Azure Policy 云治理
原名:azure-policy
用策略定义、计划和合规结果约束云资源配置。
中文 Skills 技能说明
适合统一限制区域、规格、标签、网络和安全基线。技能会先评估现有资源影响并从审计模式开始,不能直接把不合规等同于安全事件;切换拒绝、修改或自动修复前必须做例外清单、分批验证和回退。
上游能力依据
上游原始适用说明:Expert knowledge for Azure Policy development including troubleshooting, best practices, decision making, architecture & design patterns, security, configuration, integrations & coding patterns, and deployment. Use when authoring JSON policies, Machine Config, DevOps policy-as-code, Terraform/Gatekeeper, or CI/CD governance, and other Azure Policy related development tasks. Not for Azure Blueprints (use azure-blueprints), Azure Resource Manager (use azure-resource-manager), Azure Role-based access control (use azure-rbac), Azure Security (use azure-security).
上游 SKILL.md 主要章节(保留原文标题):
- How to Use This Skill
- Category Index
- Troubleshooting
- Best Practices
- Decision Making
- Architecture & Design Patterns
- Security
- Configuration
- Integrations & Coding Patterns
- Deployment
使用边界
先确认授权范围、资产边界和证据来源。输出用于防御性检查与人工决策,不自动执行攻击、绕过或破坏性操作。
作者、翻译与许可证
- 原作者
- Microsoft Corporation 与 MicrosoftDocs/Agent-Skills contributors
- 中文翻译
- CEOFans翻译
- 许可证
- CC-BY-4.0
- 上游来源
- https://github.com/MicrosoftDocs/Agent-Skills/tree/c579bb4b37e7969ffc8bc071ca0f53048c3bfe41/skills/azure-policy
适用范围
平台:linux、macos、windows;标签:安全与合规、Azure Policy 云治理
安全提示
基础静态扫描不等于绝对安全。技能可能调用命令、浏览器、云服务或本地文件,请在最小权限环境中使用,高风险操作必须人工确认。
如发现侵权、许可证或安全问题,可在本页前台提交投诉,管理员复核后可立即下架。