Official agent skill

Sdaf Control Plane Bootstrap

by Azure in Azure/sap-automation

Deploy the SDAF control plane locally: prepare DEPLOYER and LIBRARY tfvars, review the plan, run deploycontrolplane.sh per docs/local/03-00-control-plane.md § Run, and validate the deployer +…

OfficialMITAuto-check passedDevOps & Cloud

Install Sdaf Control Plane Bootstrap

skills CLI
$ npx skills add Azure/sap-automation --skill sdaf-control-plane-bootstrap -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/sap-automation sdaf-control-plane-bootstrap --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sdaf-control-plane-bootstrap .claude/skills/sdaf-control-plane-bootstrap && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sdaf-control-plane-bootstrap
GitHub stars
145
Token cost
~1.3k tokens
SKILL.md length
390 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Deploy the SDAF control plane locally: prepare DEPLOYER and LIBRARY tfvars, review the plan, run deploycontrolplane.sh per docs/local/03-00-control-plane.md § Run, and validate the deployer +…

  • Works in 5 steps: Review the tfvars → Confirm the review gate → Run the documented control-plane deploy → …
  • A user says deploy the SDAF control plane
  • SKILL.md covers When to invoke, Preconditions (documented gates), Recipe and If the run fails, plus 2 more sections
  • Calls terraform

What it does

Sdaf Control Plane Bootstrap is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Deploy the SDAF control plane locally: prepare DEPLOYER and LIBRARY tfvars, review the plan, run deploycontrolplane.sh per docs/local/03-00-control-plane.md § Run, and validate the deployer + library + state hand-off. Grounded in docs/local/03-00-control-plane.md. Use when a user says "deploy the SDAF control plane", "run deploycontrolplane.sh", "bootstrap SDAF from an empty subscription", "install the deployer" or "create the SAP library". Do NOT use for workload zone (see sdaf-workload-zone), SAP system (see…

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Microsoft Azure. The repository describes itself as: This is the repository supporting the SAP deployment automation framework on Azure. The licence is MIT.

When your agent uses it

  • A user says deploy the SDAF control plane
  • Run deploycontrolplane.sh
  • Bootstrap SDAF from an empty subscription
  • Install the deployer

Example prompts

  • “deploy the SDAF control plane”
  • “run deploycontrolplane.sh”
  • “bootstrap SDAF from an empty subscription”
  • “/sdaf-control-plane-bootstrap”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): shell

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Review the tfvars
  2. Confirm the review gate
  3. Run the documented control-plane deploy
  4. Do not update SDAF between plan and apply
  5. Validate

What it can do on your machine

Read from SKILL.md and the folder at commit 78835f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • shell

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sdaf Control Plane Bootstrap loads about 1.3k tokens when it runs. Until then it costs about 168 tokens; SKILL.md has 390 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~168
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/sap-automation at commit 78835f0, republished under its MIT licence (© Azure). 390 words, ~1,261 tokens.

Download SKILL.mdSave it as .claude/skills/sdaf-control-plane-bootstrap/SKILL.md (or your agent's skills folder).
name
sdaf-control-plane-bootstrap
description
Deploy the SDAF control plane locally: prepare DEPLOYER and LIBRARY tfvars, review the plan, run `deploy_controlplane.sh` per `docs/local/03-00-control-plane.md § Run`, and validate the deployer + library + state hand-off. Grounded in `docs/local/03-00-control-plane.md`. Use when a user says "deploy the SDAF control plane", "run deploy_controlplane.sh", "bootstrap SDAF from an empty subscription", "install the deployer" or "create the SAP library". Do NOT use for workload zone (see sdaf-workload-zone), SAP system (see sdaf-sap-system), removal (`sdaf-safe-removal`), or Azure Government / sovereign-cloud deltas (`sdaf-sovereign-cloud`).
allowed-tools
shell
license
MIT

SDAF Control Plane Bootstrap

Action-loop skill. Deploys the control plane strictly per docs/local/03-00-control-plane.md for local execution. On ADO / GitHub surfaces, defer stage mechanics to the surface bootstrap plugin — this skill covers the shared control-plane semantics.

When to invoke

Trigger on: "deploy the SDAF control plane", "run deploy_controlplane.sh", "install the deployer", "create the SAP library", "bootstrap SDAF from empty".

Do NOT trigger on: workload zone, SAP system, software download, install, removal, or state repair.

Preconditions (documented gates)

  • sdaf-readiness-check has passed (docs/local/02-00-prepare-execution-environment.md § Readiness verification; docs/local/03-00-control-plane.md § Before you begin).
  • Control-plane config files (DEPLOYER + LIBRARY tfvars) are prepared under the documented WORKSPACES layout — see sdaf-workspace-and-tfvars (§ Configuration preparation, § Inputs).
  • The three required env vars are set (docs/local/troubleshooting.md § A required export is missing): SAP_AUTOMATION_REPO_PATH, CONFIG_REPO_PATH, ARM_SUBSCRIPTION_ID.

Recipe

Step 1 — Review the tfvars

Re-read the DEPLOYER and LIBRARY tfvars once (docs/local/03-00-control-plane.md § Review before execution). Confirm naming matches docs/region-codes.md § Where the region code appears.

Step 2 — Confirm the review gate

Docs require an explicit review before every state-changing step (docs/local/03-00-control-plane.md § Review before execution; § Run).

Step 3 — Run the documented control-plane deploy

From CONFIG_REPO_PATH, exactly per docs/local/03-00-control-plane.md § Run:

bash
set -e
cd "$CONFIG_REPO_PATH/WORKSPACES"
"$SAP_AUTOMATION_REPO_PATH/deploy/scripts/deploy_controlplane.sh" \
    --deployer_parameter_file \
    "$CONFIG_REPO_PATH/WORKSPACES/DEPLOYER/<CONTROL_PLANE>-INFRASTRUCTURE/<CONTROL_PLANE>-INFRASTRUCTURE.tfvars" \
    --library_parameter_file \
    "$CONFIG_REPO_PATH/WORKSPACES/LIBRARY/<ENVIRONMENT>-<LOCATION>-SAP_LIBRARY/<ENVIRONMENT>-<LOCATION>-SAP_LIBRARY.tfvars" \
    --subscription "$ARM_SUBSCRIPTION_ID" || {
  rc=$?
  echo "control-plane exit=$rc — route to sdaf-failure-triage"
  exit "$rc"
}

Do not claim success unless the exit code is 0 AND the validation checks in Step 5 pass. Treat exit 2 as a validation-gate failure that must not be silenced.

Step 4 — Do not update SDAF between plan and apply

docs/local/01-00-prerequisites.md § Pin versions.

Show full SKILL.md (168 more words)Show less
Step 5 — Validate

docs/local/03-00-control-plane.md § Validate and § Outcome:

  • Deployer + library deployed.
  • Terraform state migrated to the library storage account (tfstate container) — see § What the automation does.
  • .sap_deployment_automation metadata populated (§ What the automation does, § Validate).
  • Summary written (§ Outcome).

If the run fails

Route to sdaf-failure-triage. It walks docs/local/troubleshooting.md and hands back the specific documented anchor. Stage-owned preventive checks (that belong here rather than in triage):

  • Filename / directory / basename mismatch — fix before rerun (docs/local/troubleshooting.md § A parameter file is not found).
  • Interrupted control-plane rerun with --recover — do so only after the state agrees (docs/local/troubleshooting.md § A control-plane run stopped partway through).

Hard rules

  • Documented behaviour only (D19). If a knob is not in the shipped docs or the script's own --help, do not describe it.
  • Do not pass --auto-approve for reviewed local deployment (docs/local/03-00-control-plane.md § Review before execution).
  • Do not --force casually (docs/local/03-00-control-plane.md § Safe retry).
  • Repo-wide rules apply: do not run terraform fmt and follow the Terraform / Ansible / Python guidance in .github/copilot-instructions.md.

See also

  • sdaf-workspace-and-tfvars, sdaf-readiness-check, sdaf-workload-zone, sdaf-sap-system, sdaf-safe-removal, sdaf-sovereign-cloud, sdaf-failure-triage.
  • docs/local/03-00-control-plane.md, docs/local/troubleshooting.md, .github/copilot-instructions.md.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sdaf-control-plane-bootstrap of Azure/sap-automation.

Open the folder on GitHubat commit 78835f0

Compare with similar skills

Sdaf Control Plane Bootstrap next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sdaf Control Plane Bootstrap compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sdaf Control Plane Bootstrap this skillAzure/sap-automation145—~1.3kAutomated safety check: PassMIT
Azure Diagnosticsmicrosoft/azure-skills1.5k1 repos~1.6kAutomated safety check: PassMIT
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Thesvgglincker/thesvg2.8k—~1.5kAutomated safety check: PassMIT
Azure PricingAzure/Copilot-Studio-and-Azure1103 repos~2.4kAutomated safety check: PassMIT

Similar skills

  • Azure Diagnostics

    microsoft/azure-skills

    Official

    Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage.

    1.5k GitHub starsUsed in 1 repo~1.6k tokens
    DevOps & CloudAuto-check passed
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Azure Pricing

    Azure/Copilot-Studio-and-Azure

    Official

    Fetches real-time Azure retail pricing using the Azure Retail Prices API (prices.azure.com) and estimates Copilot Studio agent credit consumption.

    110 GitHub starsUsed in 3 repos~2.4k tokens
    DevOps & CloudAuto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed

More from Azure/sap-automation

All 19 skills in this repo
  • Sdaf Bom Selection

    Azure/sap-automation

    Official

    Pick the right SDAF BOM for a target SAP product / release / DB platform / version / kernel / topology.

    145 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Orientation And Surface

    Azure/sap-automation

    Official

    Orient a newcomer to the SAP Deployment Automation Framework (SDAF): explain the spine (control plane → workload zone → SAP system → software → install → operate/remove), summarise the three…

    145 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Quality Assurance

    Azure/sap-automation

    Official

    Validate a deployed SDAF SAP system through the SDAF-owned QA entry points: the local quality-assurance menu and the documented Azure DevOps pipeline 13 path.

    145 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Sap Installation

    Azure/sap-automation

    Official

    Guide SDAF operating-system, database, and SAP installation after the SAP-system workspace and reviewed media are ready.

    145 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Sovereign Cloud

    Azure/sap-automation

    Official

    Explain the current SDAF sovereign-cloud deltas without inventing a generic "all sovereigns" runbook.

    145 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Sdaf State Management

    Azure/sap-automation

    Official

    Inspect and repair SDAF Terraform state safely before any reviewed import/remove.

    145 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Sdaf Control Plane Bootstrap

What does Sdaf Control Plane Bootstrap do?

Deploy the SDAF control plane locally: prepare DEPLOYER and LIBRARY tfvars, review the plan, run deploycontrolplane.sh per docs/local/03-00-control-plane.md § Run, and validate the deployer +…. Sdaf Control Plane Bootstrap is an agent skill from Azure/sap-automation, published by the product's own GitHub organization.md § Run, and validate the deployer + library + state hand-off.

When should I use Sdaf Control Plane Bootstrap?

Sdaf Control Plane Bootstrap fits situations like: A user says deploy the SDAF control plane; run deploycontrolplane.sh; bootstrap SDAF from an empty subscription; install the deployer.

How do I install Sdaf Control Plane Bootstrap in Claude Code?

Run `npx skills add Azure/sap-automation --skill sdaf-control-plane-bootstrap -a claude-code`. Or copy the skill folder (skills/sdaf-control-plane-bootstrap in Azure/sap-automation) into .claude/skills/sdaf-control-plane-bootstrap in your project. Claude Code loads it when a task matches its description.

How do I install Sdaf Control Plane Bootstrap in Codex?

Run `npx skills add Azure/sap-automation --skill sdaf-control-plane-bootstrap -a codex`. Or copy the skill folder (skills/sdaf-control-plane-bootstrap in Azure/sap-automation) into .agents/skills/sdaf-control-plane-bootstrap in your project. Codex loads it when a task matches its description.

Can I use Sdaf Control Plane Bootstrap in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/sap-automation --skill sdaf-control-plane-bootstrap -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sdaf-control-plane-bootstrap, .gemini/skills/sdaf-control-plane-bootstrap, .github/skills/sdaf-control-plane-bootstrap and .opencode/skills/sdaf-control-plane-bootstrap in your project.

What does Sdaf Control Plane Bootstrap need to run?

Going by SKILL.md and its folder, Sdaf Control Plane Bootstrap needs the command-line tools its instructions call (terraform). Our summary lists: Python 3. Its frontmatter pre-approves these tools: shell.

Does Sdaf Control Plane Bootstrap access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sdaf Control Plane Bootstrap safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sdaf Control Plane Bootstrap use?

Sdaf Control Plane Bootstrap is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sdaf Control Plane Bootstrap use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sdaf Control Plane Bootstrap?

Skills that share tags, products or a category with Sdaf Control Plane Bootstrap: Azure Diagnostics (microsoft/azure-skills, 1.5k stars), Cloud Cost Optimization (wshobson/agents, 40k stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars) and Thesvg (glincker/thesvg, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sdaf Control Plane Bootstrap?

Azure (a GitHub organization, an official publisher) maintains it in Azure/sap-automation, which has 145 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.

Source: Azure/sap-automation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.