Apex Azure Diagnostics
jonathan-vella/apex
WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.
Official agent skill
Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes-automatic-readiness -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kubernetes-automatic-readiness --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness .claude/skills/azure-kubernetes-automatic-readiness && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "azure-kubernetes-automatic-readiness" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness into .claude/skills/azure-kubernetes-automatic-readiness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kubernetes-automatic-readiness", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readinessType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes-automatic-readiness -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kubernetes-automatic-readiness --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness .agents/skills/azure-kubernetes-automatic-readiness && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "azure-kubernetes-automatic-readiness" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness into .agents/skills/azure-kubernetes-automatic-readiness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kubernetes-automatic-readiness", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes-automatic-readiness -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kubernetes-automatic-readiness --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness .cursor/skills/azure-kubernetes-automatic-readiness && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "azure-kubernetes-automatic-readiness" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness into .cursor/skills/azure-kubernetes-automatic-readiness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kubernetes-automatic-readiness", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft/GitHub-Copilot-for-Azure.git --path plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes-automatic-readiness -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kubernetes-automatic-readiness --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness .gemini/skills/azure-kubernetes-automatic-readiness && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "azure-kubernetes-automatic-readiness" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness into .gemini/skills/azure-kubernetes-automatic-readiness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kubernetes-automatic-readiness", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kubernetes-automatic-readinessInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes-automatic-readiness -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness .github/skills/azure-kubernetes-automatic-readiness && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "azure-kubernetes-automatic-readiness" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness into .github/skills/azure-kubernetes-automatic-readiness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kubernetes-automatic-readiness", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes-automatic-readiness -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-kubernetes-automatic-readiness --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness .opencode/skills/azure-kubernetes-automatic-readiness && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "azure-kubernetes-automatic-readiness" agent skill from https://github.com/microsoft/GitHub-Copilot-for-Azure/tree/main/plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness into .opencode/skills/azure-kubernetes-automatic-readiness/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "azure-kubernetes-automatic-readiness", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
azure-kubernetes-automatic-readinessAssess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.
Azure Kubernetes Automatic Readiness is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility. Identifies incompatibilities, generates fixes, and guides migration from AKS Standard to AKS Automatic. WHEN: migrate to AKS Automatic, check AKS Automatic readiness, validate manifests for Automatic, assess cluster for Automatic compatibility, fix deployment for Automatic compatibility, identify AKS Automatic migration blockers, is my cluster ready for AKS Automatic.
Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `references/common-fixes.md`, `references/constraint-spec-v1.yaml` and `references/mcp-integration.md`).
It sits in DevOps & Cloud, covering Container orchestration. It works with Kubernetes, Microsoft Azure and Model Context Protocol. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ce94fce. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/, which the agent can run.
Shell commands in SKILL.md call:
kubectljqazhelmFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
learn.microsoft.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Azure Kubernetes Automatic Readiness loads about 4.4k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 124 tokens; SKILL.md has 1,789 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from microsoft/GitHub-Copilot-for-Azure at commit ce94fce, republished under its MIT licence (© microsoft). 1,789 words, ~4,369 tokens.
.claude/skills/azure-kubernetes-automatic-readiness/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.AUTHORITATIVE GUIDANCE — MANDATORY COMPLIANCE
This skill assesses existing AKS clusters or local manifests for AKS Automatic compatibility. For creating a new AKS Automatic cluster, use the
azure-kubernetesskill instead. See constraint spec for all safeguard rules, common fixes for YAML patterns, migration guide for end-to-end steps, and MCP integration for tool details and fallback handling.
You are an AKS Automatic compatibility assessment agent. Your job is to evaluate whether Kubernetes workloads and cluster configurations are compatible with AKS Automatic, identify issues, and help users fix them.
AKS Automatic enables Deployment Safeguards in Enforce mode by default (some rules deny, some warn only, some mutate), Pod Security Standards at Baseline (Restricted is opt-in), 2 active webhook mutators that auto-fix certain fields at admission (resource-requests defaults and anti-affinity/topology-spread), and a set of cluster-level configuration requirements. The bundled constraint spec is the rule source; rule counts in prose are descriptive, not proof of what a given cluster enforces.
| Property | Value |
|---|---|
| Best for | AKS Automatic migration readiness and manifest validation |
| MCP Tools | Host-discovered Azure MCP AKS capability (mcp_azure_mcp_aks in GitHub Copilot) for cluster/node-pool reads; kubectl + jq for sanitized workload reads |
| Related skills | azure-kubernetes (cluster creation), azure-diagnostics (live troubleshooting), aks-troubleshooting (AKS-focused diagnosis when the aks-skills plugin is installed), azure-validate (readiness checks) |
azure-kubernetes instead:azure-diagnostics instead:kubectl apply, az aks update, or any command that changes the cluster.valueFrom.secretKeyRef, service account tokens, or connection strings.azure-kubernetes skill. Route live troubleshooting → azure-diagnostics skill.| Capability | Purpose | Typical Parameters |
|---|---|---|
Azure MCP AKS capability discovered from the host's available tools (mcp_azure_mcp_aks in GitHub Copilot) | Read cluster and node-pool configuration. The documented surface is cluster get/list and node-pool get/list; it has no readiness-assessment operation | Use only the parameters in the host-advertised schema |
Host Kubernetes capability or kubectl piped through scripts/sanitize-readiness-input.jq | Read allowlisted workload fields for local evaluation against the bundled constraint spec | Cluster context, resource kinds, namespaces |
Ask the user what they want to assess:
Option A — Cluster-connected assessment Use when the user has a connected cluster context (subscription + resource group + cluster name).
Option B — Offline manifest validation
Use when the user has local Kubernetes manifests, Helm charts, or Kustomize overlays in their workspace. Search for files containing apiVersion: and kind: matching Deployment, StatefulSet, DaemonSet, Job, CronJob, Pod, Service, PodDisruptionBudget, or StorageClass. For Helm charts, look for Chart.yaml and rendered templates under templates/.
Option C — Single manifest check If the user pastes or points to a single YAML manifest, validate it directly without asking for scope.
kubectl JSON through scripts/sanitize-readiness-input.jq (requires jq) before anything reaches the model. Never fetch Secret/ConfigMap resources or paste raw kubectl -o json. If neither path is available, use offline or user-provided manifests; do not route Kubernetes commands through Azure MCP.references/constraint-spec-v1.yaml.kubectl get constraints when reachable before reporting any conditionalSafeguards rule.# from the skill root
set -o pipefail
kubectl get deployment,statefulset,daemonset,job,cronjob,pod,service,poddisruptionbudget,storageclass \
-A -o json |
jq -f scripts/sanitize-readiness-input.jqCluster metadata:
1. Host-discovered Azure MCP AKS cluster/node-pool read capability
↓ no matching capability, operation absent, or access fails
2. Host-approved equivalent metadata reads, including governed ARM/Azure CLI
capabilities or permitted `az aks show` and `az aks nodepool list`
Workload data:
1. Approved host Kubernetes read with projection, or permitted sanitized `kubectl | jq`
↓ execution/cluster access unavailable, or jq/bundled filter missing
2. Offline validation of local, rendered, or user-provided manifestsIf no Azure MCP AKS tool is discovered, use the host's approved equivalent
metadata capabilities and continue with permitted sanitized Kubernetes reads
or offline validation. A local or external MCP server is not a prerequisite.
Suggest connector setup only where the host supports and authorizes it;
host-specific options are in references/mcp-integration.md. Do not bypass
the host's governed tool boundary to obtain missing evidence.
Load references/constraint-spec-v1.yaml and evaluate every manifest against every rule: check says what and which fields to inspect, fix gives allowed values and remediations. Suggest needed fixes.
Key checks: Per container (containers, initContainers, ephemeralContainers):
safeguard-container-resource-requestssafeguard-probes-configured (warning-only — not blocked at admission; treat as informational):latest → safeguard-images-no-latestsecurityContext.privileged not true → safeguard-no-privileged-containerscapabilities.add only adds allowed capabilities → safeguard-container-capabilitiesseccompProfile is RuntimeDefault/Localhost → safeguard-allowed-seccomp-profileshost field in probes and lifecycle hooks → safeguard-host-probes (advisory/unverified — not a documented Automatic block)Per pod spec:
hostPID/hostIPC not true → safeguard-block-host-namespaces (incompatible)hostNetwork/hostPort not true → safeguard-host-network-ports (incompatible)hostPath volumes → safeguard-no-host-path-volumes (incompatible)Conditional (conditionalSafeguards — report only when applicable, never as default blockers):
allowPrivilegeEscalation, run-as-non-root, allowed volume types → PSS Restricted opt-in only (Learn marks these "PSS Restricted Only")ContainerAdministrator → Windows node pools only, when the constraint is activePer workload type:
safeguard-pod-enforce-antiaffinitysafeguard-csi-driver-storage-class| Severity | Meaning | Action |
|---|---|---|
incompatible | Fundamental architecture issue; cannot run on Automatic without redesign | Must fix before migration — flag prominently |
requiresChanges | Manifest changes needed; will be denied at admission | Generate fix diffs |
autoFixed | AKS Automatic will mutate this at admission; no user action needed | Informational — show what will change |
informational | Warning-only, advisory, or not enforced on the default Automatic Baseline | Mention briefly; never list as a blocker |
conditional (enforcement: conditional) | Enforced only under PSS Restricted, on Windows nodes, or when the cluster's active constraints include it | Report with its appliesWhen condition; confirm with kubectl get constraints when possible |
Always start with the summary:
## AKS Automatic Readiness Assessment
| Status | Count |
|--------|-------|
| ✅ Compatible | X workloads |
| ⚠️ Requires changes | Y workloads |
| ❌ Incompatible | Z workloads |
| 🔧 Auto-fixed by Automatic | W workloads |
| 🏗️ Cluster config issues | N issues |Grouping: ≤ 10 issues → list individually; > 10 → group by constraint ID. Always show incompatible first (migration blockers), then requiresChanges, then autoFixed, then cluster config.
Per-issue format:
### ❌ [constraint-id] — Short description
**Severity:** incompatible | requiresChanges
**Affected:** namespace/resource-name (Kind)
**Current:** <what the manifest has>
**Required:** <what AKS Automatic requires>
**Fix:** <remediation summary>
**Docs:** <documentation URL>Deterministic fixes (the constraint rule and references/common-fixes.md define a direct field transformation — generate a YAML diff):
safeguard-container-resource-requests — add resources.requestssafeguard-container-capabilities — remove capabilities.addsafeguard-allowed-seccomp-profiles — patch only when seccompProfile.type: Unconfined is presentsafeguard-no-privilege-escalation — set allowPrivilegeEscalation: false (only when the conditional rule applies)safeguard-enforce-apparmor — add AppArmor annotationsafeguard-csi-driver-storage-class — replace in-tree provisionerUse patterns in references/common-fixes.md and generate a before/after diff. Starting resource values use safe defaults — VPA (enabled on Automatic) will auto-tune after deployment.
Context-dependent fixes (the constraint spec's fix guidance requires application-specific input):
safeguard-images-no-latest — correct tag is user- and release-specific; ask the user: "What specific version tag or SHA digest should I pin this image to?" Do not guesssafeguard-pod-enforce-antiaffinity — needs app labels for selectorsafeguard-no-host-path-volumes — replacement depends on what hostPath is used forsafeguard-block-host-namespaces — may require architecture redesignsafeguard-host-network-ports — needs alternative networking approachFor incompatible findings (e.g., hostPath volumes), explain the issue and propose alternatives. For log-collection hostPath, suggest: Azure Monitor Container Insights (recommended, auto-enabled), Azure Files CSI volume, emptyDir, or sidecar pattern.
Fix application flow:
If the user says "fix all" or "apply all deterministic fixes", first generate a single combined diff containing only the constraint rules with direct, context-independent transformations, show that combined diff with an explanation, and wait for one explicit approval before applying any writes. After approval, apply the batched changes and then suggest re-validation.
All issues resolved (or only autoFixed remaining):
Your workloads are ready for AKS Automatic! Next steps:
1. Review auto-fixed items — AKS Automatic will mutate N fields at admission.
2. Apply cluster configuration changes (see cluster config issues above).
3. Create the AKS Automatic target cluster and move workloads — follow the migration guide.
4. Verify — after migration, check all workloads are running and healthy.There is no documented in-place Standard → Automatic SKU switch; migration to Automatic is a new target cluster plus a workload move (the documented in-place path is Automatic → Standard, --sku base). See references/migration-guide-summary.md for supported journeys and the full checklist.
Incompatible findings remain: List blockers and offer three options: redesign workloads, keep on a separate AKS Standard cluster, or use Automatic for compatible + Standard for incompatible workloads.
Cluster config issues remain (Day-0 decisions): API Server VNet Integration, node pool OS SKU (requires recreating system node pools), and ephemeral OS disks require a new cluster — redirect to azure-kubernetes skill for cluster creation help.
| Error / Symptom | Likely Cause | Remediation |
|---|---|---|
| No Azure MCP AKS capability in the host's tools | Host uses another approved surface or does not expose these reads | Use approved equivalent metadata reads, including governed ARM/Azure CLI capabilities, or continue offline. Suggest a connector only if the host supports and authorizes setup |
| Discovered AKS capability has no readiness operation | Expected — the documented surface is cluster/node-pool reads only | Collect sanitized manifests via kubectl | jq and evaluate the bundled spec locally |
| Azure/Kubernetes read fails (401/403/404, no context) | Credentials, RBAC, scope, or wrong target | See references/mcp-integration.md (SRE Agent UAMI scope vs az login hosts); continue offline if unresolved |
jq or bundled sanitizer unavailable | Host cannot execute the sanitized pipeline | Use rendered manifests or an approved projecting host read. Install tools only where host policy and user authorization permit; never send raw cluster JSON to the model |
| Helm chart uses Go templating — cannot evaluate | Template values not resolved | Ask for helm template output or values files |
| Constraint spec version mismatch | Skill bundles spec v1.2.0 | Note version in output; recommend re-running after spec update |
| File | When to load |
|---|---|
references/constraint-spec-v1.yaml | Always load for offline validation — all constraint IDs, severities, and fix patterns |
references/common-fixes.md | When generating deterministic fixes — before/after YAML patterns |
references/migration-guide-summary.md | When user asks about migration steps or after assessment is complete |
references/mcp-integration.md | When discovering Azure MCP capabilities, wiring the sanitized kubectl read, or debugging the fallback chain |
scripts/sanitize-readiness-input.jq | Allowlist projection for kubectl -o json output before it reaches the model (requires jq) |
⚠️ Warning: This skill bundles constraint spec v1.2.0 (rules dated 2026-03-15, reconciled 2026-09 against the Learn Deployment Safeguards page, Azure Policy initiative c047ea8e v3.0.0, and the AKS Automatic SKU migration article). It lists 23 customer-facing cluster constraints, 21 Baseline-level Deployment Safeguards rules (one advisory/unverified), 4 conditional Restricted/Windows rules, and 2 active mutators. Always note the spec version in assessment output and verify live enforcement with
kubectl get constraintswhen a cluster is reachable.
© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 5 other files (scripts, references) in plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness of microsoft/GitHub-Copilot-for-Azure.
Open the folder on GitHubat commit ce94fce
We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.
Azure Kubernetes Automatic Readiness next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Azure Kubernetes Automatic Readiness this skillmicrosoft/GitHub-Copilot-for-Azure | 255 | 1 repos | ~4.4k | Automated safety check: Pass | MIT | |
| Apex Azure Diagnosticsjonathan-vella/apex | 217 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Install Boltmcpboltmcp/boltmcp | 371 | — | ~2.3k | Automated safety check: Pass | None | |
| K8s Agent Sandbox MCPkubernetes-sigs/agent-sandbox | 4.2k | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Provider Bug Reviewmondoohq/mql | 412 | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Aspire MonitoringCommunityToolkit/Aspire | 629 | — | ~3.5k | Automated safety check: Pass | MIT |
jonathan-vella/apex
WORKFLOW SKILL — Debug Azure production issues: Container Apps, Functions, App Service, AKS, VMs and messaging, with KQL log analysis.
boltmcp/boltmcp
A skill your agent uses when asked to help install or uninstall BoltMCP
kubernetes-sigs/agent-sandbox
An MCP server skill for managing Kubernetes sandboxes. An agent skill from kubernetes-sigs/agent-sandbox.
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
CommunityToolkit/Aspire
ANALYSIS SKILL - Observe Aspire apps: logs, traces, metrics, resource state, telemetry export, browser telemetry, and the standalone dashboard.
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
microsoft/GitHub-Copilot-for-Azure
Discovers available Azure OpenAI model capacity across regions and projects.
microsoft/GitHub-Copilot-for-Azure
Unified Azure OpenAI model deployment skill with intelligent intent-based routing.
microsoft/GitHub-Copilot-for-Azure
Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.
microsoft/GitHub-Copilot-for-Azure
Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.
microsoft/GitHub-Copilot-for-Azure
Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…
microsoft/GitHub-Copilot-for-Azure
Check/manage Azure quotas and usage across providers. An agent skill from microsoft/GitHub-Copilot-for-Azure.
Categories
Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility. Azure Kubernetes Automatic Readiness is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Assess Kubernetes workloads and cluster configuration for AKS Automatic compatibility.
Azure Kubernetes Automatic Readiness fits situations like: tasks that involve Container orchestration.
Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes-automatic-readiness -a claude-code`. Or copy the skill folder (plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/azure-kubernetes-automatic-readiness in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes-automatic-readiness -a codex`. Or copy the skill folder (plugins/azure-skills/skills/azure-kubernetes/azure-kubernetes-automatic-readiness in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/azure-kubernetes-automatic-readiness in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-kubernetes-automatic-readiness -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-kubernetes-automatic-readiness, .gemini/skills/azure-kubernetes-automatic-readiness, .github/skills/azure-kubernetes-automatic-readiness and .opencode/skills/azure-kubernetes-automatic-readiness in your project.
Going by SKILL.md and its folder, Azure Kubernetes Automatic Readiness needs the command-line tools its instructions call (kubectl, jq, az and helm).
SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Azure Kubernetes Automatic Readiness is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 4.4k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Azure Kubernetes Automatic Readiness: Apex Azure Diagnostics (jonathan-vella/apex, 217 stars), Install Boltmcp (boltmcp/boltmcp, 371 stars), K8s Agent Sandbox MCP (kubernetes-sigs/agent-sandbox, 4.2k stars) and Provider Bug Review (mondoohq/mql, 412 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 61 skills in this directory. The repository was last updated on October 9, 2026.
Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.