Azure diagnostics skill

Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage.

by microsoft·MIT license·★ 3,077 Stars on the repo·GitHub ↗

Use now

Files of Azure diagnostics

microsoft/main1 file shown
SKILL.md
Show the full text156 lines

Azure Diagnostics

AUTHORITATIVE GUIDANCE — MANDATORY COMPLIANCE

This document is the official source for debugging and troubleshooting Azure production issues. Follow these instructions to diagnose and resolve common Azure service problems systematically.

Triggers

Activate this skill when user wants to:

  • Debug or troubleshoot production issues
  • Diagnose errors in Azure services
  • Analyze application logs or metrics
  • Fix image pull, cold start, or health probe issues
  • Investigate why Azure resources are failing
  • Find root cause of application errors
  • Troubleshoot App Service issues (high CPU, deployment failures, crashes, slow responses, TLS/custom domains)
  • Respond to prompts like "troubleshoot app service", "app service high CPU", or "app service deployment failure"
  • Troubleshoot Azure Function Apps (invocation failures, timeouts, binding errors)
  • Find the App Insights or Log Analytics workspace linked to a Function App
  • Troubleshoot AKS clusters, nodes, pods, ingress, or Kubernetes networking issues
  • Troubleshoot Azure VM connectivity issues (RDP/SSH failures, port 3389/22 timeouts, NSG or firewall blocking, credential resets)
  • Troubleshoot Azure Messaging SDK issues (Event Hubs, Service Bus connection failures, AMQP errors, message lock issues)

Rules

  1. Start with systematic diagnosis flow
  2. Use AppLens (MCP) for AI-powered diagnostics when available
  3. Check resource health before deep-diving into logs
  4. Select appropriate troubleshooting guide based on service type
  5. Document findings and attempted remediation steps
  6. Route AKS incidents to the dedicated AKS troubleshooting document

Quick Diagnosis Flow

  1. Identify symptoms - What's failing?
  2. Check resource health - Is Azure healthy?
  3. Review logs - What do logs show?
  4. Analyze metrics - Performance patterns?
  5. Investigate recent changes - What changed?

Troubleshooting Guides by Service

Service Common Issues Reference
Container Apps Image pull failures, cold starts, health probes, port mismatches container-apps/
App Service High CPU, deployment failures, crashes, slow responses, TLS/custom domains app-service/
Function Apps App details, invocation failures, timeouts, binding errors, cold starts, missing app settings functions/
AKS Cluster access, nodes, kube-system, scheduling, crash loops, ingress, DNS, upgrades AKS Troubleshooting
Compute VM RDP/SSH connectivity, NSG/firewall blocks, credential resets, VM agent/tooling issues VM Connectivity Troubleshooting
Messaging Event Hubs & Service Bus SDK errors, AMQP failures, message lock, connectivity Messaging Troubleshooting

Routing

  • Keep Container Apps and Function Apps diagnostics in this parent skill.
  • Route active AKS incidents, AKS-specific intake, evidence gathering, and remediation guidance to AKS Troubleshooting.
  • Route Azure VM RDP/SSH connectivity, NSG/firewall, credential reset, and VM agent troubleshooting to VM Connectivity Troubleshooting.
  • Route Azure Messaging SDK troubleshooting (Event Hubs, Service Bus) to Messaging Troubleshooting.

Quick Reference

Common Diagnostic Commands
# Check resource health
az resource show --ids RESOURCE_ID
# View activity log
az monitor activity-log list -g RG --max-events 20
# Container Apps logs
az containerapp logs show --name APP -g RG --follow
# Function App logs (query App Insights traces)
az monitor app-insights query --apps APP-INSIGHTS -g RG \
  --analytics-query "traces | where timestamp > ago(1h) | order by timestamp desc | take 50"
AppLens (MCP Tools)

For AI-powered diagnostics, use:

mcp_azure_mcp_applens
  intent: "diagnose issues with <resource-name>"
  command: "diagnose"
  parameters:
    resourceId: "<resource-id>"

Provides:
- Automated issue detection
- Root cause analysis
- Remediation recommendations
Azure Monitor (MCP Tools)

For querying logs and metrics:

mcp_azure_mcp_monitor
  intent: "query logs for <resource-name>"
  command: "logs_query"
  parameters:
    workspaceId: "<workspace-id>"
    query: "<KQL-query>"

See kql-queries.md for common diagnostic queries.


Check Azure Resource Health

Using MCP
mcp_azure_mcp_resourcehealth
  intent: "check health status of <resource-name>"
  command: "get"
  parameters:
    resourceId: "<resource-id>"
Using CLI
# Check specific resource health
az resource show --ids RESOURCE_ID

# Check recent activity
az monitor activity-log list -g RG --max-events 20

References

1---
2name: azure-diagnostics
3description: "Debug Azure production issues on Azure using AppLens, Azure Monitor, resource health, and safe triage. WHEN: debug production issues, troubleshoot app service, app service high CPU, app service deployment failure, troubleshoot container apps, troubleshoot functions, troubleshoot AKS, VM RDP, Linux SSH, VM black screen, can't connect to VM, reset VM password, NSG or firewall blocking, kubectl cannot connect, kube-system/CoreDNS failures, pod pending, crashloop, node not ready, upgrade failures, analyze logs, KQL, insights, image pull failures, cold start issues, health probe failures, resource health, root cause of errors, troubleshoot event hubs, troubleshoot service bus, messaging SDK error, AMQP connection failure, message lock lost, service bus dead letter."
4license: MIT
5metadata:
6 author: Microsoft
7 version: "1.2.7"
8---
9 
10# Azure Diagnostics
11 
12> **AUTHORITATIVE GUIDANCE — MANDATORY COMPLIANCE**
13>
14> This document is the **official source** for debugging and troubleshooting Azure production issues. Follow these instructions to diagnose and resolve common Azure service problems systematically.
15 
16## Triggers
17 
18Activate this skill when user wants to:
19- Debug or troubleshoot production issues
20- Diagnose errors in Azure services
21- Analyze application logs or metrics
22- Fix image pull, cold start, or health probe issues
23- Investigate why Azure resources are failing
24- Find root cause of application errors
25- Troubleshoot App Service issues (high CPU, deployment failures, crashes, slow responses, TLS/custom domains)
26- Respond to prompts like "troubleshoot app service", "app service high CPU", or "app service deployment failure"
27- Troubleshoot Azure Function Apps (invocation failures, timeouts, binding errors)
28- Find the App Insights or Log Analytics workspace linked to a Function App
29- Troubleshoot AKS clusters, nodes, pods, ingress, or Kubernetes networking issues
30- Troubleshoot Azure VM connectivity issues (RDP/SSH failures, port 3389/22 timeouts, NSG or firewall blocking, credential resets)
31- Troubleshoot Azure Messaging SDK issues (Event Hubs, Service Bus connection failures, AMQP errors, message lock issues)
32 
33## Rules
34 
351. Start with systematic diagnosis flow
362. Use AppLens (MCP) for AI-powered diagnostics when available
373. Check resource health before deep-diving into logs
384. Select appropriate troubleshooting guide based on service type
395. Document findings and attempted remediation steps
406. Route AKS incidents to the dedicated AKS troubleshooting document
41 
42---
43 
44## Quick Diagnosis Flow
45 
461. **Identify symptoms** - What's failing?
472. **Check resource health** - Is Azure healthy?
483. **Review logs** - What do logs show?
494. **Analyze metrics** - Performance patterns?
505. **Investigate recent changes** - What changed?
51 
52---
53 
54## Troubleshooting Guides by Service
55 
56| Service | Common Issues | Reference |
57|---------|---------------|-----------|
58| **Container Apps** | Image pull failures, cold starts, health probes, port mismatches | [container-apps/](references/container-apps/README.md) |
59| **App Service** | High CPU, deployment failures, crashes, slow responses, TLS/custom domains | [app-service/](references/app-service/README.md) |
60| **Function Apps** | App details, invocation failures, timeouts, binding errors, cold starts, missing app settings | [functions/](references/functions/README.md) |
61| **AKS** | Cluster access, nodes, `kube-system`, scheduling, crash loops, ingress, DNS, upgrades | [AKS Troubleshooting](troubleshooting/aks/aks-troubleshooting.md) |
62| **Compute** | VM RDP/SSH connectivity, NSG/firewall blocks, credential resets, VM agent/tooling issues | [VM Connectivity Troubleshooting](troubleshooting/compute/vm-troubleshooting.md) |
63| **Messaging** | Event Hubs & Service Bus SDK errors, AMQP failures, message lock, connectivity | [Messaging Troubleshooting](troubleshooting/messaging/README.md) |
64 
65---
66 
67## Routing
68 
69- Keep Container Apps and Function Apps diagnostics in this parent skill.
70- Route active AKS incidents, AKS-specific intake, evidence gathering, and remediation guidance to [AKS Troubleshooting](troubleshooting/aks/aks-troubleshooting.md).
71- Route Azure VM RDP/SSH connectivity, NSG/firewall, credential reset, and VM agent troubleshooting to [VM Connectivity Troubleshooting](troubleshooting/compute/vm-troubleshooting.md).
72- Route Azure Messaging SDK troubleshooting (Event Hubs, Service Bus) to [Messaging Troubleshooting](troubleshooting/messaging/README.md).
73 
74---
75 
76## Quick Reference
77 
78### Common Diagnostic Commands
79 
80```bash
81# Check resource health
82az resource show --ids RESOURCE_ID
83# View activity log
84az monitor activity-log list -g RG --max-events 20
85# Container Apps logs
86az containerapp logs show --name APP -g RG --follow
87# Function App logs (query App Insights traces)
88az monitor app-insights query --apps APP-INSIGHTS -g RG \
89 --analytics-query "traces | where timestamp > ago(1h) | order by timestamp desc | take 50"
90```
91 
92### AppLens (MCP Tools)
93 
94For AI-powered diagnostics, use:
95```
96mcp_azure_mcp_applens
97 intent: "diagnose issues with <resource-name>"
98 command: "diagnose"
99 parameters:
100 resourceId: "<resource-id>"
101 
102Provides:
103- Automated issue detection
104- Root cause analysis
105- Remediation recommendations
106```
107 
108### Azure Monitor (MCP Tools)
109 
110For querying logs and metrics:
111```
112mcp_azure_mcp_monitor
113 intent: "query logs for <resource-name>"
114 command: "logs_query"
115 parameters:
116 workspaceId: "<workspace-id>"
117 query: "<KQL-query>"
118```
119 
120See [kql-queries.md](references/kql-queries.md) for common diagnostic queries.
121 
122---
123 
124## Check Azure Resource Health
125 
126### Using MCP
127 
128```
129mcp_azure_mcp_resourcehealth
130 intent: "check health status of <resource-name>"
131 command: "get"
132 parameters:
133 resourceId: "<resource-id>"
134```
135 
136### Using CLI
137 
138```bash
139# Check specific resource health
140az resource show --ids RESOURCE_ID
141 
142# Check recent activity
143az monitor activity-log list -g RG --max-events 20
144```
145 
146---
147 
148## References
149 
150- [KQL Query Library](references/kql-queries.md)
151- [Azure Resource Graph Queries](references/azure-resource-graph.md)
152- [App Service Troubleshooting](references/app-service/README.md)
153- [Function Apps Troubleshooting](references/functions/README.md)
154- [VM Connectivity Troubleshooting](troubleshooting/compute/vm-troubleshooting.md)
155- [Messaging Troubleshooting](troubleshooting/messaging/README.md)
156 

Discussion

Alternatives

Azure app onboardEnd-to-end orchestrator: from a business idea, app idea, or existing app to running Azure deployment with cost estimates and pre-deploy approval. Analyzes your app, auto-detects the right Azure services, scaffolds infrastructure code, and deploys — tailored to your app, not a template. Handles moving existing apps to Azure without rewriting or with minimal changes. WHEN: bring your app to Azure, plan my app, cost to run, is my code ready to deploy, deploy my app to the cloud, deploy all my services, what Azure services do I need, plan my Azure deployment, deploy my new app to Azure, one-click deploy, I have an app and want it on Azure, migrate my app to Azure, help me get started, build an app, no code yet, starter project. DO NOT USE FOR: use azd for deployment(use azure-deploy), optimizing existing costs (use cost-optimization), code readiness checks only (use azure-app-onboard-prereq).Infrastructure & ops · MITAzure App Onboard Prereq — Repository EvaluationAssess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work. Evaluates build health, app completeness, dependencies and local services, stack compatibility, and deployment feasibility. Answers questions about what your app needs before it can be deployed — frameworks, dependencies, and configuration. Checks whether dependencies are compatible and identifies deployment blockers and unsupported frameworks. WHEN: "evaluate my repo", "is my app ready to deploy", "what does my app need to deploy", "what do I need before deploying", "does my app need", "can I ship this to Azure", "scan my repo for issues", "is this app deployable", "check if my app is ready for Azure", "do I need a Dockerfile", "what's blocking my deployment", "are there any blockers", "are my dependencies compatible", "does Azure support my framework", "what needs to change before deploying", "check my app configuration".Infrastructure & ops · MITDocker MCP gatewayDocker's own CLI plugin: run any server from the Docker MCP Catalog in its own container, behind one connection, with secrets kept out of env vars.Coding · MITAzure cloud migrateAssess and migrate cross-cloud workloads to Azure with reports and code conversion. Supports Lambda→Functions, Beanstalk/Heroku/App Engine→App Service, Fargate/Kubernetes/Cloud Run/Spring Boot→Container Apps. WHEN: migrate Lambda to Functions, AWS to Azure, migrate Beanstalk, migrate Heroku, migrate App Engine, Cloud Run migration, Fargate to ACA, ECS/Kubernetes/GKE/EKS to Container Apps, Spring Boot to Container Apps, cross-cloud migration.Infrastructure & ops · MIT