Available, Orphaned, Deprecated), the 0.x.y pre-GA versioning rule that applies to ALL AVM modules right now, and the support obligations that come with module ownership. Trigger this skill on phrases like "propose Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf LifecycleUse this skill whenever an Azure Verified Module (AVM) is being proposed, approved, published, handed over to a new owner, orphaned, or deprecated — and whenever a contributor is choosing a version number for a Terraform AVM module release. Covers the four lifecycle stages (Proposed, Available, Orphaned, Deprecated), the 0.x.y pre-GA versioning rule that applies to ALL AVM modules right now, and the support obligations that come with module ownership. Trigger this skill on phrases like "propose Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Avm Tf MigrationUse for AVM Terraform AzureRM-to-AzAPI migrations, state preservation, moved blocks, provider state moves, submodule extraction, upgrade tests, and post-migration specification compliance.Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf MigrationUse for AVM Terraform AzureRM-to-AzAPI migrations, state preservation, moved blocks, provider state moves, submodule extraction, upgrade tests, and post-migration specification compliance.Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Avm Tf ProcessUse for the AVM Terraform contribution process from module proposal and repository setup through implementation, Avm.Authoring validation, pull request review, and release.Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Avm Tf ProcessUse for the AVM Terraform contribution process from module proposal and repository setup through implementation, Avm.Authoring validation, pull request review, and release.Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf SubmodulesUse for AVM Terraform ARM subresources implemented as local submodules, including cardinality, parent_id, resource_types, retry, timeouts, ignore_body_changes, outputs, files, and tests.Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Avm Tf SubmodulesUse for AVM Terraform ARM subresources implemented as local submodules, including cardinality, parent_id, resource_types, retry, timeouts, ignore_body_changes, outputs, files, and tests.Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf TelemetryUse this skill whenever an Azure Verified Module (AVM) for Terraform needs to wire up, debug, or explain telemetry — the `main.telemetry.tf` file with `modtm_telemetry` + `random_uuid.telemetry` + `data.azapi_client_config.telemetry` + `data.modtm_module_source.telemetry`, the `enable_telemetry` consumer-facing variable (which MUST default to `true` per SFR4), the `modtm` provider's role in shipping anonymous deployment counts to Application Insights, and the AzAPI request-header telemetry that Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Avm Tf TelemetryUse this skill whenever an Azure Verified Module (AVM) for Terraform needs to wire up, debug, or explain telemetry — the `main.telemetry.tf` file with `modtm_telemetry` + `random_uuid.telemetry` + `data.azapi_client_config.telemetry` + `data.modtm_module_source.telemetry`, the `enable_telemetry` consumer-facing variable (which MUST default to `true` per SFR4), the `modtm` provider's role in shipping anonymous deployment counts to Application Insights, and the AzAPI request-header telemetry that Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf TestingUse for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Avm Tf TestingUse for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf TflintUse whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation. Covers the current canonical avm_* rules and the Avm.Authoring override merge process. Trigger on "tflint", "lint failure", "disable rule", "ignore rule", "rule override", "avm.tflint", "severity", and any AVM TFLint rule identifier.Azure/terraform-azure-avm-ptn-alz-application-landing-zone-cicd-bootstrap-azure-devops6
- Avm Tf TflintUse whenever an AVM Terraform task involves TFLint findings, AVM rule names, rule applicability, severity, exclusions, exceptions, override files, or lint validation. Covers the current canonical avm_* rules and the Avm.Authoring override merge process. Trigger on "tflint", "lint failure", "disable rule", "ignore rule", "rule override", "avm.tflint", "severity", and any AVM TFLint rule identifier.Azure/terraform-azurerm-avm-ptn-monitoring-amba-alz6
- Build Private PackageBuild a private NuGet package for the Application Insights Profiler ASP.NET Core SDK. Use this skill when asked to build, pack, or create a private or test NuGet package for the profiler. Handles restore, build, uploader packing, and NuGet packaging.Azure/azuremonitor-opentelemetry-profiler-net6
- Bump Submodule RefBump the ServiceProfiler submodule reference in the main repo. Use this skill when asked to bump, update, or sync the ServiceProfiler submodule reference. Handles validation, commit, tagging, and push.Azure/azuremonitor-opentelemetry-profiler-net6
- Documentdb Azure DeploymentDeploy an Azure DocumentDB cluster (`Microsoft.DocumentDB/mongoClusters`) end-to-end — Bicep (primary), Azure CLI one-shot, Terraform, or portal. Covers resource-group creation, cluster parameters (tier, storage, server version, sharding, HA), firewall rule configuration, retrieving the connection string, and teardown. Use when the user asks to provision, create, deploy, or spin up an Azure DocumentDB cluster, or wants infrastructure-as-code for one.Azure/documentdb-agent-kit6
- Documentdb ConnectionOptimize MongoDB client connection configuration (pools, timeouts, patterns) for Azure DocumentDB. Use this skill when working on functions that instantiate or configure a MongoDB client (e.g., calling `connect()`), configuring connection pools, troubleshooting connection errors (ECONNREFUSED, timeouts, pool exhaustion), optimizing connection-related performance issues. Includes scenarios like building serverless functions, creating API endpoints, optimizing high-traffic applications, or debuggiAzure/documentdb-agent-kit6
- Documentdb Data ModelingData modeling patterns for Azure DocumentDB — embed vs reference, 16 MB document limit, denormalization for read-heavy workloads, schema versioning. Use when designing new schemas, reviewing existing data models, migrating from SQL, deciding between embedding and referencing, modeling one-to-one / one-to-many / many-to-many relationships, or troubleshooting document-size and query-performance problems that stem from the data model.Azure/documentdb-agent-kit6
- Documentdb DriverMongoDB driver and SDK best practices for Azure DocumentDB — singleton `MongoClient`, connection reuse, connection-pool fundamentals. Use when writing code that instantiates a MongoDB client, reviewing driver initialization, or diagnosing connection-related bugs. For full connection-pool tuning (serverless vs OLTP vs OLAP, timeouts, retries), see the `documentdb-connection` skill.Azure/documentdb-agent-kit6
- Documentdb Full Text SearchFull-text search best practices for Azure DocumentDB using the `createSearchIndexes` command and `$search` aggregation stage — BM25 keyword scoring, fuzzy search (`maxEdits`), phrase search with `slop`, custom analyzers (keyword + lowerCase + asciiFolding + edgeGram) for prefix / ID matching, `pathHierarchy` tokenizer for hierarchical IDs, multi-field search indexes, and hybrid (BM25 + vector) retrieval via Reciprocal Rank Fusion. Use when building search experiences, adding typo tolerance, matcAzure/documentdb-agent-kit6
- Documentdb High AvailabilityHigh availability, business-continuity, and disaster-recovery best practices for Azure DocumentDB — enabling in-region HA with availability zones (99.99% SLA), adding active-passive cross-region replica clusters (99.995% SLA), and understanding automatic backup retention. Use when designing production topology, planning failover, provisioning DR, picking regions, or reviewing cluster architecture.Azure/documentdb-agent-kit6
- Documentdb IndexingIndex-type selection and shape guidance for Azure DocumentDB — when to use single-field, compound (ESR), multikey, wildcard, hashed, 2dsphere, TTL, and vector indexes; query-pattern → index-shape cookbook; per-collection index budget; DocumentDB-specific preference for `textSearch` over community `$text`. Use when designing or reviewing indexes, choosing an index type for a query pattern, or deciding whether an additional index is worth the write cost.Azure/documentdb-agent-kit6
- Documentdb Local DeploymentBest practices for running Azure DocumentDB locally for development — choosing between the Gateway Docker image and the psql-only image, docker-compose setup, connection config (port 10260, TLS, SCRAM-SHA-256), env-driven configuration, sample-data management (`SKIP_INIT_DATA` / `INIT_DATA_PATH`), port bindings, and dev/prod parity via versioned seed and schema scripts. Use when setting up a new local dev environment, writing sample apps, building integration tests, or diagnosing local connectioAzure/documentdb-agent-kit6
- Documentdb Mcp SetupGuide users through installing and configuring the DocumentDB MCP server for Azure DocumentDB. Use this skill when a user wants to wire the DocumentDB MCP server into an agentic client (Claude Code, Claude Desktop, Cursor, Copilot CLI, Gemini CLI, VS Code) and define a `CONNECTION_PROFILES` entry, or when they hit MCP connection / auth / profile errors.Azure/documentdb-agent-kit6
- Documentdb MonitoringMonitoring and diagnostics best practices for Azure DocumentDB — enabling diagnostic settings and slow-query logs, analyzing them in Log Analytics, and alerting on CPU / memory / IOPS / storage / connection saturation per cluster tier. Use when setting up observability on a new cluster, investigating production incidents, or tuning alert thresholds.Azure/documentdb-agent-kit6
- Documentdb Natural Language QueryingGenerate read-only DocumentDB/MongoDB queries (find) or aggregation pipelines using natural language, with collection schema context and sample documents. Use this skill whenever the user asks to write, create, or generate queries for Azure DocumentDB, wants to filter/query/aggregate data, asks "how do I query...", needs help with query syntax, or discusses finding/filtering/grouping documents. Also use for translating SQL-like requests to MongoDB syntax. Does NOT analyze or optimize existing quAzure/documentdb-agent-kit6
- Documentdb Query OptimizationQuery and aggregation-pipeline optimization rules for Azure DocumentDB — using `explain("executionStats")` to verify index usage and avoid `COLLSCAN`. Use when reviewing a specific query, diagnosing a slow query, or validating that an index is actually being used. For full index-design workflow, see the `documentdb-query-optimizer` skill.Azure/documentdb-agent-kit6
- Documentdb Query OptimizerHelp with DocumentDB/MongoDB query optimization and indexing for Azure DocumentDB. Use only when the user asks for optimization or performance: "How do I optimize this query?", "How do I index this?", "Why is this query slow?", "Can you fix my slow queries?", etc. Do not invoke for general query writing unless user asks for performance or index help. Prefer indexing as optimization strategy. Use DocumentDB MCP when available.Azure/documentdb-agent-kit6
- Documentdb SecuritySecurity best practices for Azure DocumentDB — TLS enforcement, Private Endpoint / firewall configuration, Microsoft Entra ID + RBAC for authentication, and customer-managed keys (CMK) for encryption at rest. Use when reviewing production security posture, configuring networking, setting up authentication / authorization, or preparing for compliance audits.Azure/documentdb-agent-kit6
- Documentdb ShardingHorizontal sharding (partitioning) for Azure DocumentDB collections — when to shard vs stay single-shard, how to pick a shard key for read-heavy vs write-heavy workloads, the logical/physical shard mental model, scaling out vs scaling up, hot-partition diagnosis, and the `sh.shardCollection` / `sh.reshardCollection` commands. Use when deciding whether to shard a collection, choosing or changing a shard key, sizing a cluster, or troubleshooting uneven storage / throughput across physical shards.Azure/documentdb-agent-kit6
- Documentdb StorageStorage configuration guidance for Azure DocumentDB — when and how to use Premium SSD v2 high-performance storage, IOPS/bandwidth caps that are gated by compute tier (not disk size), Premium SSD v2 limitations (no CMK, migration paths, disk-hydration sequencing), and storage capacity change limits. Use when picking a storage type at cluster creation, sizing for I/O-intensive workloads, migrating from Premium SSD to Premium SSD v2, or sequencing compute/storage/HA changes on a Premium SSD v2 clusAzure/documentdb-agent-kit6
- Documentdb Vector SearchVector search best practices for Azure DocumentDB using `cosmosSearch` — choosing between DiskANN / HNSW / IVF, creating indexes, tuning `lBuild` / `lSearch` / `maxDegree`, Product Quantization (up to 16,000 dims), half-precision (fp16) indexing, and normalizing embeddings for cosine similarity. Use when building RAG / semantic-search applications, creating a vector index, tuning recall/latency, or reducing vector-index memory footprint.Azure/documentdb-agent-kit6
- Go Provider ReleaseRelease the Azure App Configuration Go Provider. Use when: releasing a new version, bumping version, tagging a release, publishing to Go proxy, creating release PRs.Azure/AppConfiguration-GoProvider6
- Aks Automatic ReadinessAssess Kubernetes workloads and cluster configuration for AKS Automatic compatibility. Identifies incompatibilities, generates fixes, and guides migration from AKS Standard to AKS Automatic. WHEN: migrate to AKS Automatic, check AKS Automatic readiness, validate manifests for Automatic, assess cluster for Automatic compatibility, fix deployment for Automatic compatibility, identify AKS Automatic migration blockers, is my cluster ready for AKS Automatic. DO NOT USE FOR: creating a brand-new clustAzure/AKS-Skills5
- Aks Cluster SetupMake the AKS-specific design decisions for a new production Azure Kubernetes Service (AKS) cluster — SKU (Automatic vs Standard), pod IP model (Azure CNI Overlay vs kubenet), API-server access, egress, identity, upgrades, node pools, and reliability — then delegate the actual provisioning to the Azure Skills deployment engine. WHEN: create AKS cluster, provision AKS environment, design AKS networking, choose AKS SKU, Day-0 AKS checklist, plan a production AKS cluster. DO NOT USE FOR: debugging aAzure/AKS-Skills5
- Aks Cost OptimizationReduce Azure Kubernetes Service (AKS) spending: pod rightsizing, VPA-driven recommendations, cluster-autoscaler tuning, spot node pools, namespace-level cost visibility, and cost-anomaly detection. WHEN: rightsize pods, VPA recommendations, idle nodes, scale-down, autoscaler profile, spot nodes, cheaper compute, cost add-on, namespace cost breakdown, spending anomaly, 'my AKS bill is too high', 'is my app consuming what it requests', resource requests vs actual usage, over-provisioned workloads,Azure/AKS-Skills5
- Aks Gpu InferenceDay-2 operations for GPU and model-inference workloads on Azure Kubernetes Service (AKS): diagnose GPU pods stuck Pending, missing nvidia.com/gpu, CUDA/driver mismatches, model OOM on weight load, GPU vCPU-quota failures, KAITO (AI toolchain operator) Workspaces stuck not-ready, and GPU cost / scale-to-zero / spot eviction. WHEN: GPU pod Pending 'Insufficient nvidia.com/gpu', no nvidia.com/gpu on node, CUDA driver version insufficient, model OOMKilled loading weights, GPU node pool quota exceedeAzure/AKS-Skills5
- Aks Known IssuesMatch exact AKS operation-failure signatures to documented causes and fixes. WHEN: an AKS create, scale, upgrade, node-image, or image-pull failure names VMCannotFitEphemeralOSDisk, LinkedAuthorizationFailed, NodePoolMcVersionIncompatible, 'NodeImageVersion is not accepted', SkuNotAvailable, ZonalAllocationFailed, OverconstrainedAllocationRequest, or an AKS vmssCSE/CSE nested signature: VMExtensionError_OutboundConnFail (exit 50), VMExtensionError_K8SAPIServerConnFail (exit 51), or VMExtensionErAzure/AKS-Skills5
- Aks Network CapturePacket-level network evidence for AKS: run a bounded, distributed packet capture across nodes (filtered by IP, port, or tcpdump/BPF expression), and collect Azure network resources (NSG rules, route tables, firewall, VNET peering) when you need pcap-level proof of where traffic drops. Escalation tool for when logs and read-only checks are inconclusive. WHEN: capture packets on a node, take a pcap, tcpdump on AKS, prove where a packet is dropped, verify an NSG or route is blocking traffic at the Azure/AKS-Skills5
- Aks TroubleshootingDebug and root-cause live Azure Kubernetes Service (AKS) incidents with a read-only, evidence-first investigation and structured report. WHEN: pod crashes or Pending, CrashLoopBackOff, OOMKilled, ImagePullBackOff, node NotReady, DNS failure, ingress 502/503, connectivity timeout, network policy, SNAT exhaustion, upgrade stuck, cordon/drain failure, spot or zone disruption, expired certificate, or 'investigate my AKS cluster'. DO NOT USE FOR: packet capture (use aks-network-capture); GPU or modelAzure/AKS-Skills5
- Avm Tf AzapiUse for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and ignore_body_changes.Azure/terraform-azurerm-avm-ptn-avd-lza-insights5
- Avm Tf ClassificationsUse this skill whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module / GitHub repo / Terraform Registry entry. Covers the three module classes, the criteria that separate them ("single resource only" vs "opinionated multi-resource solution" vs "shared logic"), the naming conventions per class (`avm-res-`, `avm-ptn-`, `avm-utl-`), and the corresponding GitHub repo name (`terraform-azAzure/terraform-azurerm-avm-ptn-avd-lza-insights5
- Avm Tf CodestyleUse for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.Azure/terraform-azurerm-avm-ptn-avd-lza-insights5
- Avm Tf ConftestUse whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory. Covers current policy identifiers, example-local exception placement, package names, and managed policy validation. Trigger on "conftest", "rego", "APRL", "AVMSEC", "policy failure", "policy exception", "deny_", and "avm check policy".Azure/terraform-azurerm-avm-ptn-avd-lza-insights5
- Avm Tf DocumentationUse for AVM Terraform generated README content, _header.md, _footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.Azure/terraform-azurerm-avm-ptn-avd-lza-insights5
- Avm Tf InterfacesUse for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.Azure/terraform-azurerm-avm-ptn-avd-lza-insights5
- Avm Tf LifecycleUse this skill whenever an Azure Verified Module (AVM) is being proposed, approved, published, handed over to a new owner, orphaned, or deprecated — and whenever a contributor is choosing a version number for a Terraform AVM module release. Covers the four lifecycle stages (Proposed, Available, Orphaned, Deprecated), the 0.x.y pre-GA versioning rule that applies to ALL AVM modules right now, and the support obligations that come with module ownership. Trigger this skill on phrases like "propose Azure/terraform-azurerm-avm-ptn-avd-lza-insights5
- Avm Tf MigrationUse for AVM Terraform AzureRM-to-AzAPI migrations, state preservation, moved blocks, provider state moves, submodule extraction, upgrade tests, and post-migration specification compliance.Azure/terraform-azurerm-avm-ptn-avd-lza-insights5
- Avm Tf ProcessUse for the AVM Terraform contribution process from module proposal and repository setup through implementation, Avm.Authoring validation, pull request review, and release.Azure/terraform-azurerm-avm-ptn-avd-lza-insights5
- Avm Tf SubmodulesUse for AVM Terraform ARM subresources implemented as local submodules, including cardinality, parent_id, resource_types, retry, timeouts, ignore_body_changes, outputs, files, and tests.Azure/terraform-azurerm-avm-ptn-avd-lza-insights5