Agent skill

Apex Azure Kubernetes

by jonathan-vella in jonathan-vella/apex

ANALYSIS SKILL — Day-0 AKS design advice: Automatic vs Standard, networking, identity, observability, upgrades, node pools, autoscaling and Spot.

MITAuto-check passedDevOps & Cloud

Install Apex Azure Kubernetes

skills CLI
$ npx skills add jonathan-vella/apex --skill apex-azure-kubernetes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jonathan-vella/apex apex-azure-kubernetes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jonathan-vella/apex.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/apex-azure-kubernetes .claude/skills/apex-azure-kubernetes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
apex-azure-kubernetes
GitHub stars
217
Token cost
~2.1k tokens
SKILL.md length
821 words
Files
8 (incl. references)
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

ANALYSIS SKILL — Day-0 AKS design advice: Automatic vs Standard, networking, identity, observability, upgrades, node pools, autoscaling and Spot.

  • Works in 9 steps: Cluster Type → Networking (Day-0) → Security → …
  • : AKS troubleshooting (apex-azure-diagnostics)
  • SKILL.md covers Quick Reference, Rules, Required Inputs and Design Checklist, plus 3 more sections
  • Calls az

What it does

Apex Azure Kubernetes is an agent skill from jonathan-vella/apex. ANALYSIS SKILL — Day-0 AKS design advice: Automatic vs Standard, networking, identity, observability, upgrades, node pools, autoscaling and Spot. WHEN: "design AKS", "AKS Automatic or Standard", "AKS networking", "AKS node pools", "rightsize AKS pods", "AKS spot nodes". DO NOT USE FOR: AKS troubleshooting (apex-azure-diagnostics), provisioning or IaC (05-IaC Planner, 06b/06t).

Its SKILL.md is about 2.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `references/azure-aks-autoscaler.md`, `references/azure-aks-rightsizing.md` and `references/azure-aks-spot.md`).

It sits in DevOps & Cloud, covering Container orchestration, Infrastructure as code and Observability. It works with Microsoft Azure and Kubernetes. The repository describes itself as: APEX turns Azure platform engineering requirements into verified, deploy-ready IaC — powered by GitHub Copilot agents, real-time pricing, and built-in compliance. The licence is MIT.

When your agent uses it

  • : AKS troubleshooting (apex-azure-diagnostics)
  • IaC (05-IaC Planner

Example prompts

  • “design AKS”
  • “AKS Automatic or Standard”
  • “AKS networking”
  • “/apex-azure-kubernetes”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Cluster Type
  2. Networking (Day-0)
  3. Security
  4. Observability
  5. Upgrades and Patching
  6. Performance
  7. Node Pools and Compute
  8. Reliability
  9. Cost

What it can do on your machine

Read from SKILL.md and the folder at commit b8e5908. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Apex Azure Kubernetes loads about 2.1k tokens when it runs, and up to ~8.4k if it reads all its reference files. Until then it costs about 101 tokens; SKILL.md has 821 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~101
When it runs · the whole SKILL.md, loaded when a task matches
~2.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jonathan-vella/apex at commit b8e5908, republished under its MIT licence (© jonathan-vella). 821 words, ~2,114 tokens.

Download SKILL.mdSave it as .claude/skills/apex-azure-kubernetes/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
apex-azure-kubernetes
description
**ANALYSIS SKILL** — Day-0 AKS design advice: Automatic vs Standard, networking, identity, observability, upgrades, node pools, autoscaling and Spot. WHEN: "design AKS", "AKS Automatic or Standard", "AKS networking", "AKS node pools", "rightsize AKS pods", "AKS spot nodes". DO NOT USE FOR: AKS troubleshooting (apex-azure-diagnostics), provisioning or IaC (05-IaC Planner, 06b/06t).
user-invocable
true
disable-model-invocation
false
argument-hint
workload requirements, environment type, region and constraints
license
MIT
metadata.author
Microsoft
metadata.version
1.2.2

Azure Kubernetes Service Design

Adapted from upstream azure-kubernetes. This skill recommends an AKS configuration and separates Day-0 decisions (networking, API server access, identity — hard to change later) from Day-1 features that can be enabled after creation. It advises; it never creates or changes a cluster.

Quick Reference

PropertyValue
Best forAKS cluster planning and Day-0 decisions in Steps 2 and 4
MCP toolsmcp_azure-mcp_aks (read-only discovery of existing clusters)
ImplementationAVM avm/res/container-service/managed-cluster (Bicep) or Azure/avm-res-containerservice-managedcluster/azurerm (Terraform) through 06b/06t
Related skillsapex-azure-diagnostics (troubleshooting), apex-azure-quotas (node SKU availability and quota), apex-azure-defaults (naming, regions, AVM)

Rules

  1. Start from the user's requirements; ask only for missing Day-0 inputs.
  2. Default to AKS Automatic unless a requirement needs Standard (custom node pools, networking or autoscaling that Node Auto-Provisioning doesn't support). Confirm the chosen features are exposed by the AVM module before recommending them.
  3. Record each Day-0 decision with its rationale; they are expensive to change after creation.
  4. Apply the APEX baseline: private API server access (API Server VNet Integration or a private cluster) for production, Microsoft Entra ID authentication with local accounts disabled, Workload Identity for pods, and the default region from apex-azure-defaults with availability zones.
  5. Confirm node VM sizes with the apex-azure-quotas SKU availability check. Price only through cost-estimate-subagent; don't quote discounts or savings percentages.
  6. Never run az aks or kubectl commands that change state. Hand the configuration to 05-IaC Planner and 06b/06t; existing-cluster changes need an approved change owner.

Required Inputs

Use safe defaults when the user is unsure.

  • Environment type (dev/test or production), region and zones
  • Expected scale (nodes, clusters, workload size) and preferred node VM sizes
  • Networking: API server access, pod IP model, ingress and egress control
  • Security and identity, including the image registry
  • Upgrade and observability preferences, and cost constraints

Design Checklist

1. Cluster Type
  • AKS Automatic (default): curated security, reliability and performance defaults for most production workloads.
  • AKS Standard: full control of node pools, networking and autoscaling at the cost of more operations work.
2. Networking (Day-0)
  • Pod IP model: Azure CNI Overlay (recommended; pod IPs from a private overlay range) or Azure CNI with VNet-routable pod IPs when pods must be addressable from the VNet or on-premises. See Azure CNI Overlay.
  • Dataplane and network policy: Azure CNI powered by Cilium.
  • Egress: Static Egress Gateway for stable outbound IPs; UDR with Azure Firewall or an NVA for restricted egress.
  • Ingress: App Routing add-on with Gateway API by default; Istio with Gateway API for mTLS and canary releases; Application Gateway for Containers for L7 load balancing with WAF.
  • DNS: enable LocalDNS on all node pools.
3. Security
  • Microsoft Entra ID everywhere (control plane, Workload Identity for pods, node access); no static credentials. See workload identity.
  • Azure Key Vault through the Secrets Store CSI Driver.
  • Azure Policy with Deployment Safeguards.
  • Encryption at rest and in transit; only signed, policy-approved images, preferably from Azure Container Registry.
  • Isolate with namespaces, network policies and scoped logging.
Show full SKILL.md (333 more words)Show less
4. Observability
  • Managed Prometheus, Container Insights and Grafana for metrics and logs.
  • Diagnostic settings sending control plane and audit logs to Log Analytics.
5. Upgrades and Patching
  • Maintenance windows, and auto-upgrade for the control plane and node OS.
  • LTS versions (Premium tier) for enterprise stability; AKS Fleet Manager for staged rollouts across environments.
6. Performance
  • Ephemeral OS disks, Azure Linux node OS, and KEDA for event-driven autoscaling beyond HPA.
7. Node Pools and Compute
  • A dedicated system node pool of at least 2 nodes, tainted CriticalAddonsOnly.
  • Node Auto-Provisioning where supported; latest-generation VM sizes with at least 4 vCPUs for production.
  • Avoid B-series (burstable) VMs; spread pods across hosts and zones with topology spread constraints.
8. Reliability
  • Three availability zones, the Standard tier (zone-redundant control plane with an SLA), PodDisruptionBudgets for production workloads, and Microsoft Defender for Containers.
9. Cost
  • Spot node pools only for interruptible workloads; stop dev/test clusters outside working hours through an approved operational runbook; consider reservations or savings plans for steady-state capacity.

Deep-Dive Scenarios

Load only the reference that matches the request; if a prompt matches several, ask which one the user means.

ScenarioTrigger keywordsReference
Pod rightsizingover-provisioned pods, CPU or memory requestsazure-aks-rightsizing.md
VPAvertical pod autoscaler, VPA recommendationsazure-aks-vpa.md
Cluster autoscaleridle nodes, scale-down profile, node utilizationazure-aks-autoscaler.md
Spot node poolsSpot VMs, batch workloads, cheaper nodesazure-aks-spot.md

Guardrails

  • Don't request or output secrets, tokens or keys, and don't ask the user to paste subscription IDs; discover scope with mcp_azure-mcp_subscription_list or az account show.
  • For ambiguous Day-0 requirements, ask. For Day-1 features, offer two or three safe options with trade-offs.
  • Don't promise zero downtime; recommend PodDisruptionBudgets, probes, replicas and staged upgrades.
  • Inspect existing clusters only with the read-only commands in the CLI reference.

Reference Index

ReferenceWhen to Load
references/azure-aks-rightsizing.mdPod request and limit rightsizing
references/azure-aks-vpa.mdVertical Pod Autoscaler recommendations
references/azure-aks-autoscaler.mdCluster autoscaler tuning
references/azure-aks-spot.mdSpot node pool design
references/workload-identity.mdWorkload Identity setup for pods
references/safeguards.mdDeployment Safeguards rules for workload manifests
references/cli-reference.mdRead-only inspection commands

© jonathan-vella, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (references) in .github/skills/apex-azure-kubernetes of jonathan-vella/apex.

  • SKILL.md
  • references/azure-aks-autoscaler.md
  • references/azure-aks-rightsizing.md
  • references/azure-aks-spot.md
  • references/azure-aks-vpa.md
  • references/cli-reference.md
  • references/safeguards.md
  • references/workload-identity.md

Open the folder on GitHubat commit b8e5908

Compare with similar skills

Apex Azure Kubernetes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Apex Azure Kubernetes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Apex Azure Kubernetes this skilljonathan-vella/apex217—~2.1kAutomated safety check: PassMIT
Cloud Devopsdavila7/claude-code-templates33k4 repos~1.4kAutomated safety check: PassMIT
Infrastructuremicrosoft/physical-ai-toolchain126—~1.6kAutomated safety check: PassMIT
Iac Securityhardw00t/ai-security-arsenal105—~2.4kAutomated safety check: PassNone
Azure Kubernetesmicrosoft/GitHub-Copilot-for-Azure2551 repos~2.8kAutomated safety check: PassMIT
Agent Bom Scan InfraLeoYeAI/openclaw-master-skills2.2k—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Cloud Devops

    davila7/claude-code-templates

    Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.

    33k GitHub starsUsed in 4 repos~1.4k tokens
    DevOps & CloudAuto-check passed
  • Infrastructure

    microsoft/physical-ai-toolchain

    Official

    Deploy and manage Azure infrastructure for the Physical AI Toolchain including Terraform IaC, Kubernetes setup, GPU configuration, and network topology

    126 GitHub stars~1.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Iac Security

    hardw00t/ai-security-arsenal

    Infrastructure-as-Code security scanning router for Terraform, CloudFormation, Kubernetes manifests, Helm, ARM/Bicep.

    105 GitHub stars~2.4k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Azure Kubernetes

    microsoft/GitHub-Copilot-for-Azure

    Official

    Plan, create, and configure production-ready Azure Kubernetes Service (AKS) clusters.

    255 GitHub starsUsed in 1 repo~2.8k tokens
    DevOps & CloudAuto-check passed
  • Agent Bom Scan Infra

    LeoYeAI/openclaw-master-skills

    Scan infrastructure-as-code, cloud configurations, and find secrets.

    2.2k GitHub stars~1.5k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Operate Devops

    hashgraph-online/awesome-codex-plugins

    Plan and implement infrastructure, CI/CD, container, deployment, observability, and operational configuration changes with least privilege, staged validation, and rollback awareness.

    1.3k GitHub stars~618 tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from jonathan-vella/apex

All 39 skills in this repo
  • Apex Azure Diagnostics

    jonathan-vella/apex

    WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.

    217 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • ANALYSIS SKILL — Azure Policy discovery: effective assignments (incl.

    217 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Apex Context Management

    jonathan-vella/apex

    UTILITY SKILL — Two-mode context-window management. An agent skill from jonathan-vella/apex.

    217 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Apex Python Diagrams

    jonathan-vella/apex

    UTILITY SKILL — Python diagram generation for Azure architectures, WAF/cost/compliance charts, ERDs, swimlanes, timelines, and wireframes.

    217 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Apex Terraform Search Import

    jonathan-vella/apex

    WORKFLOW SKILL — Manual-only discovery and import of existing Azure resources into Terraform management.

    217 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Apex Vendor Prompting

    jonathan-vella/apex

    ANALYSIS SKILL — Manual-only audit of Anthropic Claude Opus 5.5 / Sonnet 5.5 and OpenAI GPT-6 / GPT-5.6 prompting guidance and APEX conventions.

    217 GitHub stars~2.7k tokensUpdated today
    Auto-check passed

Categories

Questions about Apex Azure Kubernetes

What does Apex Azure Kubernetes do?

ANALYSIS SKILL — Day-0 AKS design advice: Automatic vs Standard, networking, identity, observability, upgrades, node pools, autoscaling and Spot. Apex Azure Kubernetes is an agent skill from jonathan-vella/apex. ANALYSIS SKILL — Day-0 AKS design advice: Automatic vs Standard, networking, identity, observability, upgrades, node pools, autoscaling and Spot.

When should I use Apex Azure Kubernetes?

Apex Azure Kubernetes fits situations like: : AKS troubleshooting (apex-azure-diagnostics); iaC (05-IaC Planner.

How do I install Apex Azure Kubernetes in Claude Code?

Run `npx skills add jonathan-vella/apex --skill apex-azure-kubernetes -a claude-code`. Or copy the skill folder (.github/skills/apex-azure-kubernetes in jonathan-vella/apex) into .claude/skills/apex-azure-kubernetes in your project. Claude Code loads it when a task matches its description.

How do I install Apex Azure Kubernetes in Codex?

Run `npx skills add jonathan-vella/apex --skill apex-azure-kubernetes -a codex`. Or copy the skill folder (.github/skills/apex-azure-kubernetes in jonathan-vella/apex) into .agents/skills/apex-azure-kubernetes in your project. Codex loads it when a task matches its description.

Can I use Apex Azure Kubernetes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jonathan-vella/apex --skill apex-azure-kubernetes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/apex-azure-kubernetes, .gemini/skills/apex-azure-kubernetes, .github/skills/apex-azure-kubernetes and .opencode/skills/apex-azure-kubernetes in your project.

What does Apex Azure Kubernetes need to run?

Going by SKILL.md and its folder, Apex Azure Kubernetes needs the command-line tools its instructions call (az).

Does Apex Azure Kubernetes access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Apex Azure Kubernetes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Apex Azure Kubernetes use?

Apex Azure Kubernetes is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Apex Azure Kubernetes use?

About 2.1k tokens (SKILL.md is roughly 8.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.3k tokens, read only when the agent opens those files.

What are the alternatives to Apex Azure Kubernetes?

Skills that share tags, products or a category with Apex Azure Kubernetes: Cloud Devops (davila7/claude-code-templates, 33k stars), Infrastructure (microsoft/physical-ai-toolchain, 126 stars), Iac Security (hardw00t/ai-security-arsenal, 105 stars) and Azure Kubernetes (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Apex Azure Kubernetes?

jonathan-vella (a GitHub user) maintains it in jonathan-vella/apex, which has 217 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on October 10, 2026.

Source: jonathan-vella/apex on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.