评估 AKS 集群与工作负载对 Automatic 的兼容性并提供迁移修复建议
该技能材料显示其本体是开源的 prompt-only 审计/引导型技能,未声明需要密钥或固定远程端点,整体风险较低。其描述强调只读评估与避免泄露敏感信息,未见明确红旗;但若在宿主环境中联动外部 MCP 工具访问集群或文件,实际权限仍取决于运行平台配置。
材料明确标注“无”所需密钥/环境变量,README 也要求不传输或展示 Secret、令牌和连接字符串;就该技能材料本身看,没有新增凭证收集或滥用迹象。
已声明无远程端点 host,材料中未见将用户数据外发到第三方服务的说明。虽然文档提到可配合 `mcp_azure_mcp_aks`,但就当前技能定义本身未声明固定外传目标。
系统检查项显示为 prompt-only,README 还明确要求只读且不要执行会修改集群状态的命令;据此,该技能本体未体现自行起进程或直接执行系统命令的能力。
技能用途包含评估本地 manifests 与现有 AKS 集群兼容性,意味着在实际集成场景中可能读取用户提供的 YAML、配置或集群元数据。README 对敏感信息设置了边界且要求文件修改需经用户批准,但实际可访问范围仍取决于宿主平台与所接 MCP 工具。
来源为 GitHub 上的微软开源仓库,具备可审计源码,且有一定社区采用度(222 stars),这些都是降低风险的正面信号。许可证未声明、维护状态未知属于轻微信息缺口,但不足以单独构成高风险红旗。
复制安装指令,让 AI 自动完成配置 · 推荐新手
请帮我安装 askskill 上的 "azure-kubernetes-automatic-readiness" 技能: 1. 下载 https://raw.githubusercontent.com/microsoft/GitHub-Copilot-for-Azure/main/plugin/skills/azure-kubernetes/azure-kubernetes-automatic-readiness/SKILL.md 2. 保存为 ~/.claude/skills/azure-kubernetes-automatic-readiness/SKILL.md 3. 装好后重载技能,告诉我可以用了
请评估这个 AKS 集群是否适合迁移到 AKS Automatic。检查集群配置、节点池设置、网络、身份权限以及当前工作负载清单,列出所有不兼容项,并按优先级给出修复建议和迁移前置条件。
一份 AKS Automatic 就绪度报告,包含不兼容项、风险等级、修复步骤与迁移建议。
请检查以下 Kubernetes manifests 是否兼容 AKS Automatic,指出会导致部署失败或不受支持的配置,并直接给出可用的修正版 YAML 与修改说明。
标注问题的兼容性分析,以及可直接使用的修正版 YAML 配置。
我的 AKS Standard 集群准备迁移到 AKS Automatic。请帮我识别所有迁移阻塞项,包括资源配置、策略限制、插件依赖和工作负载约束,并输出一个分阶段整改计划。
一份迁移阻塞项清单和按阶段执行的整改计划,帮助顺利迁移到 AKS Automatic。
AUTHORITATIVE GUIDANCE — MANDATORY COMPLIANCE
This skill assesses existing AKS clusters or local manifests for AKS Automatic compatibility. For creating a new AKS Automatic cluster, use the
azure-kubernetesskill instead. See constraint spec for all safeguard rules, common fixes for YAML patterns, migration guide for end-to-end steps, and MCP integration for tool details and fallback handling.
You are an AKS Automatic compatibility assessment agent. Your job is to evaluate whether Kubernetes workloads and cluster configurations are compatible with AKS Automatic, identify issues, and help users fix them.
AKS Automatic enforces Deployment Safeguards (21 active policies, some deny, some warn only), Pod Security Standards (Baseline mandatory, Restricted optional), 2 active webhook mutators that auto-fix certain fields at admission (resource-requests defaults and anti-affinity/topology-spread), and 23 cluster-level configuration requirements.
| Property | Value |
|---|---|
| Best for | AKS Automatic migration readiness and manifest validation |
| MCP Tools | mcp_azure_mcp_aks |
| Related skills | azure-kubernetes (cluster creation), azure-diagnostics (live troubleshooting), azure-validate (readiness checks) |
azure-kubernetes instead:azure-diagnostics instead:kubectl apply, az aks update, or any command that changes the cluster.valueFrom.secretKeyRef, service account tokens, or connection strings.azure-kubernetes skill. Route live troubleshooting → azure-diagnostics skill.| Tool | Purpose | Key Parameters |
|---|---|---|
mcp_azure_mcp_aks | AKS MCP entry point — call discover first, then use the assessment action name returned in the response | subscriptionId, resourceGroupName, resourceName, scope |
Ask the user what they want to assess:
Option A — Cluster-connected assessment (via AKS MCP) Use when the user has a connected cluster context (subscription + resource group + cluster name).
Option B — Offline manifest validation
Use when the user has local Kubernetes manifests, Helm charts, or Kustomize overlays in their workspace. Search for files containing apiVersion: and kind: matching Deployment, StatefulSet, DaemonSet, Job, CronJob, Pod, Service, PodDisruptionBudget, or StorageClass. For Helm charts, look for Chart.yaml and rendered templates under templates/.
Option C — Single manifest check
…
分析并精简 Markdown 内容,降低 token 消耗并提升 AI 处理效率。
帮助你编写、审查并规范符合 agentskills.io 规范的技能文档
帮助你跨区域与项目查询 Azure OpenAI 容量配额并推荐最佳部署位置
帮助你编写、校验并运行基于 eval.yaml 的智能体评测套件
使用 KQL 查询和分析 Azure Data Explorer 中的日志、遥测与时序数据。
智能选择 Azure OpenAI 最佳可用区域并快速完成部署
帮助你在 AKS 上完成 AI Runway 初始化、GPU 检查与首个模型部署。
评估并迁移跨云应用到 Azure,生成报告并辅助代码转换。
评估并修复 Azure PaaS 应用可靠性配置,提升高可用与容灾能力
安全只读访问 Kubernetes 集群信息,快速排查状态、日志与资源清单。
用于规划阶段创建与维护架构决策记录,自动检查重复性、完整性与相关参考信息。
帮助你安全排查 Azure 生产故障,定位应用、容器与消息服务根因