azure-kubernetes by microsoft/azure-skills
npx skills add https://github.com/microsoft/azure-skills --skill azure-kubernetes权威指南 — 必须遵守
此技能根据用户需求生成推荐的 AKS 集群配置,区分第 0 天决策(网络、API 服务器 — 后期难以更改)和第 1 天功能(可在创建后启用)。有关命令,请参阅 CLI 参考。
| 属性 | 值 |
|---|---|
| 最适合 | AKS 集群规划和第 0 天决策 |
| MCP 工具 | mcp_azure_mcp_aks |
| CLI | az aks create, az aks show, kubectl get, |
广告位招租
在这里展示您的产品或服务
触达数万 AI 开发者,精准高效
kubectl describe| 相关技能 | azure-diagnostics (AKS 故障排除), azure-validate (就绪性检查) |
当用户希望执行以下操作时,请激活此技能:
azure MCP 服务器并首先选择 mcp_azure_mcp_aks 来发现客户端暴露的精确 AKS 特定 MCP 工具。选择适合任务的最小已发现 AKS 工具,仅当所需功能未通过 AKS MCP 接口暴露时,才回退到 Azure CLI (az aks)。如果用户不确定,请使用安全的默认值。
Pod IP 模型(关键的第 0 天决策):
数据平面和网络策略:
出口:
入口:
DNS:
--node-osdisk-type Ephemeral) 以加快节点启动速度CriticalAddonsOnly)--zones 1 2 3)az aks stop/start| 工具 | 用途 | 关键参数 |
|---|---|---|
mcp_azure_mcp_aks | AKS MCP 入口点,用于发现客户端暴露的精确 AKS 特定工具 | 首先发现可调用的 AKS 工具,然后使用该工具的参数 |
| 错误 / 症状 | 可能原因 | 补救措施 |
|---|---|---|
| MCP 工具调用失败或超时 | 凭据、订阅或 AKS 上下文无效 | 验证 az login,使用 az account show 确认活动订阅上下文,并检查目标资源组,而不向用户回显订阅标识符 |
| 配额超出 | 区域 vCPU 或资源限制 | 请求增加配额或选择不同的区域/VM SKU |
| 网络冲突(IP 耗尽) | Pod 子网对于覆盖网络/CNI 太小 | 重新规划 IP 范围;可能需要重新创建集群(第 0 天) |
| 工作负载身份无效 | 缺少 OIDC 颁发者或联合凭据 | 启用 --enable-oidc-issuer --enable-workload-identity,配置联合身份 |
每周安装量
3.1K
仓库
GitHub 星标数
528
首次出现
1 天前
安全审计
安装于
github-copilot3.1K
gemini-cli7
deepagents7
antigravity7
codex7
warp7
AUTHORITATIVE GUIDANCE — MANDATORY COMPLIANCE
This skill produces a recommended AKS cluster configuration based on user requirements, distinguishing Day-0 decisions (networking, API server — hard to change later) from Day-1 features (can enable post-creation). See CLI reference for commands.
| Property | Value |
|---|---|
| Best for | AKS cluster planning and Day-0 decisions |
| MCP Tools | mcp_azure_mcp_aks |
| CLI | az aks create, az aks show, kubectl get, kubectl describe |
| Related skills | azure-diagnostics (troubleshooting AKS), azure-validate (readiness checks) |
Activate this skill when user wants to:
azure MCP server and select mcp_azure_mcp_aks first to discover the exact AKS-specific MCP tools surfaced by the client. Choose the smallest discovered AKS tool that fits the task, and fall back to Azure CLI (az aks) only when the needed functionality is not exposed through the AKS MCP surface.If the user is unsure, use safe defaults.
Pod IP Model (Key Day-0 decision):
Dataplane & Network Policy:
Egress :
Ingress :
DNS :
--node-osdisk-type Ephemeral) for faster node startupCriticalAddonsOnly)--zones 1 2 3)az aks stop/start| Tool | Purpose | Key Parameters |
|---|---|---|
mcp_azure_mcp_aks | AKS MCP entry point used to discover the exact AKS-specific tools exposed by the client | Discover the callable AKS tool first, then use that tool's parameters |
| Error / Symptom | Likely Cause | Remediation |
|---|---|---|
| MCP tool call fails or times out | Invalid credentials, subscription, or AKS context | Verify az login, confirm the active subscription context with az account show, and check the target resource group without echoing subscription identifiers back to the user |
| Quota exceeded | Regional vCPU or resource limits | Request quota increase or select different region/VM SKU |
| Networking conflict (IP exhaustion) | Pod subnet too small for overlay/CNI | Re-plan IP ranges; may require cluster recreation (Day-0) |
| Workload Identity not working | Missing OIDC issuer or federated credential | Enable --enable-oidc-issuer --enable-workload-identity, configure federated identity |
Weekly Installs
3.1K
Repository
GitHub Stars
528
First Seen
1 day ago
Security Audits
Gen Agent Trust HubPassSocketPassSnykPass
Installed on
github-copilot3.1K
gemini-cli7
deepagents7
antigravity7
codex7
warp7
Azure 升级评估与自动化工具 - 轻松迁移 Functions 计划、托管层级和 SKU
59,200 周安装