Official agent skill

Azure Kubernetes

by microsoft in microsoft/GitHub-Copilot-for-Azure

Plan, create, and configure production-ready Azure Kubernetes Service (AKS) clusters.

OfficialMITAuto-check passedDevOps & Cloud

Install Azure Kubernetes

skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kubernetes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-skills/skills/azure-kubernetes .claude/skills/azure-kubernetes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-kubernetes
GitHub stars
255
Used in
1 other repo
Token cost
~2.7k tokens
SKILL.md length
1,263 words
Files
7 (incl. references)
Skills in repo
56
Repo updated
First seen
Licence
MIT

At a glance

Plan, create, and configure production-ready Azure Kubernetes Service (AKS) clusters.

  • Works in 9 steps: Cluster Type → Networking (Pod IP, Egress, Ingress,… → Security → …
  • Tasks that involve Container orchestration
  • SKILL.md covers Quick Reference, When to Use This Skill, Rules and Required Inputs (Ask only…, plus 4 more sections
  • Calls az and kubectl

What it does

Azure Kubernetes is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Plan, create, and configure production-ready Azure Kubernetes Service (AKS) clusters. Covers Day-0 checklist, SKU selection (Automatic vs Standard), networking options (private API server, Azure CNI Overlay, egress configuration), security, and operations (autoscaling, upgrade strategy, cost analysis). WHEN: create AKS environment, provision AKS, enable AKS observability, design AKS networking, choose AKS SKU, secure AKS, optimize AKS, AKS spot nodes, AKS cluster-autoscaler, rightsize AKS pod, pod rightsizing…

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/azure-aks-autoscaler.md`, `references/azure-aks-rightsizing.md` and `references/azure-aks-spot.md`).

It sits in DevOps & Cloud, covering Container orchestration, Observability and Cloud cost optimization. It works with Microsoft Azure, Azure Kubernetes Service, Kubernetes and Model Context Protocol. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.

When your agent uses it

  • Tasks that involve Container orchestration
  • Tasks that involve Observability
  • Tasks that involve Cloud cost optimization

Example prompts

  • “/azure-kubernetes”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Cluster Type
  2. Networking (Pod IP, Egress, Ingress, Dataplane)
  3. Security
  4. Observability
  5. Upgrades & Patching
  6. Performance
  7. Node Pools & Compute
  8. Reliability
  9. Cost Controls

What it can do on your machine

Read from SKILL.md and the folder at commit d8f4f4e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az
    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Kubernetes loads about 2.7k tokens when it runs, and up to ~6.2k if it reads all its reference files. Until then it costs about 160 tokens; SKILL.md has 1,263 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~160
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/GitHub-Copilot-for-Azure at commit d8f4f4e, republished under its MIT licence (© microsoft). 1,263 words, ~2,723 tokens.

Download SKILL.mdSave it as .claude/skills/azure-kubernetes/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
azure-kubernetes
description
Plan, create, and configure production-ready Azure Kubernetes Service (AKS) clusters. Covers Day-0 checklist, SKU selection (Automatic vs Standard), networking options (private API server, Azure CNI Overlay, egress configuration), security, and operations (autoscaling, upgrade strategy, cost analysis). WHEN: create AKS environment, provision AKS, enable AKS observability, design AKS networking, choose AKS SKU, secure AKS, optimize AKS, AKS spot nodes, AKS cluster-autoscaler, rightsize AKS pod, pod rightsizing, over-provisioned AKS pod, pod resource requests and limits, Vertical Pod Autoscaler, VPA recommendations.
license
MIT
metadata.author
Microsoft
metadata.version
0.0.0-placeholder

Azure Kubernetes Service

AUTHORITATIVE GUIDANCE — MANDATORY COMPLIANCE

This skill produces a recommended AKS cluster configuration based on user requirements, distinguishing Day-0 decisions (networking, API server — hard to change later) from Day-1 features (can enable post-creation). See CLI reference for commands.

Quick Reference

PropertyValue
Best forAKS cluster planning and Day-0 decisions
MCP Toolsmcp_azure_mcp_aks
CLIaz aks create, az aks show, kubectl get, kubectl describe
Related skillsazure-kubernetes-app-deploy (deploy an app to an existing cluster), azure-diagnostics (troubleshooting AKS), azure-validate (readiness checks), azure-kubernetes-automatic-readiness (migrate existing cluster to AKS Automatic)

When to Use This Skill

Activate this skill when user wants to:

  • Create a new AKS cluster
  • Plan AKS cluster configuration for production workloads
  • Design AKS networking (API server access, pod IP model, egress)
  • Set up AKS identity and secrets management
  • Configure AKS governance (Azure Policy, Deployment Safeguards)
  • Enable AKS observability (Container Insights, Managed Prometheus, Grafana)
  • Define AKS upgrade and patching strategy
  • Understand AKS Automatic vs Standard SKU differences
  • Get a Day-0 checklist for AKS cluster setup and configuration

Deploying an application to an existing cluster? This skill provisions and configures the cluster. To containerize an app and deploy it to a cluster that already exists (Dockerfile + manifests + Deployment Safeguards), use the azure-kubernetes-app-deploy sub-skill instead.

Rules

  1. Start with the user's requirements for provisioning compute, networking, security, and other settings.
  2. Use the azure MCP server and select mcp_azure_mcp_aks first to discover the exact AKS-specific MCP tools surfaced by the client. Choose the smallest discovered AKS tool that fits the task, and fall back to Azure CLI (az aks) only when the needed functionality is not exposed through the AKS MCP surface.
  3. Determine if AKS Automatic or Standard SKU is more appropriate based on the user's need for control vs convenience. Default to AKS Automatic unless specific customizations are required.
  4. Document decisions and rationale for cluster configuration choices, especially for Day-0 decisions that are hard to change later (networking, API server access).

Required Inputs (Ask only what’s needed)

If the user is unsure, use safe defaults.

  • AKS environment type: dev/test or production
  • Region(s), availability zones, preferred node VM sizes
  • Expected scale (node/cluster count, workload size)
  • Networking requirements (API server access, pod IP model, ingress/egress control)
  • Security and identity requirements, including image registry
  • Upgrade and observability preferences
  • Cost constraints

Workflow

1. Cluster Type
  • AKS Automatic (default): Best for most production workloads, provides a curated experience with pre-configured best practices for security, reliability, and performance. Use unless you have specific custom requirements for networking, autoscaling, or node pool configurations not supported by Node Auto-Provisioning (NAP).
  • AKS Standard: Use if you need full control over environment configuration, which requires additional overhead to set up and manage.
2. Networking (Pod IP, Egress, Ingress, Dataplane)

Pod IP Model (Key Day-0 decision):

  • Azure CNI Overlay (recommended): pod IPs from private overlay range, not VNet-routable, scales to large environments and good for most workloads
  • Azure CNI (VNet-routable): pod IPs directly from VNet (pod subnet or node subnet), use when pods must be directly addressable from VNet or on-prem

Dataplane & Network Policy:

  • Azure CNI powered by Cilium (recommended): eBPF-based for high-performance packet processing, network policies, and observability

Egress:

  • Static Egress Gateway for stable, predictable outbound IPs
  • For restricted egress: UDR + Azure Firewall or NVA

Ingress:

  • App Routing addon with Gateway API — recommended default for HTTP/HTTPS workloads
  • Istio service mesh with Gateway API - for advanced traffic management, mTLS, canary releases
  • Application Gateway for Containers — for L7 load balancing with WAF integration

DNS:

  • Enable LocalDNS on all node pools for reliable, performant DNS resolution
3. Security
  • Use Microsoft Entra ID everywhere (control plane, Workload Identity for pods, node access). Avoid static credentials.
  • Azure Key Vault via Secrets Store CSI Driver for secrets
  • Enable Azure Policy + Deployment Safeguards
  • Enable Encryption at rest for etcd/API server; in-transit for node-to-node
  • Allow only signed, policy-approved images (Azure Policy + Ratify), prefer Azure Container Registry
  • Isolation: Use namespaces, network policies, scoped logging
4. Observability
  • Use Managed Prometheus and Container Insights with Grafana for AKS observability (logs + metrics).
  • Enable Diagnostic Settings to collect control plane logs and audit logs in a Log Analytics workspace for security monitoring and troubleshooting.
  • For other monitoring and troubleshooting tools, use features like the Agentic CLI for AKS, Application Insights, Resource Health Center, AppLens detectors, and Azure Advisors.
5. Upgrades & Patching
  • Configure Maintenance Windows for controlled upgrade timing
  • Enable auto-upgrades for control plane and node OS to stay up-to-date with security patches and Kubernetes versions
  • Consider LTS versions for enterprise stability (2-year support) by upgrading your AKS environment to the Premium tier
  • Fleet upgrades: Use AKS Fleet Manager for staged rollout across test to production environments
Show full SKILL.md (496 more words)Show less
6. Performance
  • Use Ephemeral OS disks (--node-osdisk-type Ephemeral) for faster node startup
  • Select Azure Linux as node OS (smaller footprint, faster boot)
  • Enable KEDA for event-driven autoscaling beyond HPA
7. Node Pools & Compute
  • Dedicated system node pool: At least 2 nodes, tainted for system workloads only (CriticalAddonsOnly)
  • Enable Node Auto Provisioning (NAP) on all pools for cost savings and responsive scaling
  • Use latest generation SKUs (v5/v6) for host-level optimizations
  • Avoid B-series VMs — burstable SKUs cause performance/reliability issues
  • Use SKUs with at least 4 vCPUs for production workloads
  • Set topology spread constraints to distribute pods across hosts/zones per SLO
8. Reliability
  • Deploy across 3 Availability Zones (--zones 1 2 3)
  • Use Standard tier for zone-redundant control plane + 99.95% SLA for API server availability
  • Enable Microsoft Defender for Containers for runtime protection
  • Configure PodDisruptionBudgets for all production workloads
  • Use topology spread constraints to ensure pod distribution across failure domains
9. Cost Controls
  • Use Spot node pools for batch/interruptible workloads (up to 90% savings)
  • Stop/Start dev/test clusters: az aks stop/start
  • Consider Reserved Instances or Savings Plans for steady-state workloads

Deep-dive scenarios — load only the relevant reference file:

ScenarioTrigger KeywordsReference
Pod Rightsizingover-provisioned pods, CPU requests, memory requests, rightsize workloadsazure-aks-rightsizing.md
VPA Setupvertical pod autoscaler, VPA recommendations, VPA enableazure-aks-vpa.md
Cluster Autoscaleridle nodes, CAS off, enable autoscaler, scale-down profile, node utilizationazure-aks-autoscaler.md
Spot Node PoolsSpot VMs, Spot nodes, batch workloads, cheaper nodesazure-aks-spot.md

Disambiguation: If a prompt matches multiple rows (e.g., "cheaper nodes" could suggest both Spot and autoscaler), prefer the most specific match. If ambiguous, ask the user to clarify their intent before loading a reference file.

Guardrails / Safety

  • Do not request or output secrets (tokens, keys).
  • Do not ask the user to paste subscription IDs. Discover subscription and resource scope via MCP tools (e.g., list subscriptions, list resource groups) or az account show / az account list so the agent can resolve context without exposing identifiers.
  • If requirements are ambiguous for day-0 critical decisions, ask the user clarifying questions. For day-1 enabled features, propose 2–3 safe options with tradeoffs and choose a conservative default.
  • Do not promise zero downtime; advise workload safeguards (PDBs, probes, replicas) and staged upgrades along with best practices for reliability and performance.

MCP Tools

ToolPurposeKey Parameters
mcp_azure_mcp_aksAKS MCP entry point used to discover the exact AKS-specific tools exposed by the clientDiscover the callable AKS tool first, then use that tool's parameters

Error Handling

Error / SymptomLikely CauseRemediation
MCP tool call fails or times outInvalid credentials, subscription, or AKS contextVerify az login, confirm the active subscription context with az account show, and check the target resource group without echoing subscription identifiers back to the user
Quota exceededRegional vCPU or resource limitsRequest quota increase or select different region/VM SKU
Networking conflict (IP exhaustion)Pod subnet too small for overlay/CNIRe-plan IP ranges; may require cluster recreation (Day-0)
Workload Identity not workingMissing OIDC issuer or federated credentialEnable --enable-oidc-issuer --enable-workload-identity, configure federated identity

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in plugins/azure-skills/skills/azure-kubernetes of microsoft/GitHub-Copilot-for-Azure.

  • SKILL.md
  • references/azure-aks-autoscaler.md
  • references/azure-aks-rightsizing.md
  • references/azure-aks-spot.md
  • references/azure-aks-vpa.md
  • references/cli-reference.md
  • version.json

Open the folder on GitHubat commit d8f4f4e

Used in 3 other repositories

We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Azure Kubernetes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Kubernetes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Kubernetes this skillmicrosoft/GitHub-Copilot-for-Azure2551 repos~2.7kAutomated safety check: PassMIT
Eks Cost Intelligenceaws-samples/appmod-blueprints113—~3.8kAutomated safety check: WarnMIT-0
Apex Azure Diagnosticsjonathan-vella/apex217—~2.1kAutomated safety check: PassMIT
Aks Deployment Skilltimothywarner/chatgptclass143—~916Automated safety check: PassCustom licence
Environment Deploymentmicrosoft/physical-ai-toolchain122—~5.8kAutomated safety check: PassMIT
Cloud Devopsdavila7/claude-code-templates32k4 repos~1.4kAutomated safety check: PassMIT

Similar skills

  • Eks Cost Intelligence

    aws-samples/appmod-blueprints

    Official

    Run a live EKS cluster cost efficiency assessment — analyze spending across 6 dimensions (compute efficiency, Spot/Graviton adoption, networking, storage, observability, idle resources), calculate a…

    113 GitHub stars~3.8k tokensUpdated today
    DevOps & CloudAuto-check: warnings
  • Apex Azure Diagnostics

    jonathan-vella/apex

    WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.

    217 GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Aks Deployment Skill

    timothywarner/chatgptclass

    Deploy and operate workloads on Azure Kubernetes Service (AKS) the safe way.

    143 GitHub stars~916 tokensUpdated 17 days ago
    DevOps & CloudAuto-check passed
  • Environment Deployment

    microsoft/physical-ai-toolchain

    Official

    Generate, transfer, and consume environment-specific Azure, AKS, OSMO, ACR, and Azure ML deployment bundles.

    122 GitHub stars~5.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloud Devops

    davila7/claude-code-templates

    Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.

    32k GitHub starsUsed in 4 repos~1.4k tokens
    DevOps & CloudAuto-check passed
  • Infrastructure

    microsoft/physical-ai-toolchain

    Official

    Deploy and manage Azure infrastructure for the Physical AI Toolchain including Terraform IaC, Kubernetes setup, GPU configuration, and network topology

    122 GitHub stars~1.6k tokensUpdated today
    DevOps & CloudAuto-check passed

More from microsoft/GitHub-Copilot-for-Azure

All 56 skills in this repo
  • Capacity

    microsoft/GitHub-Copilot-for-Azure

    Official

    Discovers available Azure OpenAI model capacity across regions and projects.

    255 GitHub starsUsed in 2 repos~1.7k tokens
    Auto-check passed
  • Deploy Model

    microsoft/GitHub-Copilot-for-Azure

    Official

    Unified Azure OpenAI model deployment skill with intelligent intent-based routing.

    255 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 3 repos~4k tokens
    Auto-check passed
  • Microsoft Foundry

    microsoft/GitHub-Copilot-for-Azure

    Official

    Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.

    255 GitHub starsUsed in 1 repo~6.7k tokens
    Auto-check passed
  • Azure Storage

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Azure Diagnostics

    microsoft/GitHub-Copilot-for-Azure

    Official

    Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage.

    255 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed

Categories

Questions about Azure Kubernetes

What does Azure Kubernetes do?

Plan, create, and configure production-ready Azure Kubernetes Service (AKS) clusters. Azure Kubernetes is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Plan, create, and configure production-ready Azure Kubernetes Service (AKS) clusters.

When should I use Azure Kubernetes?

Azure Kubernetes fits situations like: tasks that involve Container orchestration; tasks that involve Observability; tasks that involve Cloud cost optimization.

How do I install Azure Kubernetes in Claude Code?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes -a claude-code`. Or copy the skill folder (plugins/azure-skills/skills/azure-kubernetes in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/azure-kubernetes in your project. Claude Code loads it when a task matches its description.

How do I install Azure Kubernetes in Codex?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes -a codex`. Or copy the skill folder (plugins/azure-skills/skills/azure-kubernetes in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/azure-kubernetes in your project. Codex loads it when a task matches its description.

Can I use Azure Kubernetes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-kubernetes, .gemini/skills/azure-kubernetes, .github/skills/azure-kubernetes and .opencode/skills/azure-kubernetes in your project.

What does Azure Kubernetes need to run?

Going by SKILL.md and its folder, Azure Kubernetes needs the command-line tools its instructions call (az and kubectl).

Does Azure Kubernetes access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Azure Kubernetes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Kubernetes use?

Azure Kubernetes is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Kubernetes use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.5k tokens, read only when the agent opens those files.

What are the alternatives to Azure Kubernetes?

Skills that share tags, products or a category with Azure Kubernetes: Eks Cost Intelligence (aws-samples/appmod-blueprints, 113 stars), Apex Azure Diagnostics (jonathan-vella/apex, 217 stars), Aks Deployment Skill (timothywarner/chatgptclass, 143 stars) and Environment Deployment (microsoft/physical-ai-toolchain, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Kubernetes?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 56 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.