Azure Bicep Skill
timothywarner-org/claude-code
A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.
Deploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists.
$ npx skills add Azure/sap-automation --skill sdaf-workload-zone -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Azure/sap-automation sdaf-workload-zone --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sdaf-workload-zone .claude/skills/sdaf-workload-zone && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sdaf-workload-zone" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-workload-zone into .claude/skills/sdaf-workload-zone/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-workload-zone", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Azure/sap-automation/tree/main/skills/sdaf-workload-zoneType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Azure/sap-automation --skill sdaf-workload-zone -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Azure/sap-automation sdaf-workload-zone --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/sdaf-workload-zone .agents/skills/sdaf-workload-zone && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sdaf-workload-zone" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-workload-zone into .agents/skills/sdaf-workload-zone/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-workload-zone", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/sap-automation --skill sdaf-workload-zone -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Azure/sap-automation sdaf-workload-zone --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/sdaf-workload-zone .cursor/skills/sdaf-workload-zone && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sdaf-workload-zone" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-workload-zone into .cursor/skills/sdaf-workload-zone/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-workload-zone", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Azure/sap-automation.git --path skills/sdaf-workload-zone--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Azure/sap-automation --skill sdaf-workload-zone -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Azure/sap-automation sdaf-workload-zone --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/sdaf-workload-zone .gemini/skills/sdaf-workload-zone && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sdaf-workload-zone" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-workload-zone into .gemini/skills/sdaf-workload-zone/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-workload-zone", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Azure/sap-automation sdaf-workload-zoneInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Azure/sap-automation --skill sdaf-workload-zone -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/sdaf-workload-zone .github/skills/sdaf-workload-zone && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sdaf-workload-zone" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-workload-zone into .github/skills/sdaf-workload-zone/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-workload-zone", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/sap-automation --skill sdaf-workload-zone -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Azure/sap-automation sdaf-workload-zone --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/sdaf-workload-zone .opencode/skills/sdaf-workload-zone && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sdaf-workload-zone" agent skill from https://github.com/Azure/sap-automation/tree/main/skills/sdaf-workload-zone into .opencode/skills/sdaf-workload-zone/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sdaf-workload-zone", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sdaf-workload-zoneDeploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists.
Sdaf Workload Zone is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Deploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists. Drives installworkloadzone.sh per docs/local/04-00-workload-zone.md, reviews the plan, and validates the state blob and summary. This skill owns the decision boundary for workload-zone private-endpoint / subnet-policy conflicts — inspect the actual Azure error and the workload-zone tfvars against docs/local/04-00-workload-zone.md § Configuration preparation before changing settings, and do not auto-apply a…
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Secrets management. It works with Microsoft Azure. The repository describes itself as: This is the repository supporting the SAP deployment automation framework on Azure. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 78835f0. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
shellFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
terraformFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DEPLOYER_STATE_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sdaf Workload Zone loads about 1.5k tokens when it runs. Until then it costs about 235 tokens; SKILL.md has 525 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Azure/sap-automation at commit 78835f0, republished under its MIT licence (© Azure). 525 words, ~1,522 tokens.
.claude/skills/sdaf-workload-zone/SKILL.md (or your agent's skills folder).Action-loop skill. Deploys the workload zone per
docs/local/04-00-workload-zone.md. Canonical owner of workload-zone
private-endpoint / subnet-policy decisions — the failure-triage skill
routes those symptoms here.
Trigger on: "deploy a workload zone", "deploy the landscape", "run install_workloadzone.sh", "workload-zone Key Vault", "workload-zone private endpoint failure", "workload-zone subnet policy failure".
Do NOT trigger on: control plane, SAP system, install, removal.
docs/local/04-00-workload-zone.md § Before you begin; the WZ reads control-plane / deployer state per
§ What the automation does).sdaf-workspace-and-tfvars (§ Configuration preparation, § Inputs).§ Before you begin) — see sdaf-readiness-check.Re-read the landscape tfvars once and cross-check network, storage, Key
Vault, and peering
(docs/local/04-00-workload-zone.md § Review before execution).
From the landscape parameter directory, exactly per
docs/local/04-00-workload-zone.md § Run:
set -e
cd "$CONFIG_REPO_PATH/WORKSPACES/LANDSCAPE/<WORKLOAD_ZONE>-INFRASTRUCTURE"
"$SAP_AUTOMATION_REPO_PATH/deploy/scripts/install_workloadzone.sh" \
--parameterfile "<WORKLOAD_ZONE>-INFRASTRUCTURE.tfvars" \
--control_plane_name "<CONTROL_PLANE>" \
--deployer_tfstate_key "<DEPLOYER_STATE_KEY>" \
--storageaccountname "<STATE_STORAGE_ACCOUNT>" \
--state_subscription "<STATE_SUBSCRIPTION_ID>" \
--subscription "<WORKLOAD_SUBSCRIPTION_ID>" || {
rc=$?
echo "workload-zone exit=$rc — route to sdaf-failure-triage"
exit "$rc"
}Run from the directory that contains the tfvars; pass the basename only
(docs/local/troubleshooting.md § A parameter file is not found).
docs/local/04-00-workload-zone.md § Validate and § Outcome:
.tfvars and backend metadata written to the state
account's tfvars container (§ What the automation does).§ Outcome).Canonical owner. The failure-triage skill routes any workload-zone private-endpoint or subnet-policy failure here rather than restating the fix inline.
Decision boundary — apply on every occurrence, do not shortcut:
docs/local/04-00-workload-zone.md § Configuration preparation for
the current documented setting names, allowed values, and the specific
cloud / condition under which the doc prescribes a change. Treat that
section as the source of truth — it may evolve; this skill deliberately
does not restate the setting name, allowed values, or the exact error
string, so it cannot go stale against the doc.If the log's error text, the tfvars values, and the doc section do not line up cleanly, say docs are silent on the specific combination and stop. Do not synthesize a fix from analogous settings elsewhere.
Route to sdaf-failure-triage, which walks the full symptom map. The
workload-zone-owned preventive checks that stay here rather than in
triage:
docs/local/troubleshooting.md § A parameter file is not found).--auto-approve
(docs/local/04-00-workload-zone.md § Review before execution).--force casually
(docs/local/04-00-workload-zone.md § Safe retry).terraform fmt and follow the
Terraform / Ansible / Python guidance in
.github/copilot-instructions.md.sdaf-control-plane-bootstrap, sdaf-workspace-and-tfvars,
sdaf-sap-system, sdaf-state-management, sdaf-failure-triage.docs/local/04-00-workload-zone.md, docs/local/troubleshooting.md,
.github/copilot-instructions.md.© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/sdaf-workload-zone of Azure/sap-automation.
Open the folder on GitHubat commit 78835f0
Sdaf Workload Zone next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sdaf Workload Zone this skillAzure/sap-automation | 145 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Azure Bicep Skilltimothywarner-org/claude-code | 224 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Azure FunctionsDataDog/dd-trace-dotnet | 573 | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | |
| Letta Configurationletta-ai/skills | 147 | — | ~1.3k | Automated safety check: Notes | MIT | |
| Managing Workflow Secretsbitwarden/ai-plugins | 154 | — | ~4k | Automated safety check: Pass | Custom licence | |
| Azure App Service Securityvinayaklatthe/microsoft-security-skills | 175 | — | ~1.9k | Automated safety check: Pass | MIT |
timothywarner-org/claude-code
A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.
DataDog/dd-trace-dotnet
Dev/test workflow for tracer engineers working on the Datadog .NET tracer — build a local Datadog.AzureFunctions NuGet package, deploy it to a test Azure Function App, trigger it, and analyze…
letta-ai/skills
Configure LLM models and providers for Letta agents and servers.
bitwarden/ai-plugins
Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…
vinayaklatthe/microsoft-security-skills
Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…
sickn33/agentic-awesome-skills
Manage secrets and certificates in Azure Key Vault. An agent skill from sickn33/agentic-awesome-skills.
Azure/sap-automation
Pick the right SDAF BOM for a target SAP product / release / DB platform / version / kernel / topology.
Azure/sap-automation
Orient a newcomer to the SAP Deployment Automation Framework (SDAF): explain the spine (control plane → workload zone → SAP system → software → install → operate/remove), summarise the three…
Azure/sap-automation
Validate a deployed SDAF SAP system through the SDAF-owned QA entry points: the local quality-assurance menu and the documented Azure DevOps pipeline 13 path.
Azure/sap-automation
Guide SDAF operating-system, database, and SAP installation after the SAP-system workspace and reviewed media are ready.
Azure/sap-automation
Explain the current SDAF sovereign-cloud deltas without inventing a generic "all sovereigns" runbook.
Azure/sap-automation
Inspect and repair SDAF Terraform state safely before any reviewed import/remove.
Works with
Categories
Deploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists. Sdaf Workload Zone is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Deploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists.
Sdaf Workload Zone fits situations like: A user says deploy a workload zone; deploy the landscape; run installworkloadzone.sh; connect the workload zone to control-plane state.
Run `npx skills add Azure/sap-automation --skill sdaf-workload-zone -a claude-code`. Or copy the skill folder (skills/sdaf-workload-zone in Azure/sap-automation) into .claude/skills/sdaf-workload-zone in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Azure/sap-automation --skill sdaf-workload-zone -a codex`. Or copy the skill folder (skills/sdaf-workload-zone in Azure/sap-automation) into .agents/skills/sdaf-workload-zone in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/sap-automation --skill sdaf-workload-zone -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sdaf-workload-zone, .gemini/skills/sdaf-workload-zone, .github/skills/sdaf-workload-zone and .opencode/skills/sdaf-workload-zone in your project.
Going by SKILL.md and its folder, Sdaf Workload Zone needs the command-line tools its instructions call (terraform) and credentials named DEPLOYER_STATE_KEY. Our summary lists: Python 3; A credential in DEPLOYER_STATE_KEY. Its frontmatter pre-approves these tools: shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sdaf Workload Zone is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sdaf Workload Zone: Azure Bicep Skill (timothywarner-org/claude-code, 224 stars), Azure Functions (DataDog/dd-trace-dotnet, 573 stars), Letta Configuration (letta-ai/skills, 147 stars) and Managing Workflow Secrets (bitwarden/ai-plugins, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Azure (a GitHub organization, an official publisher) maintains it in Azure/sap-automation, which has 145 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.
Source: Azure/sap-automation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.