Agent skill

Apex Azure Diagnostics

by jonathan-vella in jonathan-vella/apex

WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.

MITAuto-check passedDevOps & Cloud

Install Apex Azure Diagnostics

skills CLI
$ npx skills add jonathan-vella/apex --skill apex-azure-diagnostics -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jonathan-vella/apex apex-azure-diagnostics --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jonathan-vella/apex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/apex-azure-diagnostics .claude/skills/apex-azure-diagnostics && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
apex-azure-diagnostics
GitHub stars
217
Token cost
~2.1k tokens
SKILL.md length
653 words
Files
59 (incl. scripts, references)
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.

  • Works in 8 steps: Start with systematic diagnosis flow → Use AppLens (MCP) for AI-powered… → Check resource health before deep-diving… → …
  • : pre-deploy validation (apex-azure-validate)
  • SKILL.md covers Triggers, Rules, Prerequisites and Steps, plus 5 more sections
  • Calls az

What it does

Apex Azure Diagnostics is an agent skill from jonathan-vella/apex. WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis. WHEN: 'troubleshoot container apps', 'troubleshoot AKS', 'pod crashloop', 'VM RDP or SSH failure', 'app service high CPU', 'service bus errors'. DO NOT USE FOR: pre-deploy validation (apex-azure-validate), cost (apex-azure-cost-optimization), AKS design (apex-azure-kubernetes).

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 62 other files, including scripts and reference files (for example `references/aks/aks-troubleshooting.md`, `references/aks/general-diagnostics.md` and `references/aks/load-balancer-and-ingress.md`).

It sits in DevOps & Cloud, covering Container orchestration. It works with Microsoft Azure, Microsoft Sentinel, Kubernetes and Model Context Protocol. The repository describes itself as: APEX turns Azure platform engineering requirements into verified, deploy-ready IaC — powered by GitHub Copilot agents, real-time pricing, and built-in compliance. The licence is MIT.

When your agent uses it

  • : pre-deploy validation (apex-azure-validate)
  • Cost (apex-azure-cost-optimization)
  • AKS design (apex-azure-kubernetes)

Example prompts

  • “troubleshoot container apps”
  • “troubleshoot AKS”
  • “pod crashloop”
  • “/apex-azure-diagnostics”

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Start with systematic diagnosis flow
  2. Use AppLens (MCP) for AI-powered diagnostics when available
  3. Check resource health before deep-diving into logs
  4. Select appropriate troubleshooting guide based on service type
  5. Document findings and attempted remediation steps
  6. Diagnose only the approved scope; obtain separate approval before remediation
  7. Default to read-only. Restarts, redeploys, run-command, credential resets, NSG changes,
  8. Never print secret values: list app setting names only, and never pass passwords through chat

What it can do on your machine

Read from SKILL.md and the folder at commit b8e5908. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use az, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Apex Azure Diagnostics loads about 2.1k tokens when it runs, and up to ~36k if it reads all its reference files. Until then it costs about 110 tokens; SKILL.md has 653 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~110
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~36k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jonathan-vella/apex at commit b8e5908, republished under its MIT licence (© jonathan-vella). 653 words, ~2,105 tokens.

Download SKILL.mdSave it as .claude/skills/apex-azure-diagnostics/SKILL.md (or your agent's skills folder). This skill also uses 58 other files; get the full folder from GitHub.
name
apex-azure-diagnostics
description
**WORKFLOW SKILL** — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis. WHEN: 'troubleshoot container apps', 'troubleshoot AKS', 'pod crashloop', 'VM RDP or SSH failure', 'app service high CPU', 'service bus errors'. DO NOT USE FOR: pre-deploy validation (apex-azure-validate), cost (apex-azure-cost-optimization), AKS design (apex-azure-kubernetes).
user-invocable
true
disable-model-invocation
false
argument-hint
resource scope, symptom and time range
license
MIT
metadata.author
Microsoft
metadata.version
1.0.2

Azure Diagnostics

AUTHORITATIVE GUIDANCE — MANDATORY COMPLIANCE

This document is the official source for debugging and troubleshooting Azure production issues. Follow these instructions to diagnose and resolve common Azure service problems systematically.

Triggers

Activate this skill when user wants to:

  • Debug or troubleshoot production issues
  • Diagnose errors in Azure services
  • Analyze application logs or metrics
  • Fix image pull, cold start, or health probe issues
  • Investigate why Azure resources are failing
  • Find root cause of application errors
  • Troubleshoot Azure Function Apps (invocation failures, timeouts, binding errors)
  • Find the App Insights or Log Analytics workspace linked to a Function App
  • Troubleshoot App Service issues (high CPU, deployment failures, crashes, slow responses, TLS/custom domains)
  • Troubleshoot AKS clusters, nodes, pods, ingress, DNS or upgrades
  • Troubleshoot Azure VM connectivity (RDP/SSH failures, NSG or firewall blocks, VM agent issues)
  • Troubleshoot Event Hubs and Service Bus SDK errors (AMQP failures, lock lost, connectivity)

Rules

  1. Start with systematic diagnosis flow
  2. Use AppLens (MCP) for AI-powered diagnostics when available
  3. Check resource health before deep-diving into logs
  4. Select appropriate troubleshooting guide based on service type
  5. Document findings and attempted remediation steps
  6. Diagnose only the approved scope; obtain separate approval before remediation
  7. Default to read-only. Restarts, redeploys, run-command, credential resets, NSG changes, cordon/drain and node debug pods (run-ig with --approve) each need explicit approval
  8. Never print secret values: list app setting names only, and never pass passwords through chat

Prerequisites

  • Confirm resource IDs, subscription, incident window and read access.
  • Use available Azure CLI or MCP capabilities; unavailable telemetry is a gap, not a healthy result. Do not dump credentials or app settings into reports.

Steps

Follow the diagnostic workflow for discovery, health/metrics, logs, recent changes, severity classification and reporting. That procedure owns phase order and the severity-to-priority mapping. Load only the health checks and query templates needed for the selected service.


Troubleshooting Guides by Service

ServiceCommon IssuesReference
Container AppsImage pull failures, cold starts, health probes, port mismatchescontainer-apps/
App ServiceHigh CPU, deployment failures, crashes, slow responses, TLS/custom domainsapp-service/
Function AppsApp details, invocation failures, timeouts, binding errors, cold starts, missing app settingsfunctions/
AKSCluster access, nodes, kube-system, scheduling, crash loops, ingress, DNS, upgradesAKS troubleshooting
Compute (VM)RDP/SSH connectivity, NSG/firewall blocks, credential resets, VM agent issuesVM connectivity
MessagingEvent Hubs and Service Bus SDK errors, AMQP failures, message lock, connectivityMessaging troubleshooting

Route active AKS incidents, VM connectivity and messaging SDK problems to their guides above; keep Container Apps, App Service and Function Apps diagnostics in this skill.

Show full SKILL.md (232 more words)Show less

Scripts

Bash and PowerShell pairs in scripts/ gather evidence in one pass. All are read-only except run-ig.

ScriptPurpose
aks-baselineAKS provisioning state, node pools, recent activity, node readiness and kube-system health
pod-evidenceStatus, describe, current and previous logs, and resource usage for unhealthy pods
run-igInspektor Gadget trace through a privileged node debug pod; runs only with --approve/-Approve
appservice-diagnosticsApp Service config, recent deployments, app setting names and custom domains
containerapp-diagnosticsContainer App revisions, registry and ingress config, and recent logs
test-messaging-connectivityDNS, HTTPS and AMQP/Kafka port reachability for a Service Bus or Event Hubs namespace

Quick Reference

Common Diagnostic Commands
bash
# Inspect resource metadata (not Resource Health availability)
az resource show --ids RESOURCE_ID

# View activity log
az monitor activity-log list -g RG --max-events 20

# Container Apps logs
az containerapp logs show --name APP -g RG --follow

# Function App logs (query App Insights traces)
az monitor app-insights query --apps APP-INSIGHTS -g RG \
  --analytics-query "traces | where timestamp > ago(1h) | order by timestamp desc | take 50"
AppLens (MCP Tools)

For AI-powered diagnostics, use:

mcp_azure-mcp_applens
  intent: "diagnose issues with <resource-name>"
  command: "diagnose"
  parameters:
    resourceId: "<resource-id>"

Provides:
- Automated issue detection
- Root cause analysis
- Remediation recommendations
Azure Monitor (MCP Tools)

For querying logs and metrics:

mcp_azure-mcp_monitor
  intent: "query logs for <resource-name>"
  command: "logs_query"
  parameters:
    workspaceId: "<workspace-id>"
    query: "<KQL-query>"

See kql-queries.md for common diagnostic queries.


Check Azure Resource Health

Using MCP
mcp_azure-mcp_resourcehealth
  intent: "check health status of <resource-name>"
  command: "get"
  parameters:
    resourceId: "<resource-id>"

Metadata/provisioning state from az resource show is not Resource Health availability. If the Resource Health tool is unavailable, report that check as unavailable and continue the approved health checks.


Reference Index

Load these references on demand, not all at once.

© jonathan-vella, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 58 other files (scripts, references) in .github/skills/apex-azure-diagnostics of jonathan-vella/apex.

  • SKILL.md
  • references/aks/aks-troubleshooting.md
  • references/aks/general-diagnostics.md
  • references/aks/load-balancer-and-ingress.md
  • references/aks/network-policy.md
  • references/aks/networking.md
  • references/aks/node-issues.md
  • references/aks/pod-failures.md
  • references/aks/references/aks-mcp.md
  • references/aks/references/command-flows.md
  • references/aks/references/inspektor-gadget.md
  • references/aks/references/structured-input-modes.md
  • references/aks/spot-and-zone-issues.md
  • references/aks/upgrade-operations.md
  • references/app-service/README.md
  • references/azure-resource-graph.md
  • references/compute
  • … and 42 more

Open the folder on GitHubat commit b8e5908

Compare with similar skills

Apex Azure Diagnostics next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Apex Azure Diagnostics compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Apex Azure Diagnostics this skilljonathan-vella/apex217—~2.1kAutomated safety check: PassMIT
Azure Kubernetes Automatic Readinessmicrosoft/GitHub-Copilot-for-Azure2551 repos~4.4kAutomated safety check: PassMIT
Azure Diagnosticsmicrosoft/GitHub-Copilot-for-Azure255—~1.9kAutomated safety check: PassMIT
Install Boltmcpboltmcp/boltmcp371—~2.3kAutomated safety check: PassNone
K8s Agent Sandbox MCPkubernetes-sigs/agent-sandbox4.2k—~1.3kAutomated safety check: PassApache-2.0
Provider Bug Reviewmondoohq/mql412—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Azure Kubernetes Automatic Readiness

    microsoft/GitHub-Copilot-for-Azure

    Official

    Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.

    255 GitHub starsUsed in 1 repo~4.4k tokens
    DevOps & CloudAuto-check passed
  • Azure Diagnostics

    microsoft/GitHub-Copilot-for-Azure

    Official

    Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage.

    255 GitHub stars~1.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Install Boltmcp

    boltmcp/boltmcp

    A skill your agent uses when asked to help install or uninstall BoltMCP

    371 GitHub stars~2.3k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • K8s Agent Sandbox MCP

    kubernetes-sigs/agent-sandbox

    Official

    An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.

    4.2k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.

    412 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Aspire Monitoring

    CommunityToolkit/Aspire

    ANALYSIS SKILL - Observe Aspire apps: logs, traces, metrics, resource state, telemetry export, browser telemetry, and the standalone dashboard.

    627 GitHub stars~3.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from jonathan-vella/apex

All 39 skills in this repo
  • ANALYSIS SKILL — Azure Policy discovery: effective assignments (incl.

    217 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Apex Context Management

    jonathan-vella/apex

    UTILITY SKILL — Two-mode context-window management. An agent skill from jonathan-vella/apex.

    217 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Apex Python Diagrams

    jonathan-vella/apex

    UTILITY SKILL — Python diagram generation for Azure architectures, WAF/cost/compliance charts, ERDs, swimlanes, timelines, and wireframes.

    217 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Apex Terraform Search Import

    jonathan-vella/apex

    WORKFLOW SKILL — Manual-only discovery and import of existing Azure resources into Terraform management.

    217 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Apex Vendor Prompting

    jonathan-vella/apex

    ANALYSIS SKILL — Manual-only audit of Anthropic Claude Opus 5.5 / Sonnet 5.5 and OpenAI GPT-6 / GPT-5.6 prompting guidance and APEX conventions.

    217 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Apex Agent Authoring

    jonathan-vella/apex

    WORKFLOW SKILL — Creates, restructures, and audits GitHub Copilot .agent.md and .prompt.md files with correct frontmatter, handoffs, model policy, context budgets, and validation.

    217 GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Categories

Questions about Apex Azure Diagnostics

What does Apex Azure Diagnostics do?

WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis. Apex Azure Diagnostics is an agent skill from jonathan-vella/apex. WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.

When should I use Apex Azure Diagnostics?

Apex Azure Diagnostics fits situations like: : pre-deploy validation (apex-azure-validate); cost (apex-azure-cost-optimization); AKS design (apex-azure-kubernetes).

How do I install Apex Azure Diagnostics in Claude Code?

Run `npx skills add jonathan-vella/apex --skill apex-azure-diagnostics -a claude-code`. Or copy the skill folder (.github/skills/apex-azure-diagnostics in jonathan-vella/apex) into .claude/skills/apex-azure-diagnostics in your project. Claude Code loads it when a task matches its description.

How do I install Apex Azure Diagnostics in Codex?

Run `npx skills add jonathan-vella/apex --skill apex-azure-diagnostics -a codex`. Or copy the skill folder (.github/skills/apex-azure-diagnostics in jonathan-vella/apex) into .agents/skills/apex-azure-diagnostics in your project. Codex loads it when a task matches its description.

Can I use Apex Azure Diagnostics in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jonathan-vella/apex --skill apex-azure-diagnostics -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/apex-azure-diagnostics, .gemini/skills/apex-azure-diagnostics, .github/skills/apex-azure-diagnostics and .opencode/skills/apex-azure-diagnostics in your project.

What does Apex Azure Diagnostics need to run?

Going by SKILL.md and its folder, Apex Azure Diagnostics needs the command-line tools its instructions call (az).

Does Apex Azure Diagnostics access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Apex Azure Diagnostics safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Apex Azure Diagnostics use?

Apex Azure Diagnostics is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Apex Azure Diagnostics use?

About 2.1k tokens (SKILL.md is roughly 8.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 34k tokens, read only when the agent opens those files.

What are the alternatives to Apex Azure Diagnostics?

Skills that share tags, products or a category with Apex Azure Diagnostics: Azure Kubernetes Automatic Readiness (microsoft/GitHub-Copilot-for-Azure, 255 stars), Azure Diagnostics (microsoft/GitHub-Copilot-for-Azure, 255 stars), Install Boltmcp (boltmcp/boltmcp, 371 stars) and K8s Agent Sandbox MCP (kubernetes-sigs/agent-sandbox, 4.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Apex Azure Diagnostics?

jonathan-vella (a GitHub user) maintains it in jonathan-vella/apex, which has 217 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on October 10, 2026.

Source: jonathan-vella/apex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.