microsoft / microsoft/GitHub-Copilot-for-Azure
Replace microsoft-foundry skill private-network connectivity test with a script
- Dominant language
- Python
- Stars
- 250
- Forks
- 204
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 67
Description
## Summary
Copilot has identified a portion of a skill that is a good candidate for replacement with a script.
The candidate is the **private-network connectivity test** in the `microsoft-foundry` skill (`resource/private-network/references/end-to-end-test.md`) — a DNS-resolution + port-443 reachability loop that is already written as parallel bash and PowerShell blocks.
## Candidate description
To verify private connectivity after a private-network deployment, the skill loops a fixed set of endpoints:
1. For each of ~6 endpoint hostnames, resolve DNS (`Resolve-DnsName` / `dig`).
2. Probe TCP port 443 (`Test-NetConnection` / `nc`).
3. Emit one ✅/❌ line per endpoint and a summary verdict before proceeding.
This is a strong script candidate because it is:
- **Already a script in both PowerShell and Bash** — the canonical signal of an un-extracted script.
- **A fixed resolve-and-probe loop** over a known endpoint array, with no branching.
- **Output-reducing** — high-volume per-endpoint output collapses to a per-endpoint pass/fail and a single "all 6 endpoints resolved to private IPs and reachable" verdict.
- **Duplicated** — the DNS-resolution intent recurs in `vpn-dns-setup.md` (L140–L146, `nslookup` of private endpoints).
**Sketch — `test-private-connectivity.{sh,ps1}`:**
- **Input:** the resource names (or fully-qualified endpoint hostnames) as parameters.
- **Output:** ✅/❌ per endpoint plus a one-line summary verdict.
> Collecting the actual resource names (a one-time substitution) and deciding to proceed to Phase 2 stay in prose. The mechanical resolve-and-probe loop is fully scriptable.
## Affected file and lines
- [`resource/private-network/references/end-to-end-test.md` — DNS + port-443 loop, bash + PowerShell (L41–L77)](https://github.com/microsoft/GitHub-Copilot-for-Azure/blob/3890cbfb65c548ce8daa96cabd1d8de63f7bbcca/plugin/skills/microsoft-foundry/resource/private-network/references/end-to-end-test.md#L41-L77)
- [`resource/private-network/references/vpn-dns-setup.md` — private-endpoint DNS verification (L140–L146)](https://github.com/microsoft/GitHub-Copilot-for-Azure/blob/3890cbfb65c548ce8daa96cabd1d8de63f7bbcca/plugin/skills/microsoft-foundry/resource/private-network/references/vpn-dns-setup.md#L140-L146)
## Next steps
1. **Evaluate the candidate** — confirm the steps are stable and parameterizable, and that the script captures everything the skill needs.
2. **Create both a bash _and_ a PowerShell version** of the script so the skill works across platforms.
3. **Run integration tests** to verify the scripts behave correctly and the skill still completes end-to-end.
## Background Information
### Why replace regular steps with scripts
Replacing a regular, well-defined series of steps with a script can:
- **Reduce token usage** — the skill no longer needs to spell out each command and parse large command output inline; the agent invokes one script and reads a compact result.
- **Improve reliability** — the logic is written and tested once, instead of being re-derived by the agent on every run.
- **Improve determinism** — the same inputs always produce the same steps and output, removing run-to-run variation.
- **Improve speed of execution** — a single script call replaces multiple round-trips of command generation, execution, and large-output parsing.
### Authoring notes for the scripts
- **Reference scripts with markdown links**, not just a bare path to the script file.
- **Include examples** in the skill showing how to run each script (sample invocation with arguments).
- **Briefly explain what each script does** where it is referenced.
- **The script output should explain what it did**, so the agent and user can understand the result without re-inspecting raw command output.
Contributor guide
Assessment
This issue has not been assessed yet.