Skip to content

Gap-5: App Service Operate (B+ → A) — SKU selection, custom domains, networking - #1639

Merged
kvenkatrajan merged 20 commits into
mainfrom
pass-equity-gap-5
May 6, 2026
Merged

Gap-5: App Service Operate (B+ → A) — SKU selection, custom domains, networking#1639
kvenkatrajan merged 20 commits into
mainfrom
pass-equity-gap-5

Conversation

@paulyuk

Copy link
Copy Markdown
Member

Closes #1613 | Parent: #1608

3 files: sku-selection.md (Free→Isolated comparison), custom-domains.md (managed TLS via Bicep), networking.md (VNet, Private Endpoints, Access Restrictions).

Starting assessment — domain experts should review.

…(Gap-5)

Closes #1613 | Parent: #1608
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds App Service “Operate (A)” reference docs covering SKU selection, custom domains/managed TLS, and networking options (VNet integration, Private Endpoints, access restrictions).

Changes:

  • Introduces a SKU comparison/pricing guide plus IaC examples (Bicep/Terraform) for plan SKU selection.
  • Documents custom domain DNS setup and managed TLS workflows via CLI/Bicep/Terraform.
  • Adds networking guidance for VNet integration, Private Endpoints, access restrictions, and troubleshooting.

Reviewed changes

Copilot reviewed 3 out of 3 changed files in this pull request and generated 6 comments.

File Description
plugin/skills/azure-prepare/references/services/app-service/sku-selection.md New guidance to choose App Service SKUs, including feature matrix, pricing overview, and IaC examples.
plugin/skills/azure-prepare/references/services/app-service/custom-domains.md New guide for custom domains and managed certificates using CLI/Bicep/Terraform.
plugin/skills/azure-prepare/references/services/app-service/networking.md New networking reference covering VNet integration, Private Endpoints, access restrictions, and troubleshooting.

Comment thread plugin/skills/azure-prepare/references/services/app-service/networking.md Outdated
Comment thread plugin/skills/azure-prepare/references/services/app-service/networking.md Outdated
@github-actions

github-actions Bot commented Apr 1, 2026

Copy link
Copy Markdown
Contributor
Details# 🔍 Token Analysis Report

@github-copilot-for-azure/scripts@1.0.0 tokens
node --import tsx src/tokens/cli.ts compare --base origin/main --head HEAD --markdown

fatal: path 'plugin/skills/azure-prepare/references/services/app-service/custom-domains.md' exists on disk, but not in 'origin/main'
fatal: path 'plugin/skills/azure-prepare/references/services/app-service/networking.md' exists on disk, but not in 'origin/main'
fatal: path 'plugin/skills/azure-prepare/references/services/app-service/sku-selection.md' exists on disk, but not in 'origin/main'

📊 Token Change Report

Comparing origin/mainHEAD

Summary

Metric Value
📈 Total Change +4,087 tokens (+744%)
Before 549 tokens
After 4,636 tokens
Files Changed 4

Changed Files

File Before After Change
plugin/skills/azure-prepare/references/services/app-service/networking.md - 1,672 +1672
plugin/skills/azure-prepare/references/services/app-service/custom-domains.md - 1,224 +1224
plugin/skills/azure-prepare/references/services/app-service/sku-selection.md - 1,164 +1164
plugin/skills/azure-prepare/references/services/app-service/README.md 549 576 +27 (+5%)

@github-copilot-for-azure/scripts@1.0.0 tokens
node --import tsx src/tokens/cli.ts check --markdown

📊 Token Limit Check Report

Checked: 577 files
Exceeded: 87 files

⚠️ Files Exceeding Token Limits

File Tokens Limit Over By
.github/skills/analyze-skill-issues/SKILL.md 2109 500 +1609
.github/skills/analyze-test-run/SKILL.md 2471 500 +1971
.github/skills/file-test-bug/SKILL.md 628 500 +128
.github/skills/sensei/README.md 3531 2000 +1531
.github/skills/sensei/SKILL.md 3026 500 +2526
.github/skills/sensei/references/EXAMPLES.md 3701 2000 +1701
.github/skills/sensei/references/LOOP.md 4181 2000 +2181
.github/skills/sensei/references/SCORING.md 4299 2000 +2299
.github/skills/skill-authoring/SKILL.md 839 500 +339
plugin/skills/airunway-aks-setup/SKILL.md 1025 500 +525
plugin/skills/appinsights-instrumentation/SKILL.md 911 500 +411
plugin/skills/azure-ai/SKILL.md 820 500 +320
plugin/skills/azure-aigateway/SKILL.md 1261 500 +761
plugin/skills/azure-aigateway/references/policies.md 2342 2000 +342
plugin/skills/azure-cloud-migrate/SKILL.md 848 500 +348
plugin/skills/azure-cloud-migrate/references/services/container-apps/cloudrun-deployment-guide.md 2029 2000 +29
plugin/skills/azure-cloud-migrate/references/services/container-apps/deployment-guide.md 2458 2000 +458
plugin/skills/azure-cloud-migrate/references/services/container-apps/fargate-deployment-guide.md 2587 2000 +587
plugin/skills/azure-cloud-migrate/references/services/functions/lambda-to-functions.md 2600 2000 +600
plugin/skills/azure-cloud-migrate/references/services/functions/runtimes/javascript.md 2181 2000 +181
plugin/skills/azure-compliance/SKILL.md 1188 500 +688
plugin/skills/azure-compute/SKILL.md 1090 500 +590
plugin/skills/azure-compute/workflows/vm-recommender/vm-recommender.md 2631 2000 +631
plugin/skills/azure-compute/workflows/vm-troubleshooter/vm-troubleshooter.md 2509 2000 +509
plugin/skills/azure-cost/SKILL.md 1980 500 +1480
plugin/skills/azure-deploy/SKILL.md 1645 500 +1145
plugin/skills/azure-deploy/references/pre-deploy-checklist.md 4095 2000 +2095
plugin/skills/azure-deploy/references/recipes/azd/errors.md 4004 2000 +2004
plugin/skills/azure-deploy/references/troubleshooting.md 2038 2000 +38
plugin/skills/azure-diagnostics/SKILL.md 1293 500 +793
plugin/skills/azure-enterprise-infra-planner/SKILL.md 1002 500 +502
plugin/skills/azure-enterprise-infra-planner/references/constraints/compute-apps.md 2022 2000 +22
plugin/skills/azure-hosted-copilot-sdk/SKILL.md 1263 500 +763
plugin/skills/azure-kubernetes/SKILL.md 2606 500 +2106
plugin/skills/azure-kubernetes/azure-kubernetes-automatic-readiness/SKILL.md 3609 500 +3109
plugin/skills/azure-kusto/SKILL.md 2152 500 +1652
plugin/skills/azure-messaging/SKILL.md 821 500 +321
plugin/skills/azure-prepare/SKILL.md 3359 500 +2859
plugin/skills/azure-prepare/references/aspire.md 4617 2000 +2617
plugin/skills/azure-prepare/references/plan-template.md 2617 2000 +617
plugin/skills/azure-prepare/references/recipes/azd/aspire.md 2275 2000 +275
plugin/skills/azure-prepare/references/recipes/azd/terraform.md 3528 2000 +1528
plugin/skills/azure-prepare/references/research.md 2274 2000 +274
plugin/skills/azure-prepare/references/resources-limits-quotas.md 3322 2000 +1322
plugin/skills/azure-prepare/references/security.md 2147 2000 +147
plugin/skills/azure-prepare/references/services/functions/bicep.md 3127 2000 +1127
plugin/skills/azure-prepare/references/services/functions/templates/recipes/composition.md 2813 2000 +813
plugin/skills/azure-prepare/references/services/functions/terraform.md 3404 2000 +1404
plugin/skills/azure-prepare/references/services/sql-database/bicep.md 2037 2000 +37
plugin/skills/azure-quotas/SKILL.md 2821 500 +2321
plugin/skills/azure-quotas/references/commands.md 2644 2000 +644
plugin/skills/azure-resource-lookup/SKILL.md 1394 500 +894
plugin/skills/azure-resource-visualizer/SKILL.md 2122 500 +1622
plugin/skills/azure-storage/SKILL.md 1228 500 +728
plugin/skills/azure-upgrade/SKILL.md 1249 500 +749
plugin/skills/azure-upgrade/references/languages/java/INSTRUCTION.md 2724 2000 +724
plugin/skills/azure-upgrade/references/languages/java/package-specific/com.microsoft.azure.management.md 2215 2000 +215
plugin/skills/azure-upgrade/references/languages/java/templates/PLAN_TEMPLATE.md 2411 2000 +411
plugin/skills/azure-upgrade/references/languages/java/templates/PROGRESS_TEMPLATE.md 2315 2000 +315
plugin/skills/azure-upgrade/references/languages/java/templates/SUMMARY_TEMPLATE.md 2190 2000 +190
plugin/skills/azure-upgrade/references/services/functions/automation.md 3463 2000 +1463
plugin/skills/azure-upgrade/references/services/functions/consumption-to-flex.md 2773 2000 +773
plugin/skills/azure-validate/SKILL.md 950 500 +450
plugin/skills/entra-agent-id/SKILL.md 4001 500 +3501
plugin/skills/entra-app-registration/SKILL.md 2070 500 +1570
plugin/skills/entra-app-registration/references/api-permissions.md 2545 2000 +545
plugin/skills/entra-app-registration/references/cli-commands.md 2211 2000 +211
plugin/skills/entra-app-registration/references/console-app-example.md 2752 2000 +752
plugin/skills/entra-app-registration/references/oauth-flows.md 2375 2000 +375
plugin/skills/microsoft-foundry/SKILL.md 2939 500 +2439
plugin/skills/microsoft-foundry/foundry-agent/create/create.md 4315 2000 +2315
plugin/skills/microsoft-foundry/foundry-agent/create/references/toolbox.md 2802 2000 +802
plugin/skills/microsoft-foundry/foundry-agent/deploy/deploy.md 5894 2000 +3894
plugin/skills/microsoft-foundry/foundry-agent/eval-datasets/eval-datasets.md 2344 2000 +344
plugin/skills/microsoft-foundry/foundry-agent/eval-datasets/references/trace-to-dataset.md 4268 2000 +2268
plugin/skills/microsoft-foundry/foundry-agent/invoke/invoke.md 2084 2000 +84
plugin/skills/microsoft-foundry/foundry-agent/observe/observe.md 2542 2000 +542
plugin/skills/microsoft-foundry/foundry-agent/trace/references/kql-templates.md 2701 2000 +701
plugin/skills/microsoft-foundry/models/deploy-model/SKILL.md 1640 500 +1140
plugin/skills/microsoft-foundry/models/deploy-model/capacity/SKILL.md 1739 500 +1239
plugin/skills/microsoft-foundry/models/deploy-model/customize/SKILL.md 2235 500 +1735
plugin/skills/microsoft-foundry/models/deploy-model/customize/references/customize-workflow.md 3335 2000 +1335
plugin/skills/microsoft-foundry/models/deploy-model/preset/SKILL.md 1226 500 +726
plugin/skills/microsoft-foundry/models/deploy-model/preset/references/preset-workflow.md 5534 2000 +3534
plugin/skills/microsoft-foundry/quota/quota.md 2288 2000 +288
plugin/skills/microsoft-foundry/quota/references/capacity-planning.md 2080 2000 +80
plugin/skills/microsoft-foundry/references/sdk/foundry-sdk-py.md 2162 2000 +162

Consider moving content to references/ subdirectories.


Automated token analysis. See skill authoring guidelines for best practices.

@jongio Jon Gallant (jongio) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Three new App Service reference docs with solid structure - clear tables, good IaC examples, and useful troubleshooting sections. However, several SKU feature claims are outdated (Azure expanded VNet integration, Private Endpoints, and Hybrid Connections to Basic tier in 2022), which makes the decision tree and feature unlock summary steer users toward more expensive tiers than necessary.

Two CI checks are also failing:

  • Skill Structure: azure-prepare SKILL.md version needs bumping (currently 1.1.1 on this branch).
  • Markdown References: The 3 new files aren't linked from the azure-prepare SKILL.md. The app-service/README.md also needs links to the new files (matching the pattern for bicep.md, deployment-slots.md, scaling.md).

@kvenkatrajan

Copy link
Copy Markdown
Collaborator

Andrew Westgarth (@apwestgarth) is the owner - please assist

@kvenkatrajan

Copy link
Copy Markdown
Collaborator

Andrew Westgarth (@apwestgarth) - please assist

…tworking.md


Updated to use up to date property which can also be audited using policy
Copilot AI review requested due to automatic review settings April 21, 2026 22:46

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated 5 comments.

Comment thread plugin/skills/azure-prepare/references/services/app-service/networking.md Outdated
Comment thread plugin/skills/azure-prepare/references/services/app-service/networking.md Outdated
…tworking.md


standardise on using the newer outboundVnetRouting.allTraffic property

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Copilot AI review requested due to automatic review settings April 22, 2026 20:25

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 3 out of 3 changed files in this pull request and generated 3 comments.

…tworking.md

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>

@jongio Jon Gallant (jongio) left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All my prior findings are addressed. Decision tree now correctly reflects that VNet integration and Private Endpoints are available from Standard (not just Premium), CLI flags are consistent, and HC limits include Basic tier.

One minor typo in networking.md line 175: suports should be supports.

Copilot AI commented Apr 29, 2026

Copy link
Copy Markdown
Contributor

Good progress - most of my previous feedback is addressed. The SKU matrices, feature unlock table, and networking availability are accurate now, and the CLI examples are a welcome addition.

Two items...

Updated in commit c1d32e5: decision criteria now aligns with the matrix (Basic can cover VNet/Private Endpoints; Standard is recommended when slots/auto-scale/backups are needed; Premium only when you need >5 slots or >10 instances). I also updated the Production API recommendation to include Standard as the default and fixed the Hybrid Connections warning wording. I re-ran markdown references validation and azure-prepare now passes with no orphaned files.

Screenshot: N/A (documentation-only markdown change, no UI change).

Copilot AI commented Apr 29, 2026

Copy link
Copy Markdown
Contributor

All my prior findings are addressed. Decision tree now correctly reflects that VNet integration and Private Endpoints are available from Standard (not just Premium), CLI flags are consistent, and HC l...

Confirmed — this typo is already corrected (supports) in commit c1d32e5.

Screenshot: N/A (documentation-only markdown change, no UI change).

Added detail on reserved instances and savings plans

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Addressed all feedback and made appropriate changes.

@JasonYeMSFT

Copy link
Copy Markdown
Member

Jon Gallant (@jongio) kvenkatrajan Tom Meschter (@tmeschter) Wallace Breza (@wbreza) Could any of you review the PR as the code owner?

@paulyuk

Copy link
Copy Markdown
Member Author

Ready for final merge ✅

All 59 review threads resolved. CI is green across the board. Approvals from Andrew Westgarth (@apwestgarth) and JasonYeMSFT (@JasonYeMSFT). Jon Gallant (@jongio) dismissed his earlier changes-request after the SKU matrix corrections (Basic tier supports VNet integration / Private Endpoints / Hybrid Connections, etc.).

Verified all of Jon Gallant (@jongio)'s inline feedback is addressed in the current code:

  • sku-selection.md:17 — Basic tier shows ✅ for VNet integration, Private Endpoints, Hybrid Connections (5)
  • sku-selection.md:56 — Decision tree no longer routes to Premium for VNet/PE; Basic and Standard correctly listed
  • sku-selection.md:63 — Feature Unlock Summary corrected (Free→Basic gains VNet+PE+HC; Basic→Standard drops VNet)
  • networking.md:15 — Free and Basic split into separate columns showing real differences
  • networking.md:125 — Updated to "Private Endpoints require Basic (B1) or higher"
  • networking.md:164 — Updated Hybrid Connections to "Requires Basic tier or higher"
  • networking.md:200 — CLI examples added throughout (private endpoint, access restrictions)

Pinging codeowners Tom Meschter (@tmeschter) Wallace Breza (@wbreza) kvenkatrajan @microsoft/ghcp4a for final review/merge.

Also tagging Andrew Westgarth (@apwestgarth) as co-DRI on the parent issue #1613 going forward — he's the App Service Principal PM and our deepest reviewer here.

@paulyuk

Copy link
Copy Markdown
Member Author

📌 Follow-up enhancement filed: #2148

After this PR ships, we plan to refactor App Service templates to use a dynamic MCP tool pattern (analogous to Manvir Kaur (@manvkaur)'s Functions work in #1949), which would replace ~1,995 lines of hardcoded templates with runtime fetches from Azure-Samples + 3-tier fallback. This is intentionally not blocking this PR — we want to ship the proven, hand-curated templates now and layer the optimization after.

@kvenkatrajan
kvenkatrajan merged commit 4b48e67 into main May 6, 2026
12 checks passed
@kvenkatrajan
kvenkatrajan deleted the pass-equity-gap-5 branch May 6, 2026 14:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Gap-5: App Service Operate (B+ → A) — SKU selection, custom domains, networking, upgrade paths

8 participants