# Azure Enterprise Infra Planner
> Diseña y aprovisiona infraestructura Azure de empresa desde la descripción de una carga: redes, identidad, seguridad, cumplimiento y topologías multi-recurso alineadas con el WAF. Genera Bicep o Terraform.
Fuente: https://skillsagentes.com/skills/microsoft/azure-skills/azure-enterprise-infra-planner
Markdown: https://skillsagentes.com/skills/microsoft/azure-skills/azure-enterprise-infra-planner.md
Repositorio: https://github.com/microsoft/azure-skills
Autor: microsoft
Licencia: MIT
Actualizado: hace 2 meses
Coste de contexto: 144 tok instalada, 907 tok al activarse, 31.5k tok con todos los archivos del bundle
Bundle: 40 archivos, 123 KB
Permisos que pide: ninguno declarado
## Instalación
Un skill son archivos markdown: los mismos archivos valen para cualquier agente y lo único que cambia es el directorio de destino, es decir la bandera `--agent`. Añade `-g` para instalarlo en todos los proyectos de la máquina.
```bash
# Claude Code
npx -y skills add microsoft/azure-skills --skill azure-enterprise-infra-planner --agent claude-code
# Cursor
npx -y skills add microsoft/azure-skills --skill azure-enterprise-infra-planner --agent cursor
# Codex
npx -y skills add microsoft/azure-skills --skill azure-enterprise-infra-planner --agent codex
# Gemini CLI
npx -y skills add microsoft/azure-skills --skill azure-enterprise-infra-planner --agent gemini
# Windsurf
npx -y skills add microsoft/azure-skills --skill azure-enterprise-infra-planner --agent windsurf
# Cline
npx -y skills add microsoft/azure-skills --skill azure-enterprise-infra-planner --agent cline
```
## Qué hace
- Diseña y aprovisiona infraestructura Azure de empresa a partir de la descripción de una carga de trabajo, alineada con el Well-Architected Framework.
- Cubre redes, identidad, seguridad, cumplimiento y topologías multi-recurso: VNets, subredes, firewalls, private endpoints y gateways VPN.
- Genera Bicep o Terraform directamente, sin pasar por azd, incluido despliegue a nivel de suscripción.
- Planifica recuperación ante desastres, failover y alta disponibilidad entre regiones.
## Cuándo usarla
- Se quiere planificar infraestructura Azure de empresa, una landing zone, una red hub-spoke o una topología multi-región.
- Se quiere planificar identidad, RBAC o infraestructura guiada por cumplimiento.
## Cuándo no
- Para flujos centrados en una aplicación: el archivo pide preferir `azure-prepare`.
## Qué la activa
- "diseña una landing zone"
- "planifica una red hub-spoke"
- "topología multi-región para DR"
- "genera el Bicep de esta arquitectura"
## Antes de instalar
- Usa herramientas MCP de insights, buenas prácticas, WAF y esquemas Bicep, más los CLI `az deployment`, `az bicep` y `terraform`.
## Archivos
- SKILL.md — 4 KB
- references/bicep-generation.md — 4 KB
- references/constraints/README.md — 1 KB
- references/constraints/ai-ml.md — 3 KB
- references/constraints/compute-apps.md — 8 KB
- references/constraints/compute-infra.md — 5 KB
- references/constraints/data-analytics.md — 6 KB
- references/constraints/data-relational.md — 5 KB
- references/constraints/messaging.md — 3 KB
- references/constraints/monitoring.md — 2 KB
- references/constraints/networking-connectivity.md — 6 KB
- references/constraints/networking-core.md — 7 KB
- references/constraints/networking-traffic.md — 5 KB
- references/constraints/security.md — 2 KB
- references/deployment.md — 4 KB
- references/pairing-checks.md — 4 KB
- references/phases/1-extract-insights.md — 2 KB
- references/phases/2-research-best-practices.md — 3 KB
- references/phases/3-research-resources.md — 3 KB
- references/phases/4-generate-plan.md — 792 B
- references/phases/5-verify.md — 814 B
- references/phases/6-generate-iac.md — 675 B
- references/phases/7-deploy.md — 1 KB
- references/resources/README.md — 2 KB
- references/resources/ai-ml.md — 2 KB
- references/resources/compute-apps.md — 4 KB
- references/resources/compute-infra.md — 3 KB
- references/resources/data-analytics.md — 3 KB
- references/resources/data-relational.md — 3 KB
- references/resources/messaging.md — 2 KB
- references/resources/monitoring.md — 1 KB
- references/resources/networking-connectivity.md — 4 KB
- references/resources/networking-core.md — 4 KB
- references/resources/networking-traffic.md — 3 KB
- references/resources/security.md — 1 KB
- references/schema.md — 3 KB
- references/terraform-generation.md — 3 KB
- references/verification.md — 3 KB
- references/waf-checklist.md — 2 KB
- references/workflow.md — 3 KB
## SKILL.md
Reproducido tal cual desde microsoft/azure-skills bajo MIT. Esta sección es el documento original y está en inglés.
# Azure Enterprise Infra Planner
## When to Use This Skill
Activate this skill when user wants to:
- Plan enterprise Azure infrastructure from a workload or architecture description
- Architect a landing zone, hub-spoke network, or multi-region topology
- Design networking infrastructure: VNets, subnets, firewalls, private endpoints, VPN gateways
- Plan identity, RBAC, and compliance-driven infrastructure
- Generate Bicep or Terraform for subscription-scope or multi-resource-group deployments
- Plan disaster recovery, failover, or cross-region high-availability topologies
## Quick Reference
| Property | Details |
|---|---|
| MCP tools | `insights_get`, `get_azure_bestpractices_get`, `wellarchitectedframework_serviceguide_get`, `microsoft_docs_fetch`, `microsoft_docs_search`, `bicepschema_get` |
| CLI commands | `az deployment group create`, `az bicep build`, `az resource list`, `terraform init`, `terraform plan`, `terraform validate`, `terraform apply`, `checkov` |
| Output schema | [schema.md](references/schema.md) |
| Key references | [workflow.md](references/workflow.md), [waf-checklist.md](references/waf-checklist.md), [resources/](references/resources/README.md), [constraints/](references/constraints/README.md) |
## Workflow (Start Here)
Follow the step-by-step instructions in [workflow.md](references/workflow.md) to execute the 7 phases of infrastructure planning and provisioning.
## Architecture
The skill runs a **7-phase, gated pipeline**. Input is triaged into one of two flows:
- **Greenfield** — only new requirements; run the phases straight through.
- **Referenced (brownfield)** — the user supplies something that already exists (a live resource /
resource group / subscription, IaC or an infra plan, or a requirements doc). The same phases run, plus
[referenced-workload.md](references/referenced-workload.md): existing resources are inventoried and
referenced (never recreated), the new workload is wired into them, and **Phase 7 deploys additively**
(incremental only — never modifying or destroying the referenced resources).
Every phase advances only after its gate passes. Phase 5 requires explicit user approval; **Phase 6 is a
hardened, self-verifying gate** — the generated IaC must be secure-by-default, pass local validation
(`az bicep build` / `terraform validate`) with zero errors, pass a `checkov` security scan with no
unresolved high/critical findings, and the skill must **show the command output** and emit a completion
self-check before advancing; Phase 7 requires an explicit, risk-acknowledged deploy confirmation.
```mermaid
flowchart TD
IN([Input]) --> TRIAGE{Existing infra
referenced?}
TRIAGE -- "No (greenfield)" --> P1
TRIAGE -- "Yes (referenced)" --> RW[/referenced-workload.md:
inventory + assign roles
reference, never recreate/]
RW --> P1
subgraph PIPE [7-phase gated pipeline]
direction TB
P1[Phase 1 · Extract insights] --> P2[Phase 2 · Research best practices]
P2 --> P3[Phase 3 · Research resources]
P3 --> P4[Phase 4 · Generate plan]
P4 --> P5{Phase 5 · Verify
user approves?}
P5 -- "no" --> P4
P5 -- "approved" --> P6[Phase 6 · Generate IaC]
P6 --> VAL{Validate
az bicep build /
terraform validate}
VAL -- "errors" --> P6
VAL -- "clean" --> P7{Phase 7 · Deploy
risk-ack confirm?}
end
P7 -- "greenfield" --> DEP[az deployment / terraform apply]
P7 -- "referenced" --> DEPADD[Additive deploy · incremental only
what-if preview · no destroy of
referenced resources]
DEP --> OUT([Deployed])
DEPADD --> OUT
classDef gate fill:#fff3cd,stroke:#d39e00,color:#000;
classDef ref fill:#e2f0d9,stroke:#548235,color:#000;
class P5,VAL,P7,TRIAGE gate;
class RW,DEPADD ref;
```
**Artifacts** (written under `/`): `.azure/insights.json` (Phase 1),
`.azure/infrastructure-plan.json` (Phase 4, status `draft`→`approved`→`deployed`), and
`infra/main.bicep` + `infra/modules/*` or `infra/main.tf` + `infra/modules/**` (Phase 6).
## MCP Tools
| Tool | Purpose |
|------|---------|
| `insights_get` | Retrieve insights about the user's existing Azure environment to guide planning decisions |
| `get_azure_bestpractices_get` | Azure best practices for code generation, operations, and deployment |
| `wellarchitectedframework_serviceguide_get` | WAF service guide for a specific Azure service |
| `microsoft_docs_search` | Search Microsoft Learn for relevant documentation chunks |
| `microsoft_docs_fetch` | Fetch full content of a Microsoft Learn page by URL |
| `bicepschema_get` | Bicep schema definition for any Azure resource type (latest API version) |
## Error Handling
| Error | Cause | Fix |
|---|---|---|
| MCP tool error or not available | Tool call timeout, connection error, or tool doesn't exist | Retry once; fall back to reference files and notify user if unresolved |
| Plan approval missing | `meta.status` is not `approved` | Stop and prompt user for approval before IaC generation or deployment |
| IaC validation failure | `az bicep build` or `terraform validate` returns errors | Fix the generated code and re-validate; notify user if unresolved |
| Pairing constraint violation | Incompatible SKU or resource combination | Fix in plan before proceeding to IaC generation |
| Infra plan or IaC files not found | Files written to wrong location or not created | Verify files exist at `/.azure/` and `/infra/`; if missing, re-create the files by following [workflow.md](references/workflow.md) exactly |
## Dónde encaja
- Categoría: [DevOps e infraestructura](https://skillsagentes.com/categorias/devops-infraestructura.md) — Despliegues, contenedores, IaC y flujos de gestión de incidentes.
- Creador: [microsoft](https://skillsagentes.com/creators/microsoft.md) — 43 skills en el directorio
- [Todas las skills](https://skillsagentes.com/skills.md)
- [Ranking de instalaciones](https://skillsagentes.com/ranking.md)
---
Skills Agentes · [Índice de páginas en markdown](https://skillsagentes.com/sitemap.md) · [Inicio](https://skillsagentes.com/index.md)