Official agent skill

Sdaf Safe Removal

by Azure in Azure/sap-automation

Remove SDAF resources safely in reverse dependency order: stop SAP/database services, back up data and state evidence, remove SAP systems before the workload zone, remove workload zones before the…

OfficialMITAuto-check passedFrontend & Design

Install Sdaf Safe Removal

skills CLI
$ npx skills add Azure/sap-automation --skill sdaf-safe-removal -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/sap-automation sdaf-safe-removal --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sdaf-safe-removal .claude/skills/sdaf-safe-removal && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sdaf-safe-removal
GitHub stars
146
Token cost
~2k tokens
SKILL.md length
691 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Remove SDAF resources safely in reverse dependency order: stop SAP/database services, back up data and state evidence, remove SAP systems before the workload zone, remove workload zones before the…

  • Works in 4 steps: Remove each SAP system. → Remove workload-zone resources only… → Remove the control plane only after… → …
  • A user asks to remove an SAP system
  • SKILL.md covers When to invoke, Preconditions, Reverse-order guard and Run one approved removal stage…, plus 4 more sections
  • Calls az; needs DEPLOYER_STATE_KEY and LANDSCAPE_STATE_KEY

What it does

Sdaf Safe Removal is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Remove SDAF resources safely in reverse dependency order: stop SAP/database services, back up data and state evidence, remove SAP systems before the workload zone, remove workload zones before the control plane, and validate incomplete teardown before any retry or ARM fallback. Grounded in docs/local/07-00-operations.md, docs/local/troubleshooting.md, deploy/scripts/remover.sh, deploy/scripts/removecontrolplane.sh, and the Azure DevOps ARM-fallback pipeline. Use when a user asks to remove an SAP system, workload…

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Frontend & Design, covering State management. It works with Azure DevOps. The repository describes itself as: This is the repository supporting the SAP deployment automation framework on Azure. The licence is MIT.

When your agent uses it

  • A user asks to remove an SAP system
  • Removecontrolplane.sh
  • Explain why a control-plane removal exited 0 while the deployer still exists
  • Explicit state list / import / remove operations (see sdaf-state-management)

Example prompts

  • “/sdaf-safe-removal”

Requirements

  • A credential in DEPLOYER_STATE_KEY
  • A credential in LANDSCAPE_STATE_KEY
  • Pre-approved tools (allowed-tools): shell

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Remove each SAP system.
  2. Remove workload-zone resources only after every dependent SAP system is removed.
  3. Remove the control plane only after every dependent workload zone is removed.
  4. Remove retained shared or external resources separately according to their ownership.

What it can do on your machine

Read from SKILL.md and the folder at commit 78835f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • shell

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DEPLOYER_STATE_KEY
    • LANDSCAPE_STATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sdaf Safe Removal loads about 2k tokens when it runs. Until then it costs about 215 tokens; SKILL.md has 691 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~215
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/sap-automation at commit 78835f0, republished under its MIT licence (© Azure). 691 words, ~1,974 tokens.

Download SKILL.mdSave it as .claude/skills/sdaf-safe-removal/SKILL.md (or your agent's skills folder).
name
sdaf-safe-removal
description
Remove SDAF resources safely in reverse dependency order: stop SAP/database services, back up data and state evidence, remove SAP systems before the workload zone, remove workload zones before the control plane, and validate incomplete teardown before any retry or ARM fallback. Grounded in `docs/local/07-00-operations.md`, `docs/local/troubleshooting.md`, `deploy/scripts/remover.sh`, `deploy/scripts/remove_controlplane.sh`, and the Azure DevOps ARM-fallback pipeline. Use when a user asks to remove an SAP system, workload zone, or control plane, to run `remover.sh` or `remove_controlplane.sh`, or to explain why a control-plane removal exited 0 while the deployer still exists. Do NOT use for explicit state `list` / `import` / `remove` operations (see `sdaf-state-management`) or generic failed-run triage (see `sdaf-failure-triage`).
allowed-tools
shell
license
MIT

SDAF Safe Removal

Action-loop skill. Remove SDAF-managed resources only in the documented reverse dependency order and only after a reviewed destroy plan.

When to invoke

Trigger on: "remove an SAP system", "remove the workload zone", "remove the control plane", "safe teardown", "run remover.sh", "run remove_controlplane.sh", "destroy left resources behind", "the control-plane removal said success but the deployer is still there".

Do NOT trigger on: explicit Terraform state surgery, generic failed-run triage, or greenfield deployment.

Preconditions

  • Approved removal scope, maintenance window, identity, and retention plan (docs/local/07-00-operations.md § Inputs, § Prepare an operational change).
  • SAP and database services stopped per product procedures, and business data, configuration, keys, logs, and state evidence backed up (§ Remove resources).
  • Keep the approved SDAF commit, configuration revision, remote-state account, state keys, .sap_deployment_automation metadata, and destroy output (§ Before you begin, § Retain logs and evidence).
  • Run the stage script from the directory that contains the parameter file and pass the basename only (docs/local/troubleshooting.md § A parameter file is not found).

Reverse-order guard

Apply this order on every teardown (docs/local/07-00-operations.md § Remove resources):

  1. Remove each SAP system.
  2. Remove workload-zone resources only after every dependent SAP system is removed.
  3. Remove the control plane only after every dependent workload zone is removed.
  4. Remove retained shared or external resources separately according to their ownership.

Do not continue to a broader scope until the narrower dependency is gone and the destroy output has been reviewed.

Run one approved removal stage at a time

Remove an SAP system

From WORKSPACES/SYSTEM/<SAP_SYSTEM>, exactly per docs/local/07-00-operations.md § Remove an SAP system:

bash
cd "$CONFIG_REPO_PATH/WORKSPACES/SYSTEM/<SAP_SYSTEM>"
ARM_SUBSCRIPTION_ID="<WORKLOAD_SUBSCRIPTION_ID>" \
"$SAP_AUTOMATION_REPO_PATH/deploy/scripts/remover.sh" \
  --type sap_system \
  --parameterfile "<SAP_SYSTEM>.tfvars" \
  --control_plane_name "<CONTROL_PLANE>" \
  --deployer_tfstate_key "<DEPLOYER_STATE_KEY>" \
  --landscape_tfstate_key "<LANDSCAPE_STATE_KEY>" \
  --storageaccountname "<STATE_STORAGE_ACCOUNT>" \
  --state_subscription "<STATE_SUBSCRIPTION_ID>"

Review the destroy plan and confirm only after backups and approvals are complete.

Remove a workload zone

Only after every dependent SAP system is removed. From WORKSPACES/LANDSCAPE/<WORKLOAD_ZONE>-INFRASTRUCTURE, exactly per docs/local/07-00-operations.md § Remove a workload zone:

bash
cd "$CONFIG_REPO_PATH/WORKSPACES/LANDSCAPE/<WORKLOAD_ZONE>-INFRASTRUCTURE"
ARM_SUBSCRIPTION_ID="<WORKLOAD_SUBSCRIPTION_ID>" \
"$SAP_AUTOMATION_REPO_PATH/deploy/scripts/remover.sh" \
  --type sap_landscape \
  --parameterfile "<WORKLOAD_ZONE>-INFRASTRUCTURE.tfvars" \
  --control_plane_name "<CONTROL_PLANE>" \
  --deployer_tfstate_key "<DEPLOYER_STATE_KEY>" \
  --storageaccountname "<STATE_STORAGE_ACCOUNT>" \
  --state_subscription "<STATE_SUBSCRIPTION_ID>"

Confirm the workload-zone state and any retained shared resources match the approved removal scope before approval.

Remove the control plane

Only after every dependent workload zone is removed. From WORKSPACES, exactly per docs/local/07-00-operations.md § Remove the control plane:

bash
cd "$CONFIG_REPO_PATH/WORKSPACES"
"$SAP_AUTOMATION_REPO_PATH/deploy/scripts/remove_controlplane.sh" \
  --deployer_parameter_file \
  "$CONFIG_REPO_PATH/WORKSPACES/DEPLOYER/<CONTROL_PLANE>-INFRASTRUCTURE/<CONTROL_PLANE>-INFRASTRUCTURE.tfvars" \
  --library_parameter_file \
  "$CONFIG_REPO_PATH/WORKSPACES/LIBRARY/<ENVIRONMENT>-<LOCATION>-SAP_LIBRARY/<ENVIRONMENT>-<LOCATION>-SAP_LIBRARY.tfvars"

Review each destroy operation. Use --keep_agent only when the deployment agent retention was explicitly approved and you understand the resulting partial removal (docs/local/07-00-operations.md § Remove the control plane).

If removal is incomplete

docs/local/troubleshooting.md § Removal is incomplete is canonical:

  1. Preserve the destroy output.
  2. Confirm the dependency order was respected.
  3. Compare remaining Azure resources with the Terraform state list.
  4. Resolve locks, permissions, policies, and delete protections.
  5. For an SAP-system or workload-zone removal, rerun the same command and re-review the destroy plan.
Show full SKILL.md (285 more words)Show less
Control-plane partial-removal trap

Do not use the generic rerun rule for an interrupted control-plane removal. Inspect $CONFIG_REPO_PATH/.sap_deployment_automation, its persisted step, the library destroy result, and the remaining deployer state and resources (docs/local/07-00-operations.md § Retry deterministically, docs/local/troubleshooting.md § Removal is incomplete).

After the library destroy, remove_controlplane.sh persists step=1; a later invocation can exit successfully without destroying the deployer. Do not treat that exit as completion, do not edit the step to bypass the guard, and do not switch to ad-hoc resource-group deletion. Obtain expert review for a component-specific recovery path.

ARM fallback — last resort, Azure DevOps only

The only documented ARM fallback here is the Azure DevOps removal fallback. It removes SAP systems, the workload zone, and the region through ARM resource-group deletion and is a fallback only when Terraform destroy does not remove everything.

Use that pipeline only after:

  • the normal reverse-order Terraform removal path was attempted,
  • the destroy output was captured and reviewed,
  • the approved scope still matches the remaining resource groups, and
  • the operator explicitly approves a resource-group deletion fallback.

This repo does not document a local-script or GitHub Actions ARM-fallback procedure. Do not invent one.

Hard rules

  • Do not pass --auto-approve (docs/local/07-00-operations.md § Review before execution).
  • Do not remove the remote-state account or edit state to hide a failure (docs/local/troubleshooting.md § Removal is incomplete).
  • Do not run ad-hoc az group delete, direct ARM deletion, or explicit Terraform state list / import / remove commands in place of the documented sequence; the state-operation boundary belongs to sdaf-state-management.
  • Do not treat a control-plane rerun that exits 0 after step=1 as completed removal.
  • Documented behaviour only; if the docs or shipped scripts are silent, stop.
  • Repo-wide rules apply: follow .github/copilot-instructions.md.

See also

  • sdaf-state-management, sdaf-failure-triage, sdaf-control-plane-bootstrap, sdaf-workload-zone, sdaf-sap-system.
  • docs/local/07-00-operations.md, docs/local/troubleshooting.md, and docs/local/README.md.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sdaf-safe-removal of Azure/sap-automation.

Open the folder on GitHubat commit 78835f0

Compare with similar skills

Sdaf Safe Removal next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sdaf Safe Removal compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sdaf Safe Removal this skillAzure/sap-automation146—~2kAutomated safety check: PassMIT
Azsdk Common Pipeline TroubleshootingAzure/azure-sdk-for-android121—~496Automated safety check: PassMIT
Azsdk Common Pipeline AnalysisAzure/azure-sdk-tools134—~1.2kAutomated safety check: PassMIT
Svelte Core Best Practicesrilldata/rill2.9k4 repos~1.8kAutomated safety check: PassApache-2.0
Dify Component Writing Guidelanggenius/dify158k—~626Automated safety check: PassCustom licence
React State Managementinvolvex/youtube-music-cli45613 repos~3kAutomated safety check: PassMIT

Similar skills

  • Azsdk Common Pipeline Troubleshooting

    Azure/azure-sdk-for-android

    Official

    Diagnose and resolve failures in Azure SDK CI and generation pipelines.

    121 GitHub stars~496 tokensUpdated 4 mo ago
    Agent WorkflowsAuto-check passed
  • Azsdk Common Pipeline Analysis

    Azure/azure-sdk-tools

    Official

    Analyze Azure SDK CI/CD pipeline failures into a structured diagnosis, and define the required output format.

    134 GitHub stars~1.2k tokensUpdated today
    Testing & QAAuto-check passed
  • Rules for writing idiomatic Svelte 5 code: when to reach for runes like state, derived and effect, and how to handle props, attachments and bindings.

    2.9k GitHub starsUsed in 4 repos~1.8k tokens
    Frontend & DesignAuto-check passed
  • Use when implementing or refactoring React/TypeScript components and the task requires decisions about component ownership, feature boundaries, state, data…

    158k GitHub stars~626 tokensUpdated today
    Frontend & DesignAuto-check passed
  • React State Management

    involvex/youtube-music-cli

    Master modern React state management with Redux Toolkit, Zustand, Jotai, and React Query.

    456 GitHub starsUsed in 13 repos~3k tokens
    Frontend & DesignAuto-check passed
  • Pierre Theming Library

    pierrecomputer/pierre

    Explains how to use the @pierre/theming package to list, resolve, select, switch and persist themes, with controller, color and React references.

    6.3k GitHub stars~661 tokensUpdated today
    Frontend & DesignAuto-check passed

More from Azure/sap-automation

All 19 skills in this repo
  • Sdaf Bom Selection

    Azure/sap-automation

    Official

    Pick the right SDAF BOM for a target SAP product / release / DB platform / version / kernel / topology.

    146 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Orientation And Surface

    Azure/sap-automation

    Official

    Orient a newcomer to the SAP Deployment Automation Framework (SDAF): explain the spine (control plane → workload zone → SAP system → software → install → operate/remove), summarise the three…

    146 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Quality Assurance

    Azure/sap-automation

    Official

    Validate a deployed SDAF SAP system through the SDAF-owned QA entry points: the local quality-assurance menu and the documented Azure DevOps pipeline 13 path.

    146 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Sap Installation

    Azure/sap-automation

    Official

    Guide SDAF operating-system, database, and SAP installation after the SAP-system workspace and reviewed media are ready.

    146 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Sovereign Cloud

    Azure/sap-automation

    Official

    Explain the current SDAF sovereign-cloud deltas without inventing a generic "all sovereigns" runbook.

    146 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Sdaf State Management

    Azure/sap-automation

    Official

    Inspect and repair SDAF Terraform state safely before any reviewed import/remove.

    146 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Sdaf Safe Removal

What does Sdaf Safe Removal do?

Remove SDAF resources safely in reverse dependency order: stop SAP/database services, back up data and state evidence, remove SAP systems before the workload zone, remove workload zones before the…. Sdaf Safe Removal is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Remove SDAF resources safely in reverse dependency order: stop SAP/database services, back up data and state evidence, remove SAP systems before the workload zone, remove workload zones before the control plane, and validate incomplete teardown before any retry or ARM fallback.

When should I use Sdaf Safe Removal?

Sdaf Safe Removal fits situations like: A user asks to remove an SAP system; removecontrolplane.sh; explain why a control-plane removal exited 0 while the deployer still exists; explicit state list / import / remove operations (see sdaf-state-management).

How do I install Sdaf Safe Removal in Claude Code?

Run `npx skills add Azure/sap-automation --skill sdaf-safe-removal -a claude-code`. Or copy the skill folder (skills/sdaf-safe-removal in Azure/sap-automation) into .claude/skills/sdaf-safe-removal in your project. Claude Code loads it when a task matches its description.

How do I install Sdaf Safe Removal in Codex?

Run `npx skills add Azure/sap-automation --skill sdaf-safe-removal -a codex`. Or copy the skill folder (skills/sdaf-safe-removal in Azure/sap-automation) into .agents/skills/sdaf-safe-removal in your project. Codex loads it when a task matches its description.

Can I use Sdaf Safe Removal in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/sap-automation --skill sdaf-safe-removal -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sdaf-safe-removal, .gemini/skills/sdaf-safe-removal, .github/skills/sdaf-safe-removal and .opencode/skills/sdaf-safe-removal in your project.

What does Sdaf Safe Removal need to run?

Going by SKILL.md and its folder, Sdaf Safe Removal needs the command-line tools its instructions call (az) and credentials named DEPLOYER_STATE_KEY and LANDSCAPE_STATE_KEY. Our summary lists: A credential in DEPLOYER_STATE_KEY; A credential in LANDSCAPE_STATE_KEY. Its frontmatter pre-approves these tools: shell.

Does Sdaf Safe Removal access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sdaf Safe Removal safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sdaf Safe Removal use?

Sdaf Safe Removal is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sdaf Safe Removal use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sdaf Safe Removal?

Skills that share tags, products or a category with Sdaf Safe Removal: Azsdk Common Pipeline Troubleshooting (Azure/azure-sdk-for-android, 121 stars), Azsdk Common Pipeline Analysis (Azure/azure-sdk-tools, 134 stars), Svelte Core Best Practices (rilldata/rill, 2.9k stars) and Dify Component Writing Guide (langgenius/dify, 158k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sdaf Safe Removal?

Azure (a GitHub organization, an official publisher) maintains it in Azure/sap-automation, which has 146 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 8, 2026.

Source: Azure/sap-automation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.