Official agent skill

Sdaf Workload Zone

by Azure in Azure/sap-automation

Deploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists.

OfficialMITAuto-check passedDevOps & Cloud

Install Sdaf Workload Zone

skills CLI
$ npx skills add Azure/sap-automation --skill sdaf-workload-zone -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/sap-automation sdaf-workload-zone --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/sap-automation.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sdaf-workload-zone .claude/skills/sdaf-workload-zone && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sdaf-workload-zone
GitHub stars
145
Token cost
~1.5k tokens
SKILL.md length
525 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Deploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists.

  • Works in 3 steps: Review the plan → Run install_workloadzone.sh (documented… → Validate
  • A user says deploy a workload zone
  • SKILL.md covers When to invoke, Preconditions, Recipe and Decision: workload-zone…, plus 3 more sections
  • Calls terraform; needs DEPLOYER_STATE_KEY

What it does

Sdaf Workload Zone is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Deploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists. Drives installworkloadzone.sh per docs/local/04-00-workload-zone.md, reviews the plan, and validates the state blob and summary. This skill owns the decision boundary for workload-zone private-endpoint / subnet-policy conflicts — inspect the actual Azure error and the workload-zone tfvars against docs/local/04-00-workload-zone.md § Configuration preparation before changing settings, and do not auto-apply a…

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Secrets management. It works with Microsoft Azure. The repository describes itself as: This is the repository supporting the SAP deployment automation framework on Azure. The licence is MIT.

When your agent uses it

  • A user says deploy a workload zone
  • Deploy the landscape
  • Run installworkloadzone.sh
  • Connect the workload zone to control-plane state

Example prompts

  • “deploy a workload zone”
  • “deploy the landscape”
  • “run installworkloadzone.sh”
  • “/sdaf-workload-zone”

Requirements

  • Python 3
  • A credential in DEPLOYER_STATE_KEY
  • Pre-approved tools (allowed-tools): shell

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Review the plan
  2. Run install_workloadzone.sh (documented shape)
  3. Validate

What it can do on your machine

Read from SKILL.md and the folder at commit 78835f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • shell

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DEPLOYER_STATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sdaf Workload Zone loads about 1.5k tokens when it runs. Until then it costs about 235 tokens; SKILL.md has 525 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~235
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/sap-automation at commit 78835f0, republished under its MIT licence (© Azure). 525 words, ~1,522 tokens.

Download SKILL.mdSave it as .claude/skills/sdaf-workload-zone/SKILL.md (or your agent's skills folder).
name
sdaf-workload-zone
description
Deploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists. Drives `install_workloadzone.sh` per `docs/local/04-00-workload-zone.md`, reviews the plan, and validates the state blob and summary. This skill owns the decision boundary for workload-zone private-endpoint / subnet-policy conflicts — inspect the actual Azure error and the workload-zone tfvars against `docs/local/04-00-workload-zone.md § Configuration preparation` before changing settings, and do not auto-apply a cloud-specific workaround outside its documented scope. Use when a user says "deploy a workload zone", "deploy the landscape", "run install_workloadzone.sh", "connect the workload zone to control-plane state", "workload-zone private endpoint failure", or "workload-zone subnet policy failure". Do NOT use for the control plane (see sdaf-control-plane-bootstrap) or SAP system (see sdaf-sap-system).
allowed-tools
shell
license
MIT

SDAF Workload Zone

Action-loop skill. Deploys the workload zone per docs/local/04-00-workload-zone.md. Canonical owner of workload-zone private-endpoint / subnet-policy decisions — the failure-triage skill routes those symptoms here.

When to invoke

Trigger on: "deploy a workload zone", "deploy the landscape", "run install_workloadzone.sh", "workload-zone Key Vault", "workload-zone private endpoint failure", "workload-zone subnet policy failure".

Do NOT trigger on: control plane, SAP system, install, removal.

Preconditions

  • Control plane deployed (docs/local/04-00-workload-zone.md § Before you begin; the WZ reads control-plane / deployer state per § What the automation does).
  • Landscape tfvars prepared under the documented WORKSPACES layout — see sdaf-workspace-and-tfvars (§ Configuration preparation, § Inputs).
  • Remote-state / storage / connectivity / quota reviewed (§ Before you begin) — see sdaf-readiness-check.

Recipe

Step 1 — Review the plan

Re-read the landscape tfvars once and cross-check network, storage, Key Vault, and peering (docs/local/04-00-workload-zone.md § Review before execution).

Step 2 — Run install_workloadzone.sh (documented shape)

From the landscape parameter directory, exactly per docs/local/04-00-workload-zone.md § Run:

bash
set -e
cd "$CONFIG_REPO_PATH/WORKSPACES/LANDSCAPE/<WORKLOAD_ZONE>-INFRASTRUCTURE"
"$SAP_AUTOMATION_REPO_PATH/deploy/scripts/install_workloadzone.sh" \
    --parameterfile "<WORKLOAD_ZONE>-INFRASTRUCTURE.tfvars" \
    --control_plane_name "<CONTROL_PLANE>" \
    --deployer_tfstate_key "<DEPLOYER_STATE_KEY>" \
    --storageaccountname "<STATE_STORAGE_ACCOUNT>" \
    --state_subscription "<STATE_SUBSCRIPTION_ID>" \
    --subscription "<WORKLOAD_SUBSCRIPTION_ID>" || {
  rc=$?
  echo "workload-zone exit=$rc — route to sdaf-failure-triage"
  exit "$rc"
}

Run from the directory that contains the tfvars; pass the basename only (docs/local/troubleshooting.md § A parameter file is not found).

Step 3 — Validate

docs/local/04-00-workload-zone.md § Validate and § Outcome:

  • Workload-zone .tfvars and backend metadata written to the state account's tfvars container (§ What the automation does).
  • Zone Key Vault deployed (§ Outcome).
  • Summary written.

Decision: workload-zone private-endpoint and subnet-policy failures

Canonical owner. The failure-triage skill routes any workload-zone private-endpoint or subnet-policy failure here rather than restating the fix inline.

Decision boundary — apply on every occurrence, do not shortcut:

  1. Read the exact Azure error text from the run log. Do not assume the error class from the operator's paraphrase.
  2. Read the current values of the workload-zone private-endpoint and subnet-policy settings in the tfvars actually being applied.
  3. Read docs/local/04-00-workload-zone.md § Configuration preparation for the current documented setting names, allowed values, and the specific cloud / condition under which the doc prescribes a change. Treat that section as the source of truth — it may evolve; this skill deliberately does not restate the setting name, allowed values, or the exact error string, so it cannot go stale against the doc.
  4. Change only what the doc prescribes for the cloud you are deploying in. Do not auto-apply a cloud-specific workaround (e.g. an Azure Government setting) to any other cloud — the same doc section warns against that.
  5. Re-review the plan (Step 1) before rerunning Step 2.
Show full SKILL.md (157 more words)Show less

If the log's error text, the tfvars values, and the doc section do not line up cleanly, say docs are silent on the specific combination and stop. Do not synthesize a fix from analogous settings elsewhere.

If the run fails

Route to sdaf-failure-triage, which walks the full symptom map. The workload-zone-owned preventive checks that stay here rather than in triage:

  • Filename / directory / basename mismatch — fix before rerun (docs/local/troubleshooting.md § A parameter file is not found).
  • Private-endpoint / subnet-policy failures — walk the decision boundary above.

Hard rules

  • Documented behaviour only (D19).
  • Do not run before the control plane exists.
  • Do not pass --auto-approve (docs/local/04-00-workload-zone.md § Review before execution).
  • Do not --force casually (docs/local/04-00-workload-zone.md § Safe retry).
  • Do not auto-apply a cloud-specific workaround outside the cloud the doc scopes it to (see the decision boundary above).
  • Repo-wide rules apply: do not run terraform fmt and follow the Terraform / Ansible / Python guidance in .github/copilot-instructions.md.

See also

  • sdaf-control-plane-bootstrap, sdaf-workspace-and-tfvars, sdaf-sap-system, sdaf-state-management, sdaf-failure-triage.
  • docs/local/04-00-workload-zone.md, docs/local/troubleshooting.md, .github/copilot-instructions.md.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sdaf-workload-zone of Azure/sap-automation.

Open the folder on GitHubat commit 78835f0

Compare with similar skills

Sdaf Workload Zone next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sdaf Workload Zone compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sdaf Workload Zone this skillAzure/sap-automation145—~1.5kAutomated safety check: PassMIT
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT
Azure FunctionsDataDog/dd-trace-dotnet573—~4.7kAutomated safety check: PassApache-2.0
Letta Configurationletta-ai/skills147—~1.3kAutomated safety check: NotesMIT
Managing Workflow Secretsbitwarden/ai-plugins154—~4kAutomated safety check: PassCustom licence
Azure App Service Securityvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT

Similar skills

  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Azure Functions

    DataDog/dd-trace-dotnet

    Official

    Dev/test workflow for tracer engineers working on the Datadog .NET tracer — build a local Datadog.AzureFunctions NuGet package, deploy it to a test Azure Function App, trigger it, and analyze…

    573 GitHub stars~4.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Letta Configuration

    letta-ai/skills

    Configure LLM models and providers for Letta agents and servers.

    147 GitHub stars~1.3k tokensUpdated 6 days ago
    DevOps & CloudAuto-check: notes
  • Managing Workflow Secrets

    bitwarden/ai-plugins

    Official

    Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions…

    154 GitHub stars~4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Azure Keyvault

    sickn33/agentic-awesome-skills

    Manage secrets and certificates in Azure Key Vault. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.2k tokens
    DevOps & CloudAuto-check passed

More from Azure/sap-automation

All 19 skills in this repo
  • Sdaf Bom Selection

    Azure/sap-automation

    Official

    Pick the right SDAF BOM for a target SAP product / release / DB platform / version / kernel / topology.

    145 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Orientation And Surface

    Azure/sap-automation

    Official

    Orient a newcomer to the SAP Deployment Automation Framework (SDAF): explain the spine (control plane → workload zone → SAP system → software → install → operate/remove), summarise the three…

    145 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Quality Assurance

    Azure/sap-automation

    Official

    Validate a deployed SDAF SAP system through the SDAF-owned QA entry points: the local quality-assurance menu and the documented Azure DevOps pipeline 13 path.

    145 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Sap Installation

    Azure/sap-automation

    Official

    Guide SDAF operating-system, database, and SAP installation after the SAP-system workspace and reviewed media are ready.

    145 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Sdaf Sovereign Cloud

    Azure/sap-automation

    Official

    Explain the current SDAF sovereign-cloud deltas without inventing a generic "all sovereigns" runbook.

    145 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Sdaf State Management

    Azure/sap-automation

    Official

    Inspect and repair SDAF Terraform state safely before any reviewed import/remove.

    145 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about Sdaf Workload Zone

What does Sdaf Workload Zone do?

Deploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists. Sdaf Workload Zone is an agent skill from Azure/sap-automation, published by the product's own GitHub organization. Deploy an SDAF workload zone (landscape network, peering, zone Key Vault) after the control plane exists.

When should I use Sdaf Workload Zone?

Sdaf Workload Zone fits situations like: A user says deploy a workload zone; deploy the landscape; run installworkloadzone.sh; connect the workload zone to control-plane state.

How do I install Sdaf Workload Zone in Claude Code?

Run `npx skills add Azure/sap-automation --skill sdaf-workload-zone -a claude-code`. Or copy the skill folder (skills/sdaf-workload-zone in Azure/sap-automation) into .claude/skills/sdaf-workload-zone in your project. Claude Code loads it when a task matches its description.

How do I install Sdaf Workload Zone in Codex?

Run `npx skills add Azure/sap-automation --skill sdaf-workload-zone -a codex`. Or copy the skill folder (skills/sdaf-workload-zone in Azure/sap-automation) into .agents/skills/sdaf-workload-zone in your project. Codex loads it when a task matches its description.

Can I use Sdaf Workload Zone in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/sap-automation --skill sdaf-workload-zone -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sdaf-workload-zone, .gemini/skills/sdaf-workload-zone, .github/skills/sdaf-workload-zone and .opencode/skills/sdaf-workload-zone in your project.

What does Sdaf Workload Zone need to run?

Going by SKILL.md and its folder, Sdaf Workload Zone needs the command-line tools its instructions call (terraform) and credentials named DEPLOYER_STATE_KEY. Our summary lists: Python 3; A credential in DEPLOYER_STATE_KEY. Its frontmatter pre-approves these tools: shell.

Does Sdaf Workload Zone access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Sdaf Workload Zone safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sdaf Workload Zone use?

Sdaf Workload Zone is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sdaf Workload Zone use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sdaf Workload Zone?

Skills that share tags, products or a category with Sdaf Workload Zone: Azure Bicep Skill (timothywarner-org/claude-code, 224 stars), Azure Functions (DataDog/dd-trace-dotnet, 573 stars), Letta Configuration (letta-ai/skills, 147 stars) and Managing Workflow Secrets (bitwarden/ai-plugins, 154 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sdaf Workload Zone?

Azure (a GitHub organization, an official publisher) maintains it in Azure/sap-automation, which has 145 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 7, 2026.

Source: Azure/sap-automation on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.