Best for
- Import existing Azure resources into Terraform
- Generate IaC from live Azure environments
- Handle any Azure resource type supported by AVM (and document justified non-AVM fallbacks)
github/awesome-copilot/skills/import-infrastructure-as-code/SKILL.md
Import existing Azure resources into Terraform using Azure CLI discovery and Azure Verified Modules (AVM). Use when asked to reverse-engineer live Azure infrastructure, generate Infrastructure as Code from existing subscriptions/resource groups/resource IDs, map dependencies, derive exact import addresses from downloaded module source, prevent configuration drift, and produce AVM-based Terraform files ready for validation and planning across any Azure resource type.
Decision brief
Convert existing Azure infrastructure into maintainable Terraform code using discovery data and Azure Verified Modules.
Compatibility matrix
| Platform | Status | Evidence | What to check |
|---|---|---|---|
| Codex | Not declared | No explicit evidence | Portability before use |
| Claude Code | Not declared | No explicit evidence | Portability before use |
| Cursor | Not declared | No explicit evidence | Portability before use |
| Gemini CLI | Not declared | No explicit evidence | Portability before use |
Installation
The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.
npx skills add https://github.com/github/awesome-copilot --skill "skills/import-infrastructure-as-code"Inspect the Agent Skill "import-infrastructure-as-code" from https://github.com/github/awesome-copilot/blob/9933dcad5be5caeb288cebcd370eeeb2fc2f1685/skills/import-infrastructure-as-code/SKILL.md at commit 9933dcad5be5caeb288cebcd370eeeb2fc2f1685. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.
Workflow
Request one of these scopes before running discovery commands:
This reveals whether the module uses azurerm or azapiresource labels. For example, avm-res-network-virtualnetwork exposes azapiresource "vnet", not azurermvirtualnetwork "this".
If child resources are managed in a sub-module (subnets, extensions, etc.), the import address must include every intermediate module label:
Any resource using count requires an index in the import address. When count = 1 (e.g., conditional Linux vs Windows selection), the address must end with [0]. Resources using foreach use string keys, not numeric indexes.
Use this skill when the user asks to:
Permission review
The documentation asks the agent to create, modify, or delete local files.
IMPORTANT: Generate the following documentation and save it to a docs folder in the root of the project.The documentation includes network, browsing, or remote request actions.
https://raw.githubusercontent.com/Azure/terraform-azurerm-avm-res-<service>-<resource>/refs/heads/main/README.mdThe documentation asks the agent to run terminal commands or scripts.
| Discovery output is empty | Incorrect scope or no resources in scope | Re-check scope input and run scoped list/show command again |The documentation asks the agent to read local files, directories, or repositories.
| Tool tries to read ARM resource ID as file path or asks repeated scope questions | Resource ID not treated as `--ids` input, or agent did not trust already-provided scope | Treat ARM IDs strictly as cloud identifiers, use `az ... --ids ..Evidence record
| Signal | Value | Evidence type | Meaning |
|---|---|---|---|
| Quality score | 95/100 | Computed | Documentation, specificity, maintenance, and trust rules |
| Repository stars | 37,126 | Source | Repository attention, not individual Skill quality |
| Compatibility | 0 platforms | Source | Declared in the catalog source record |
| Usage guide | automated source guide | Editorial | Generated or reviewed according to the visible evidence level |
Pinned source
Convert existing Azure infrastructure into maintainable Terraform code using discovery data and Azure Verified Modules.
Use this skill when the user asks to:
azurerm_* resourcesaz login)| Parameter | Required | Default | Description |
|---|---|---|---|
subscription-id | No | Active CLI context | Azure subscription used for subscription-scope discovery and context setting |
resource-group-name | No | None | Azure resource group used for resource-group-scope discovery |
resource-id | No | None | One or more Azure ARM resource IDs used for specific-resource-scope discovery |
At least one of subscription-id, resource-group-name, or resource-id is required.
Request one of these scopes before running discovery commands:
<subscription-id><resource-group-name><resource-id> valuesScope handling rules:
/subscriptions/.../providers/...) as cloud resource identifiers, not local file system paths.--ids arguments (for example az resource show --ids <resource-id>).cat, ls, read_file, glob searches) unless the user explicitly says they are local file paths.If scope is missing, ask for it explicitly and stop.
Run only the commands required for the selected scope.
For subscription scope:
az login
az account set --subscription <subscription-id>
az account show --query "{subscriptionId:id, name:name, tenantId:tenantId}" -o json
Expected output: JSON object with subscriptionId, name, and tenantId.
For resource group or specific resource scope, az login is still required but az account set is optional if the active context is already correct.
When using specific resource scope, prefer direct --ids-based commands first and avoid extra discovery prompts for subscription or resource group unless needed for a concrete command.
Discover resources using the selected scopes. Ensure to fetch all necessary information for accurate Terraform generation.
# Subscription scope
az resource list --subscription <subscription-id> -o json
# Resource group scope
az resource list --resource-group <resource-group-name> -o json
# Specific resource scope
az resource show --ids <resource-id-1> <resource-id-2> ... -o json
Expected output: JSON object or array containing Azure resource metadata (id, type, name, location, tags, properties).
Parse exported JSON and map:
propertiesIMPORTANT: Generate the following documentation and save it to a docs folder in the root of the project.
exported-resources.json with all discovered resources and their metadata, including dependencies and references.EXPORTED-ARCHITECTURE.MD file with a human-readable architecture overview based on the discovered resources and their relationships.Use the latest AVM version for each resource type.
Note: The following links always point to the latest version of the CSV files on the main branch. As intended, this means the files may change over time. If you require a point-in-time version, consider using a specific release tag in the URL.
https://raw.githubusercontent.com/Azure/Azure-Verified-Modules/refs/heads/main/docs/static/module-indexes/TerraformResourceModules.csvhttps://raw.githubusercontent.com/Azure/Azure-Verified-Modules/refs/heads/main/docs/static/module-indexes/TerraformPatternModules.csvhttps://raw.githubusercontent.com/Azure/Azure-Verified-Modules/refs/heads/main/docs/static/module-indexes/TerraformUtilityModules.csvUse the web tool or another suitable MCP method to get module information if not available locally in the .terraform folder.
Use AVM sources:
https://registry.terraform.io/modules/Azure/<module>/azurerm/latesthttps://github.com/Azure/terraform-azurerm-avm-res-<service>-<resource>Prefer AVM modules over handwritten azurerm_* resources when an AVM module exists.
When fetching module information from GitHub repositories, the README.md file in the root of the repository typically contains all detailed information about the module, for example: https://raw.githubusercontent.com/Azure/terraform-azurerm-avm-res--/refs/heads/main/README.md
This step is not optional. Before writing a single line of HCL for a module, fetch and
read the full README for that module. Do not rely on knowledge of the raw azurerm provider
or prior experience with other AVM modules.
For each selected AVM module, fetch its README:
https://raw.githubusercontent.com/Azure/terraform-azurerm-avm-res-<service>-<resource>/refs/heads/main/README.md
Or if the module is already downloaded after terraform init:
cat .terraform/modules/<module_key>/README.md
From the README, extract and record before writing code:
type.
Do not assume they match the raw azurerm provider argument names or block shapes.parent_id vs
resource_group_name), how child resources are expressed (inline map vs separate module),
and what syntax each input expects.Use the lessons below as examples of the type of mismatch that often causes imports to fail.
Do not assume these exact names apply to every AVM module. Always verify each selected module's
README and variables.tf.
avm-res-compute-virtualmachine (any version)
network_interfaces is a Required Input. NICs are owned by the VM module. Never
create standalone avm-res-network-networkinterface modules alongside a VM module —
define every NIC inline under network_interfaces.secure_boot_enabled = true
and vtpm_enabled = true. The security_type argument exists only under os_disk for
Confidential VM disk encryption and must not be used for TrustedLaunch.boot_diagnostics is a bool, not an object. Use boot_diagnostics = true; use the
separate boot_diagnostics_storage_account_uri variable if a storage URI is needed.extensions map. Do not create
standalone extension resources.avm-res-network-virtualnetwork (any version)
azurerm. Use parent_id (the full
resource group resource ID string) to specify the resource group, not resource_group_name.parent_id; none show resource_group_name.Generalized takeaway for all AVM modules:
variables.tf.azurerm_* resources.After terraform init downloads the modules, inspect each module's source files to determine
the exact Terraform resource addresses before writing any import {} blocks. Never write
import addresses from memory.
grep "^resource" .terraform/modules/<module_key>/main*.tf
This reveals whether the module uses azurerm_* or azapi_resource labels. For example,
avm-res-network-virtualnetwork exposes azapi_resource "vnet", not
azurerm_virtual_network "this".
grep "^module" .terraform/modules/<module_key>/main*.tf
If child resources are managed in a sub-module (subnets, extensions, etc.), the import address must include every intermediate module label:
module.<root_module_key>.module.<child_module_key>["<map_key>"].<resource_type>.<label>[<index>]
count vs for_eachgrep -n "count\|for_each" .terraform/modules/<module_key>/main*.tf
Any resource using count requires an index in the import address. When count = 1 (e.g.,
conditional Linux vs Windows selection), the address must end with [0]. Resources using
for_each use string keys, not numeric indexes.
These are examples only. Use them as templates for reasoning, then derive the exact addresses from the downloaded source code for the modules in your current import.
| Resource | Correct import to address pattern |
|---|---|
| AzAPI-backed VNet | module.<vnet_key>.azapi_resource.vnet |
| Subnet (nested, count-based) | module.<vnet_key>.module.subnet["<subnet_name>"].azapi_resource.subnet[0] |
| Linux VM (count-based) | module.<vm_key>.azurerm_linux_virtual_machine.this[0] |
| VM NIC | module.<vm_key>.azurerm_network_interface.virtualmachine_network_interfaces["<nic_key>"] |
| VM extension (default deploy_sequence=5) | module.<vm_key>.module.extension["<ext_name>"].azurerm_virtual_machine_extension.this |
| VM extension (deploy_sequence=1–4) | module.<vm_key>.module.extension_<n>["<ext_name>"].azurerm_virtual_machine_extension.this |
| NSG-NIC association | module.<vm_key>.azurerm_network_interface_security_group_association.this["<nic_key>-<nsg_key>"] |
Produce:
providers.tf with azurerm provider and required version constraintsmain.tf with AVM module blocks and explicit dependenciesvariables.tf for environment-specific valuesoutputs.tf for key IDs and endpointsterraform.tfvars.example with placeholder valuesAfter writing the initial configuration, compare every non-zero property of each discovered
live resource against the default value declared in the corresponding AVM module's
variables.tf. Any property where the live value differs from the module default must be
set explicitly in the Terraform configuration.
Pay particular attention to the following property categories, which are common sources of silent configuration drift:
idle_timeout_in_minutes defaults to 4; live
deployments often use 30)private_endpoint_network_policies defaults to
"Enabled"; existing subnets often have "Disabled")sku, allocation_method)Retrieve full live properties with explicit az commands, for example:
az network public-ip show --ids <resource_id> --query "{idleTimeout:idleTimeoutInMinutes, sku:sku.name, zones:zones}" -o json
az network vnet subnet show --ids <resource_id> --query "{privateEndpointPolicies:privateEndpointNetworkPolicies, delegation:delegations}" -o json
Do not rely solely on az resource list output, which may omit nested or computed properties.
Pin module versions explicitly:
module "example" {
source = "Azure/<module>/azurerm"
version = "<latest-compatible-version>"
}
Run:
terraform init
terraform fmt -recursive
terraform validate
terraform plan
Expected output: no syntax errors, no validation errors, and a plan that matches discovered infrastructure intent.
| Problem | Likely Cause | Action |
|---|---|---|
az command fails with authorization errors | Wrong tenant/subscription or missing RBAC role | Re-run az login, verify subscription context, confirm required permissions |
| Discovery output is empty | Incorrect scope or no resources in scope | Re-check scope input and run scoped list/show command again |
| No AVM module found for a resource type | Resource type not yet covered by AVM | Use native azurerm_* resource for that type and document the gap |
terraform validate fails | Missing variables or unresolved dependencies | Add required variables and explicit dependencies, then re-run validation |
| Unknown argument or variable not found in module | AVM variable name differs from azurerm provider argument name | Read the module README variables.tf or Optional Inputs section for the correct name |
| Import block fails — resource not found at address | Wrong provider label (azurerm_ vs azapi_), missing sub-module path, or missing [0] index | Run grep "^resource" .terraform/modules/<key>/main*.tf and grep "^module" to find exact address |
terraform plan shows unexpected ~ update on imported resource | Live value differs from AVM module default | Fetch live property with az <resource> show, compare to module default, add explicit value |
| Child-resource module gives "provider configuration not present" | Child resources declared as standalone modules even though parent module owns them | Check Required Inputs in README, remove incorrect standalone modules, and model child resources using the parent module's documented input structure |
| Nested child resource import fails with "resource not found" | Missing intermediate module path, wrong map key, or missing index | Inspect module blocks and count/for_each in source; build full nested import address including all module segments and required key/index |
| Tool tries to read ARM resource ID as file path or asks repeated scope questions | Resource ID not treated as --ids input, or agent did not trust already-provided scope | Treat ARM IDs strictly as cloud identifiers, use az ... --ids ..., and stop re-prompting once one valid scope is present |
When returning results, provide:
parent_id vs
resource_group_name). Skipping the README is the single most common cause of
code errors in AVM-based imports.terraform init, grep the downloaded
module source to discover the actual provider (azurerm vs azapi), resource labels,
sub-module nesting, and count vs for_each usage before writing any import {} block.--ids
arguments and API queries, not file IO tools. Only read local files when a real workspace
path is provided.terraform plan shows 0 destroys and 0
unwanted changes. Telemetry + create resources are acceptable. Any ~ update or
- destroy on real infrastructure resources must be resolved.Alternatives
K-Dense-AI/scientific-agent-skills
Use when working directly with the `esm` Python SDK, ESM3 or ESMC model IDs, Forge/Biohub inference clients, or ESMFold2 folding workflows.
event4u-app/agent-config
ONLY when user asks for single-pass tech-stack detection or `agents/evidence/analysis/` write-up. Deep multi-pass audit → `universal-project-analysis`. Raw primitives → `project-analysis-core`.
event4u-app/agent-config
Use when creating or rewriting a README for a reusable package or library. Focus on installability, minimal usage example, compatibility, and developer onboarding.
Jeffallan/claude-skills
Use when building high-performance async Python APIs with FastAPI and Pydantic V2. Invoke to create REST endpoints, define Pydantic models, implement authentication flows, set up async SQLAlchemy database operations, add JWT authentication, build WebSocket endpoints, or generate OpenAPI documentation. Trigger terms: FastAPI, Pydantic, async Python, Python API, REST API Python, SQLAlchemy async, JWT authentication, OpenAPI, Swagger Python.