Communitygithub.com

bg-szy/TOP-SKILLS

Fill out Microsoft Azure Landing Zone (ALZ) Accelerator checklists by interviewing the user, mapping their Azure subscriptions, integrating IP addressing documentation, and applying Microsoft Cloud Adoption Framework best practices. Produces a completed Excel checklist (.xlsx) ready for ALZ deployment. Use this skill whenever the user mentions Azure Landing Zone, ALZ checklist, landing zone accelerator, platform landing zone configuration, ALZ bootstrap, hub-and-spoke setup, Azure network topology planning, or wants to fill out any ALZ-related checklist or configuration file. Also trigger when the user uploads an Excel file that contains tabs like "Accelerator - Bootstrap", "Accelerator - Bicep", or "Accelerator - Terraform".

¿Qué es TOP-SKILLS?

TOP-SKILLS is a Claude Code agent skill that fill out Microsoft Azure Landing Zone (ALZ) Accelerator checklists by interviewing the user, mapping their Azure subscriptions, integrating IP addressing documentation, and applying Microsoft Cloud Adoption Framework best practices. Produces a completed Excel checklist (.xlsx) ready for ALZ deployment. Use this skill whenever the user mentions Azure Landing Zone, ALZ checklist, landing zone accelerator, platform landing zone configuration, ALZ bootstrap, hub-and-spoke setup, Azure network topology planning, or wants to fill out any ALZ-related checklist or configuration file. Also trigger when the user uploads an Excel file that contains tabs like "Accelerator - Bootstrap", "Accelerator - Bicep", or "Accelerator - Terraform".

Compatible con~Claude Code~Codex CLI~Cursor
npx skills add https://github.com/bg-szy/TOP-SKILLS/tree/HEAD/skills/claude-code-skills/azure-landing-zone-checklist

Preguntar en tu IA favorita

Abre un nuevo chat con esta habilidad de agente ya precargada.

Documentación

Azure Landing Zone Checklist Skill

This skill guides you through filling out the Microsoft Azure Landing Zone (ALZ) Accelerator checklist — the spreadsheet that captures all decisions needed before deploying an ALZ using Bicep or Terraform via the ALZ Accelerator tool.

The goal is to produce a filled Excel checklist where every decision is justified, best practices are applied by default, and items requiring human input are clearly flagged for the user's attention.

Why this matters

The ALZ Accelerator checklist is the single source of truth for a platform landing zone deployment. Getting it wrong means misconfigured networking, security gaps, or hours of rework. This skill ensures consistency by applying Microsoft's Cloud Adoption Framework (CAF) recommendations while respecting the user's existing infrastructure (IP ranges, subscriptions, naming conventions).

Workflow

Phase 1: Read the checklist

Read the uploaded .xlsx checklist using openpyxl to understand its structure. ALZ checklists typically have three tabs:

  • Accelerator - Bootstrap: IaC type, VCS, subscriptions, naming, CI/CD settings
  • Accelerator - Bicep: Scenario selection, component toggles, IP addressing, policies
  • Accelerator - Terraform: Same as Bicep with additional options (AMBA, Sovereign LZ)

Parse the checklist to identify which fields already have values (column F = "Chosen Value") and which are empty. This tells you what the user has already decided vs. what needs input.

Phase 2: Interview the user

Gather decisions through structured questions. Ask in batches of 3-4 questions to avoid overwhelming the user. Prioritize in this order:

Batch 1 — Foundational decisions:

  • IaC type (Bicep or Terraform)
  • Version control system (Azure DevOps, GitHub, or local)
  • Network topology scenario (Hub & Spoke vs vWAN, single vs multi-region, Azure Firewall vs NVA)
  • Azure region

Batch 2 — Component decisions:

  • Which components to deploy (DDoS, Private DNS, Bastion, VPN Gateway, ExpressRoute, Zero Trust)
  • Security posture (AMA, Defender plans)

Batch 3 — Environment-specific details:

  • Azure DevOps / GitHub organization and project names
  • Subscription IDs (Management, Connectivity, Identity, Security)
  • Pipeline approvers
  • IP addressing (ask if they have existing documentation)

When the user says "use best practices" or defers a decision, apply the recommendations from references/alz-best-practices.md. Always explain why a recommendation is made — users trust recommendations they understand.

Phase 3: Map subscriptions

If the user provides a subscription list (from az account list or similar), map subscriptions to ALZ roles by matching naming patterns:

PatternALZ Role
*mgmt*, *management*Management
*connectivity*, *network*, *hub*Connectivity
*identity*, *ad*, *entra*Identity
*security*, *sentinel*, *defender*Security

If a required subscription is missing (commonly Security), flag it with a yellow highlight and a comment explaining the options:

  1. Create a dedicated subscription (recommended)
  2. Share with Management subscription (budget-constrained alternative)

Phase 4: Integrate IP addressing

If the user provides IP documentation (Markdown, CSV, Excel, or text), parse it to extract:

  • Subscription-level CIDR blocks — map to ALZ hub/spoke VNets
  • Existing hub VNet layout — identify subnet allocations (Gateway, Firewall, Bastion, shared services)
  • On-premises public IPs — include in comments for VPN/firewall rule reference
  • AKS networking — pod/service CIDRs if applicable

For the ALZ hub VNet, recommend this subnet layout using the connectivity subscription's CIDR block:

Hub VNet: <connectivity-base>/16
  GatewaySubnet:                <base>.0.0/27     (30 hosts)
  AzureFirewallSubnet:          <base>.0.64/26    (62 hosts)
  AzureFirewallManagementSubnet:<base>.0.128/26   (62 hosts)
  AzureBastionSubnet:           <base>.0.192/26   (62 hosts)
  Shared Services:              <base>.1.0/24     (254 hosts)
  DNS Resolver Inbound:         <base>.2.0/28
  DNS Resolver Outbound:        <base>.2.16/28

If no IP documentation is provided, use ALZ defaults and flag for review.

Phase 5: Fill the checklist

Use openpyxl to write values into column F ("Chosen Value") of the appropriate tabs. Apply consistent formatting:

from openpyxl.styles import Font, PatternFill, Alignment
from openpyxl.comments import Comment

# Confirmed values — green background
green_fill = PatternFill('solid', fgColor='CCE5CC')

# Items needing user action — yellow background + red bold text
yellow_fill = PatternFill('solid', fgColor='FFFF00')
action_font = Font(bold=True, color='FF0000', size=10)

# Informational notes — italic yellow background
note_fill = PatternFill('solid', fgColor='FFFFCC')
note_font = Font(italic=True, size=10)

For every cell you fill:

  • Add a Comment explaining the rationale or best practice reference
  • Use green fill for confirmed decisions
  • Use yellow fill + red text for items requiring user action (e.g., "TO BE DEFINED", "TO BE PROVIDED")
  • Use light yellow fill + italic for items using defaults that the user should review

Tab-specific logic:

Only fill the tab matching the user's IaC choice. Clear the other tab if it had values from a previous attempt. For the active tab:

  1. Scenarios section: Set the chosen scenario to "Yes", all others to "No". Highlight the selected one with a brighter green.
  2. Options section: Apply the user's component choices. For any option not explicitly discussed, apply best practice defaults and note this in the comment.
  3. Bootstrap tab: Always fill regardless of IaC choice — it's shared.

Phase 6: Present results

After saving the filled checklist:

  1. Print a summary table showing all filled values
  2. List the items flagged for user action (yellow highlights)
  3. Call out any architectural considerations (e.g., cross-region peering needed if ALZ region differs from existing infrastructure)
  4. Provide the file link for download

Best practice recommendations

Read references/alz-best-practices.md for the full set of recommendations. The key defaults to apply when the user defers:

  • Private networking: true (state storage should never be publicly accessible)
  • Separate CI/CD template repo: true (security boundary between code and pipeline definitions)
  • Branch policies: true (require PRs for all changes)
  • Self-hosted agents/runners: true (required for private networking)
  • DDoS Protection: Yes (network-layer protection for all VNet resources)
  • Private DNS Zones: Yes (required for Private Endpoints across hub-spoke)
  • Azure Bastion: Yes (secure VM access without public IP exposure)
  • AMA (Azure Monitoring Agent): Keep enabled (centralized monitoring)
  • Defender plans: Keep enabled (threat detection across all resource types)
  • Zero Trust: Yes (least-privilege access and micro-segmentation)
  • AMBA alerts (Terraform only): Yes (proactive monitoring of platform resources)
  • Sovereign Landing Zone: No (unless explicitly required for compliance)

Cross-region considerations

If the user's existing infrastructure is in a different region than the ALZ deployment, flag this in the Bootstrap tab's region comment. They'll need to plan for cross-region VNet peering between the ALZ hub and any existing hub-spoke topology.

Cell Reference Map

The checklist has a fixed structure. Use these exact cell references when writing values to avoid row-offset bugs. Always verify by checking that column B (Name) matches the expected field before writing to column F.

Bootstrap Tab (Accelerator - Bootstrap)

RowCellField (col B)Config Setting (col D)
4F4Infrastructure as Codeiac_type
5F5Version control systembootstrap_module_name
6F6Starter modulestarter_module_name
8F8Bootstrap resource regionbootstrap_location
9F9Parent management group idroot_parent_management_group_id
10F10Management subscription idsubscription_id_management
11F11Connectivity subscription idsubscription_id_connectivity
12F12Identity subscription idsubscription_id_identity
13F13Security subscription idsubscription_id_identity (note: template typo)
15F15Bootstrap subscription idbootstrap_subscription_id
16F16Resource naming: service nameservice_name
17F17Resource naming: environment nameenvironment_name
18F18Resource naming: postfix numberpostfix_number
21F21Use separate repository for templatesuse_separate_repository_for_templates
22F22Use private networkinguse_private_networking
23F23Allow storage access from my IPallow_storage_access_from_my_ip
24F24Apply approversapply_approvers
25F25Create branch policiescreate_branch_policies
28F28Azure DevOps PATazure_devops_personal_access_token
29F29Azure DevOps Agent PATazure_devops_agents_personal_access_token
30F30Azure DevOps Organizationazure_devops_organization_name
31F31Azure DevOps legacy urlazure_devops_use_organisation_legacy_url
32F32Create Azure DevOps Projectazure_devops_create_project
33F33Azure DevOps Projectazure_devops_project_name
34F34Use self hosted agentsuse_self_hosted_agents

Note: Rows 7, 14, 19, 20, 26, 27, 35, 36, 41 are blank or section headers — skip them.

Bicep Tab (Accelerator - Bicep) — Scenarios

RowCellScenario
6F6Multi-Region Hub & Spoke + Azure Firewall
7F7Multi-Region vWAN + Azure Firewall
8F8Multi-Region Hub & Spoke + NVA
9F9Multi-Region vWAN + NVA
10F10Management Groups, Policy and Management Only
11F11Single-Region Hub & Spoke + Azure Firewall
12F12Single-Region vWAN + Azure Firewall
13F13Single-Region Hub & Spoke + NVA
14F14Single-Region vWAN + NVA

Bicep Tab — Options (rows 17-30)

RowCellOption
17F17Resource naming convention
18F18Custom management group names
19F19Deploy DDOS Protection Plan
20F20Deploy Private DNS
21F21Deploy Bastion Host
22F22Deploy VPN Gateway
23F23Deploy ExpressRoute Gateway
24F24Deploy to more than 2 regions
25F25IP Addressing
26F26Change a policy assignment enforcement mode
27F27Remove a policy assignment
28F28Turn off Azure Monitoring Agent
29F29Turn off Defender Plans
30F30Zero Trust Security

Terraform Tab (Accelerator - Terraform)

Same scenario layout as Bicep (rows 6-14). Options are rows 17-32:

RowCellOption
17F17Resource naming convention
18F18Custom management group names
19F19Deploy DDOS Protection Plan
20F20Deploy Private DNS
21F21Deploy Bastion Host
22F22Deploy VPN Gateway
23F23Deploy ExpressRoute Gateway
24F24Deploy to more than 2 regions
25F25IP Addressing
26F26Change a policy assignment enforcement mode
27F27Remove a policy assignment
28F28Turn off Azure Monitoring Agent
29F29Deploy Azure Monitoring Baseline Alerts (AMBA)
30F30Turn off Defender Plans
31F31Zero Trust Security
32F32Sovereign Landing Zone

Validation approach: Before writing any value, read cell B{row} and verify it matches the expected field name. If it doesn't match, scan the sheet to find the correct row. This prevents silent data corruption from template version differences.

Output format

The final deliverable is an .xlsx file with:

  • All three tabs preserved from the original template
  • Column F filled with chosen values
  • Cell comments with rationale and best practice references
  • Color coding: green (confirmed), yellow (needs action), light yellow (defaults to review)
  • A clear summary in the conversation listing all decisions and flagged items

Gotchas

  • openpyxl row indices are 1-based — off-by-one bugs corrupt the wrong row silently; verify with cell.value read-back before commit.
  • Subscription regex matching breaks on non-standard naming (e.g., sub-xyz-platform-mgmt) — fall back to enumeration when pattern fails.
  • Cross-region considerations: VNet peering across regions costs egress traffic; default ALZ template doesn't price this.
  • Excel checkboxes vs cell values: openpyxl can't write checkbox state — use cell value "✓" + named range to indicate checked.
  • Subscription quota propagation: requested quota increases show as "Approved" before the quota is actually applied — verify with az vm list-usage.

Individual skills in this repo

This repo contains 20 individual skills — each has its own dedicated page.

bg-szy/TOP-SKILLS

Brand-first landing page designer — runs a brand-identity interview (colors, typography, shape language), then generates and iterates on a polished landing page via Stitch with deployment-ready HTML. Use when the user asks to create, design, or build a landing page, homepage, or marketing page and has no established visual direction. Skip when they have a design mockup, need a dashboard or app UI, are working at component level, building a multi-page app, or restyling with known design tokens — use frontend-design instead.

bg-szy/TOP-SKILLS

Compose a premium, animated landing page section by section in Next.js + Tailwind + Motion (Framer Motion) — built on a real design system, with editorial copy and motion that feels human-crafted, not template-generated. Use when building or rebuilding a landing page, marketing site, or hero/feature/pricing/CTA sections that need to look production-ready and bespoke from day one.

bg-szy/TOP-SKILLS

Write high-converting landing page copy using proven frameworks like PAS (Problem-Agitate-Solution), AIDA, and StoryBrand. Creates headlines, value propositions, CTAs, and full page sections optimized for conversion. Use when users need landing page copy, sales page content, or marketing website text.

bg-szy/TOP-SKILLS

Optimize landing pages for conversions, performance, and SEO. Use when improving landing pages, increasing conversions, or optimizing page performance.

bg-szy/TOP-SKILLS

Beads Viewer - Graph-aware triage engine for Beads projects. Computes PageRank, betweenness, critical path, and cycles. Use --robot-* flags for AI agents.

bg-szy/TOP-SKILLS

CI red? Call us. Pipeline fire brigade deploys. Use when user mentions CI failures, build errors, test failures, or pipeline issues. Do NOT load for: local builds, standard implementation work, reviews, or setup.

bg-szy/TOP-SKILLS

CASS Memory System - procedural memory for AI coding agents. Three-layer cognitive architecture with confidence decay, anti-pattern learning, cross-agent knowledge transfer, trauma guard safety system. Bun/TypeScript CLI.

bg-szy/TOP-SKILLS

Use when the user asks to "pre-launch check the landing page", "run a Quality-Score preflight", or "verify ad-to-page message match before launch"; produces an ad↔page continuity report — message-match gaps, above-the-fold check, page-speed read, form-friction count, mobile-render flags — as a pass/fix punch list. Not for redesigning or rewriting the page — use landing-optimizer; not for scoring the account or the RQS — use ad-account-auditor. 落地页体验预检/广告落地页一致性检查

bg-szy/TOP-SKILLS

Use when the user asks to "optimize our landing page for influencer traffic", "fix our promo-code landing page", or "improve conversion from a creator campaign"; produces a message-match audit, page-structure and social-proof recommendations, a promo-code/CTA conversion plan, and an A/B test roadmap. Not for measuring campaign results after launch — use performance-analyzer.

bg-szy/TOP-SKILLS

Audit a landing page, sales page or checkout page for conversion leaks and return a fix list ordered by expected revenue impact. Use when asked to review, critique or improve a landing page, sales page, opt-in page, product page or checkout flow, when conversion rate is low, when paid traffic is not converting, or when someone asks "why isn't this page converting" or wants a CRO / landing page review.

bg-szy/TOP-SKILLS

Landing page conversion optimization with layout rules, hero section design, and CTA psychology. Covers above-the-fold formula, social proof placement, mobile design, and F-pattern reading. Use for: startup landing pages, product pages, SaaS marketing, conversion optimization. Triggers: landing page, hero section, above the fold, conversion optimization, landing page design, cta button, hero image, landing page layout, saas landing page, product page design, conversion rate, landing page best practices

bg-szy/TOP-SKILLS

Create high-converting, visually distinctive landing pages. Use when building marketing pages, product launches, SaaS homepages, or any single-page conversion-focused website. Guides section-by-section composition with anti-AI-slop principles.

bg-szy/TOP-SKILLS

Landing page conversion optimization with layout rules, hero section design, and CTA psychology. Covers above-the-fold formula, social proof placement, mobile design, and F-pattern reading. Use for: startup landing pages, product pages, SaaS marketing, conversion optimization. Triggers: landing page, hero section, above the fold, conversion optimization, landing page design, cta button, hero image, landing page layout, saas landing page, product page design, conversion rate, landing page best practices

bg-szy/TOP-SKILLS

Process video files with audio extraction, format conversion (mp4, webm), and Whisper transcription. Use when user mentions video conversion, audio extraction, transcription, mp4, webm, ffmpeg, or whisper transcription.

bg-szy/TOP-SKILLS

Using the Wonda CLI to generate images, videos, music, and audio from the terminal — plus LinkedIn, Reddit, and X/Twitter research and automation

bg-szy/TOP-SKILLS

Sets up and runs AFL++ for multi-core fuzzing of C/C++ projects built with afl-clang-fast or afl-gcc-fast. Covers instrumentation modes, parallel main and secondary campaigns, persistent mode, corpus minimization, and crash triage. Use when scaling fuzzing across cores, fuzzing a mature C/C++ codebase, reading the afl-fuzz status screen, or moving on after libFuzzer has plateaued.

bg-szy/TOP-SKILLS

>- Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "build codeql database", "SAST scan", "taint analysis", "dataflow analysis", or "find vulnerabilities in this repo". Covers Python, JavaScript/TypeScript, Go, Java/Kotlin, C/C++, C#, Ruby, and Swift. Supports "run all" (security-and-quality + security-experimental) and "important only" (high-precision) scan modes, and creates data extension models for project-specific sources and sinks. For fast single-file pattern matching, or when no build is available for a compiled language, use the semgrep skill; to parse SARIF that already exists rather than produce it, use the sarif-parsing skill.

bg-szy/TOP-SKILLS

Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in Word files, working with tracked changes or comments, or converting content into a polished Word document. If the user asks for a 'report', 'memo', 'letter', 'template', or similar deliverable as a Word or .docx file, use this skill. Do NOT use for PDFs, spreadsheets, Google Docs, or general coding tasks unrelated to document generation.

bg-szy/TOP-SKILLS

Enforces authenticated gh CLI workflows over unauthenticated curl, WebFetch, and MCP fetch patterns. Use when working with GitHub URLs, API access, pull requests, or issues.

bg-szy/TOP-SKILLS

Builds custom fuzzers with LibAFL, the modular Rust fuzzing library. Covers composing observers, feedbacks, mutators, schedulers, and executors into a fuzzer for targets the standard tools do not fit. Use when writing a bespoke fuzzer or mutator, fuzzing a non-standard target or architecture, implementing a fuzzing research idea, or when libFuzzer and AFL++ lack the control you need.

Skills relacionados