Official agent skill

Sdaf State Management

by Azure in Azure/sap-automation

Inspect and repair SDAF Terraform state safely before any reviewed import/remove.

OfficialMITAuto-check passedDevOps & Cloud

Install Sdaf State Management

skills CLI
$ npx skills add Azure/sap-automation --skill sdaf-state-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/sap-automation sdaf-state-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sdaf-state-management .claude/skills/sdaf-state-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sdaf-state-management
GitHub stars
145
Token cost
~1.7k tokens
SKILL.md length
694 words
Files
2 (incl. references)
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Inspect and repair SDAF Terraform state safely before any reviewed import/remove.

  • Works in 5 steps: Confirm the boundary before touching state → Reconcile backend identity and back up… → Inspect first with the documented list… → …
  • A user says advancedstatemanagement.sh
  • SKILL.md covers When to invoke, Preconditions, Recipe and Hard rules, plus 2 more sections
  • Calls az and terraform

What it does

Sdaf State Management is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Inspect and repair SDAF Terraform state safely before any reviewed import/remove. Grounded in docs/local/07-00-operations.md § Manage state safely, docs/local/troubleshooting.md § Terraform reports a state lock, and deploy/scripts/advancedstatemanagement.sh. Use when a user says "advancedstatemanagement.sh", "terraform state list", "state import", "state rm", "repair SDAF state", "remote state disagrees with Azure", or "who owns this state lock". Do NOT use for teardown, reverse-order destroy, ARM fallback, or an…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/state-safety.md`).

It sits in DevOps & Cloud, covering State management and Infrastructure as code. It works with Microsoft Azure and Terraform. The repository describes itself as: This is the repository supporting the SAP deployment automation framework on Azure. The licence is MIT.

When your agent uses it

  • A user says advancedstatemanagement.sh
  • Terraform state list
  • Repair SDAF state
  • Remote state disagrees with Azure

Example prompts

  • “advancedstatemanagement.sh”
  • “terraform state list”
  • “state import”
  • “/sdaf-state-management”

Requirements

  • Pre-approved tools (allowed-tools): shell

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Confirm the boundary before touching state
  2. Reconcile backend identity and back up first
  3. Inspect first with the documented list path
  4. Treat import / remove as reviewed repairs, never discovery
  5. Re-list, retain evidence, then hand off

What it can do on your machine

Read from SKILL.md and the folder at commit 78835f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • shell

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az
    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sdaf State Management loads about 1.7k tokens when it runs, and up to ~1.9k if it reads all its reference files. Until then it costs about 144 tokens; SKILL.md has 694 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~144
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/sap-automation at commit 78835f0, republished under its MIT licence (© Azure). 694 words, ~1,659 tokens.

Download SKILL.mdSave it as .claude/skills/sdaf-state-management/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
sdaf-state-management
description
Inspect and repair SDAF Terraform state safely before any reviewed import/remove. Grounded in `docs/local/07-00-operations.md § Manage state safely`, `docs/local/troubleshooting.md § Terraform reports a state lock`, and `deploy/scripts/advanced_state_management.sh`. Use when a user says "advanced_state_management.sh", "terraform state list", "state import", "state rm", "repair SDAF state", "remote state disagrees with Azure", or "who owns this state lock". Do NOT use for teardown, reverse-order destroy, ARM fallback, or an unclassified failed run.
allowed-tools
shell
license
MIT

SDAF State Management

Action-loop skill. Canonical owner of the warning that advanced_state_management.sh re-inits on every op. Uses only the reviewed list / import / remove path documented in the repo and the checked-out script's own --help; refuses to invent a generic unlock or teardown path.

When to invoke

Trigger on: advanced_state_management.sh, "terraform state list", "state import", "state rm", "repair remote state", "backend metadata", "resources.lst", "state lock owner", "remote tfstate disagrees with Azure".

Do NOT trigger on: destroy / teardown / ARM fallback / reverse-order removal, remover.sh, remove_controlplane.sh, hosted removal wrappers, or a failed run whose symptom is still ambiguous.

Preconditions

  • The operator has an approved state operation (docs/local/07-00-operations.md § Prepare an operational change).
  • SAP_AUTOMATION_REPO_PATH, CONFIG_REPO_PATH, and ARM_SUBSCRIPTION_ID are set, or the missing-export gate is fixed first.
  • The target root is known: sap_deployer, sap_library, sap_landscape, or sap_system.
  • The parameter file, state subscription, storage account, and key identify the intended backend.
  • For import or remove, the exact Terraform address and Azure resource ID are known. If not, stop and inspect first.

Recipe

Step 1 — Confirm the boundary before touching state
  • This skill owns reviewed state inspection and repair through deploy/scripts/advanced_state_management.sh.
  • sdaf-safe-removal owns Terraform destroy, reverse-order teardown, and removal through the documented SDAF operations.
  • sdaf-failure-triage owns an ambiguous failed run before the operator has established whether the problem is readiness, deploy, removal, or state.

If the user is trying to delete resources or finish an incomplete teardown, route to sdaf-safe-removal. Do not hide removal problems with state edits.

Step 2 — Reconcile backend identity and back up first

Walk the checklist in references/state-safety.md:

  • Remote state is authoritative after control-plane bootstrap; local .terraform/terraform.tfstate is backend metadata, not the source of truth.
  • Back up the target remote-state blob and local backend metadata before any reviewed state operation.
  • Confirm the local metadata, the supplied subscription/storage account/key, and any .sap_deployment_automation metadata all point at the same backend. The script can infer backend values when arguments are omitted; inspect before trusting.
  • Preserve lock details and prove no other workflow, pipeline, operator, or process still owns the blob.
Step 3 — Inspect first with the documented list path

Before changing anything, confirm the checked-out script contract:

bash
"$SAP_AUTOMATION_REPO_PATH/deploy/scripts/advanced_state_management.sh" --help

Then start with the non-destructive intent from the documented list example in docs/local/07-00-operations.md § Manage state safely:

bash
cd "$CONFIG_REPO_PATH/WORKSPACES/SYSTEM/<SAP_SYSTEM>"
"$SAP_AUTOMATION_REPO_PATH/deploy/scripts/advanced_state_management.sh" \
  --parameterfile "<SAP_SYSTEM>.tfvars" \
  --type sap_system \
  --operation list \
  --subscription "<STATE_SUBSCRIPTION_ID>" \
  --storage_account_name "<STATE_STORAGE_ACCOUNT>" \
  --terraform_keyfile "<SAP_SYSTEM>.terraform.tfstate" \
  --workload_zone_name "<WORKLOAD_ZONE>" \
  --control_plane_name "<CONTROL_PLANE>"

The script initializes the matching root module, writes resources.lst, and only then lists resources. Treat any unexpected copy/migrate prompt as a stop condition; reconcile the backend first and rerun only after review.

Show full SKILL.md (297 more words)Show less
Step 4 — Treat import / remove as reviewed repairs, never discovery
  • state rm stops Terraform from managing a resource; it does not delete the Azure resource.
  • The script validates --azure_resource_id with az resource show --ids before import. If that lookup fails, stop.
  • import and remove are only valid once resources.lst, the Terraform address, and the Azure resource ID all match the reviewed target.
  • Do not shorten, pattern-match, or guess a Terraform address or Azure resource ID.
  • Do not use state rm to bypass a replacement, to make an incomplete removal look clean, or as a substitute for a destroy plan. Those are boundary violations: route to sdaf-failure-triage or sdaf-safe-removal.

If the docs, script output, Azure resource lookup, and stored metadata do not line up cleanly, say docs are insufficient for a safe reviewed edit and stop.

Step 5 — Re-list, retain evidence, then hand off

After any reviewed import/remove:

  • rerun --operation list to confirm the new association;
  • retain the command, output, state account, container, and blob names; and
  • hand back to the owning stage skill for a fresh plan, or to sdaf-safe-removal if the next reviewed step is an actual teardown.

Hard rules

  • Documented behaviour only (D19). If the docs and checked-out script are silent, stop.
  • Never synthesize destructive state edits, generic unlock commands, or an undeclared hosted recovery wrapper.
  • Do not treat list as read-only; initialization can still migrate or upgrade backend/provider state.
  • Do not run two execution models concurrently against the same state.
  • Do not treat local backend metadata as the authoritative state record.

What this skill does NOT do

  • Does not perform teardown, destroy, ARM fallback, or generic failed-run triage.
  • Does not invent a terraform force-unlock procedure or approve import/remove without backups and exact identifiers.

See also

  • sdaf-safe-removal, sdaf-failure-triage, sdaf-control-plane-bootstrap, sdaf-workload-zone, sdaf-sap-system.
  • docs/local/07-00-operations.md, docs/local/troubleshooting.md, and references/state-safety.md.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/sdaf-state-management of Azure/sap-automation.

  • SKILL.md
  • references/state-safety.md

Open the folder on GitHubat commit 78835f0

Compare with similar skills

Sdaf State Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sdaf State Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sdaf State Management this skillAzure/sap-automation145—~1.7kAutomated safety check: PassMIT
Oma Tf Infrafirst-fluke/oh-my-agent1.3k—~2.8kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
TerrasharkLukasNiessen/terrashark715—~843Automated safety check: PassMIT
Azure Diagramscmb211087/azure-diagrams-skill150—~4kAutomated safety check: NotesMIT
Provider Verificationmondoohq/mql412—~3.7kAutomated safety check: PassCustom licence

Similar skills

  • Oma Tf Infra

    first-fluke/oh-my-agent

    Infrastructure-as-code specialist for multi-cloud provisioning using Terraform across any provider (AWS, GCP, Azure, Oracle Cloud).

    1.3k GitHub stars~2.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Terrashark

    LukasNiessen/terrashark

    Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.

    715 GitHub stars~843 tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Azure Diagrams

    cmb211087/azure-diagrams-skill

    Comprehensive technical diagramming toolkit for solutions architects, presales, and developers.

    150 GitHub stars~4k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: notes
  • Verify mql provider resource/field changes against real cloud infrastructure.

    412 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Avm Tf Azapi

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and…

    135 GitHub stars~2.9k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed

More from Azure/sap-automation

All 19 skills in this repo
  • Sdaf Bom Selection

    Azure/sap-automation

    Official

    Pick the right SDAF BOM for a target SAP product / release / DB platform / version / kernel / topology.

    145 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Orientation And Surface

    Azure/sap-automation

    Official

    Orient a newcomer to the SAP Deployment Automation Framework (SDAF): explain the spine (control plane → workload zone → SAP system → software → install → operate/remove), summarise the three…

    145 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Quality Assurance

    Azure/sap-automation

    Official

    Validate a deployed SDAF SAP system through the SDAF-owned QA entry points: the local quality-assurance menu and the documented Azure DevOps pipeline 13 path.

    145 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Sap Installation

    Azure/sap-automation

    Official

    Guide SDAF operating-system, database, and SAP installation after the SAP-system workspace and reviewed media are ready.

    145 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Sovereign Cloud

    Azure/sap-automation

    Official

    Explain the current SDAF sovereign-cloud deltas without inventing a generic "all sovereigns" runbook.

    145 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Workspace And Tfvars

    Azure/sap-automation

    Official

    Explain and validate the SDAF WORKSPACES layout (DEPLOYER / LIBRARY / LANDSCAPE / SYSTEM), the region-code naming convention, and how the four tfvars files hang off it.

    145 GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed

Questions about Sdaf State Management

What does Sdaf State Management do?

Inspect and repair SDAF Terraform state safely before any reviewed import/remove. Sdaf State Management is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Inspect and repair SDAF Terraform state safely before any reviewed import/remove.

When should I use Sdaf State Management?

Sdaf State Management fits situations like: A user says advancedstatemanagement.sh; terraform state list; repair SDAF state; remote state disagrees with Azure.

How do I install Sdaf State Management in Claude Code?

Run `npx skills add Azure/sap-automation --skill sdaf-state-management -a claude-code`. Or copy the skill folder (skills/sdaf-state-management in Azure/sap-automation) into .claude/skills/sdaf-state-management in your project. Claude Code loads it when a task matches its description.

How do I install Sdaf State Management in Codex?

Run `npx skills add Azure/sap-automation --skill sdaf-state-management -a codex`. Or copy the skill folder (skills/sdaf-state-management in Azure/sap-automation) into .agents/skills/sdaf-state-management in your project. Codex loads it when a task matches its description.

Can I use Sdaf State Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/sap-automation --skill sdaf-state-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sdaf-state-management, .gemini/skills/sdaf-state-management, .github/skills/sdaf-state-management and .opencode/skills/sdaf-state-management in your project.

What does Sdaf State Management need to run?

Going by SKILL.md and its folder, Sdaf State Management needs the command-line tools its instructions call (az and terraform). Its frontmatter pre-approves these tools: shell.

Does Sdaf State Management access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sdaf State Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sdaf State Management use?

Sdaf State Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sdaf State Management use?

About 1.7k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 254 tokens, read only when the agent opens those files.

What are the alternatives to Sdaf State Management?

Skills that share tags, products or a category with Sdaf State Management: Oma Tf Infra (first-fluke/oh-my-agent, 1.3k stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Terrashark (LukasNiessen/terrashark, 715 stars) and Azure Diagrams (cmb211087/azure-diagrams-skill, 150 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sdaf State Management?

Azure (a GitHub organization, an official publisher) maintains it in Azure/sap-automation, which has 145 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 8, 2026.

Source: Azure/sap-automation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.