azure-toolkit
Design and operate Azure the way a Cloud Architect does. The default move is PaaS-first: prefer the managed service that removes undifferentiated heavy lifting, so a virtual machine you patch becomes the last resort. The hard part is choosing the most managed option that still meets the constraint, modeling identity through Microsoft Entra ID, scoping the RBAC assignment, containing the blast radius behind private networking, and proving the control before an auditor or an attacker finds it.
This skill is advisory and authors IaC by default. A provision, apply, az deploy, or portal change is an external mutation that runs only behind a reviewed plan and explicit, recorded approval, never freehand from a step here.
Climb the determinism ladder: express a rule as an Azure CLI command, an Azure Policy assignment, or a deny rule in a landing zone before you write it as prose, and turn a checklist into a lint or policy-as-code gate. Judgment takes the last rung.
Steps
-
State the workload and its bar. Write what the workload must do, its traffic and state shape, its data classification, the environment (production carries the higher bar), and the compliance regime in scope. The constraints recorded here are what every later managed-service choice is measured against. This step is done when the workload, its data classification, and its environment are written down.
-
Choose the most managed service that meets the constraint. Walk the compute and data decisions through the managed-first reference: App Service or Container Apps or Functions before AKS before a VM for compute; Azure SQL Database or Cosmos DB before a self-managed engine for data; Service Bus, Storage, Event Grid, and Logic Apps for the glue. Reach for a VM or a self-managed engine only where a recorded constraint from step 1 rules the managed option out. This step is done when each compute and data component names its chosen service, and each self-managed choice names the constraint that forced it.
-
Apply the five Well-Architected pillars. Take a named stance on reliability, security, cost optimization, operational excellence, and performance efficiency, per the Well-Architected reference. A pillar with no stance counts as a gap. This step is done when each of the five pillars carries a written stance for this workload.
-
Lay the identity and governance baseline. Authenticate every compute resource through a managed identity, never a secret. Scope each RBAC assignment to the narrowest built-in role at the narrowest scope and keep secrets in Key Vault. The workload sits under its landing-zone management group with Azure Policy guardrails, per the governance-and-identity reference. This step is done when no role assignment grants
Ownerat subscription scope to a non-human principal, no secret or connection string sits in code or config, and each data resource declares private-endpoint-only access. -
Author as IaC and attach cost controls. Express every resource in Bicep or Terraform with pinned versions and remote, locked state, and keep the portal out of the change path: click-ops leaves no diff for a reviewer to read. Set an Azure budget with an alert and apply the mandatory tag set, then pull the cost levers (right-size, reservations or savings plans, deallocate idle, schedule non-production off) named in the Well-Architected cost section. This step is done when
bicep buildorterraform validatepasses clean, the budget alert exists, and every resource carries the required tags. -
Review against Well-Architected and the red flags. Check the design against each pillar's failure modes and the governance red flags: public storage,
Owner-everywhere RBAC, secrets in app settings, no diagnostic logs, a VM where a managed service fits, click-ops, per the governance-and-identity reference. Run a policy-as-code scan over the IaC withcheckov,tfsec, ortrivy config, so a misconfiguration red flag surfaces from a deterministic scanner. This step is done when the scan reports no unaddressed HIGH finding and each remaining red flag is marked absent or recorded as an accepted risk with a named owner.