Skip to content

[AKS] az aks install-cli: Add optional native Azure skills installation - #34101

Open
Tom Gamble (gambtho) wants to merge 18 commits into
Azure:devfrom
gambtho:feature/aks-azure-skills
Open

Tom Gamble (gambtho) wants to merge 18 commits into
Azure:devfrom
gambtho:feature/aks-azure-skills

Conversation

@gambtho

@gambtho Tom Gamble (gambtho) commented Sep 19, 2026

Copy link
Copy Markdown

🤖 PR Validation — ❌ Action needed

Breaking Changes Tests
⚠️ None ❌ 128/130
⚠️AzureCLI-BreakingChangeTest
⚠️acs
rule cmd_name rule_message suggest_message
⚠️ 1006 - ParaAdd aks install-cli cmd aks install-cli added parameter install_azure_skills
⚠️ 1006 - ParaAdd aks install-cli cmd aks install-cli added parameter skills_agents
❌AzureCLI-FullTest
️✔️acr
️✔️latest
️✔️3.12
️✔️3.14
❌acs
❌latest
❌3.12
Type Test Case Error Message Line
Failed test_invalid_agent_is_rejected_by_parser self = <azure.cli.command_modules.acs.tests.latest.test_azure_skills.CliArgumentTests testMethod=test_invalid_agent_is_rejected_by_parser>

    def test_invalid_agent_is_rejected_by_parser(self):
        with mock.patch('sys.stderr', new_callable=io.StringIO) as output:
            result, handler = self.invoke(['--install-azure-skills', '--skills-agents', 'unknown'])
        self.assertEqual(result, 2)
>       self.assertIn("'unknown' is not a valid value for '--skills-agents'", output.getvalue())
E       AssertionError: "'unknown' is not a valid value for '--skills-agents'" not found in "\nExamples from command's help:\naz aks install-cli --install-azure-skills true --skills-agents claude-code pi\nInstall the binaries and user-level Azure skills for selected agents without prompts.\n\naz aks install-cli --install-azure-skills false\nInstall only the binaries, without offering Azure skills.\n\naz aks install-cli\nInstall kubectl and kubelogin, then offer Azure skills in an interactive terminal.\n\nhttps://aka.ms/cli_ref\nRead more about the command in reference docs\n"

src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_azure_skills.py:609: AssertionError
azure/cli/command_modules/acs/tests/latest/test_azure_skills.py:604
❌3.14
Type Test Case Error Message Line
Failed test_invalid_agent_is_rejected_by_parser self = <azure.cli.command_modules.acs.tests.latest.test_azure_skills.CliArgumentTests testMethod=test_invalid_agent_is_rejected_by_parser>

    def test_invalid_agent_is_rejected_by_parser(self):
        with mock.patch('sys.stderr', new_callable=io.StringIO) as output:
            result, handler = self.invoke(['--install-azure-skills', '--skills-agents', 'unknown'])
        self.assertEqual(result, 2)
>       self.assertIn("'unknown' is not a valid value for '--skills-agents'", output.getvalue())
E       AssertionError: "'unknown' is not a valid value for '--skills-agents'" not found in "\nExamples from command's help:\naz aks install-cli --install-azure-skills true --skills-agents claude-code pi\nInstall the binaries and user-level Azure skills for selected agents without prompts.\n\naz aks install-cli --install-azure-skills false\nInstall only the binaries, without offering Azure skills.\n\naz aks install-cli\nInstall kubectl and kubelogin, then offer Azure skills in an interactive terminal.\n\nhttps://aka.ms/cli_ref\nRead more about the command in reference docs\n"

src/azure-cli/azure/cli/command_modules/acs/tests/latest/test_azure_skills.py:609: AssertionError
azure/cli/command_modules/acs/tests/latest/test_azure_skills.py:604
️✔️advisor
️✔️latest
️✔️3.12
️✔️3.14
️✔️ams
️✔️latest
️✔️3.12
️✔️3.14
️✔️apim
️✔️latest
️✔️3.12
️✔️3.14
️✔️appconfig
️✔️latest
️✔️3.12
️✔️3.14
️✔️appservice
️✔️latest
️✔️3.12
️✔️3.14
️✔️aro
️✔️latest
️✔️3.12
️✔️3.14
️✔️backup
️✔️latest
️✔️3.12
️✔️3.14
️✔️batch
️✔️latest
️✔️3.12
️✔️3.14
️✔️batchai
️✔️latest
️✔️3.12
️✔️3.14
️✔️billing
️✔️latest
️✔️3.12
️✔️3.14
️✔️botservice
️✔️latest
️✔️3.12
️✔️3.14
️✔️cloud
️✔️latest
️✔️3.12
️✔️3.14
️✔️cognitiveservices
️✔️latest
️✔️3.12
️✔️3.14
️✔️compute_recommender
️✔️latest
️✔️3.12
️✔️3.14
️✔️computefleet
️✔️latest
️✔️3.12
️✔️3.14
️✔️config
️✔️latest
️✔️3.12
️✔️3.14
️✔️configure
️✔️latest
️✔️3.12
️✔️3.14
️✔️consumption
️✔️latest
️✔️3.12
️✔️3.14
️✔️container
️✔️latest
️✔️3.12
️✔️3.14
️✔️containerapp
️✔️latest
️✔️3.12
️✔️3.14
️✔️core
️✔️latest
️✔️3.12
️✔️3.14
️✔️cosmosdb
️✔️latest
️✔️3.12
️✔️3.14
️✔️databoxedge
️✔️latest
️✔️3.12
️✔️3.14
️✔️dls
️✔️latest
️✔️3.12
️✔️3.14
️✔️dms
️✔️latest
️✔️3.12
️✔️3.14
️✔️eventgrid
️✔️latest
️✔️3.12
️✔️3.14
️✔️eventhubs
️✔️latest
️✔️3.12
️✔️3.14
️✔️feedback
️✔️latest
️✔️3.12
️✔️3.14
️✔️find
️✔️latest
️✔️3.12
️✔️3.14
️✔️hdinsight
️✔️latest
️✔️3.12
️✔️3.14
️✔️identity
️✔️latest
️✔️3.12
️✔️3.14
️✔️iot
️✔️latest
️✔️3.12
️✔️3.14
️✔️keyvault
️✔️latest
️✔️3.12
️✔️3.14
️✔️lab
️✔️latest
️✔️3.12
️✔️3.14
️✔️managedservices
️✔️latest
️✔️3.12
️✔️3.14
️✔️maps
️✔️latest
️✔️3.12
️✔️3.14
️✔️marketplaceordering
️✔️latest
️✔️3.12
️✔️3.14
️✔️monitor
️✔️latest
️✔️3.12
️✔️3.14
️✔️mysql
️✔️latest
️✔️3.12
️✔️3.14
️✔️netappfiles
️✔️latest
️✔️3.12
️✔️3.14
️✔️network
️✔️latest
️✔️3.12
️✔️3.14
️✔️policyinsights
️✔️latest
️✔️3.12
️✔️3.14
️✔️postgresql
️✔️latest
️✔️3.12
️✔️3.14
️✔️privatedns
️✔️latest
️✔️3.12
️✔️3.14
️✔️profile
️✔️latest
️✔️3.12
️✔️3.14
️✔️rdbms
️✔️latest
️✔️3.12
️✔️3.14
️✔️redis
️✔️latest
️✔️3.12
️✔️3.14
️✔️relay
️✔️latest
️✔️3.12
️✔️3.14
️✔️resource
️✔️latest
️✔️3.12
️✔️3.14
️✔️role
️✔️latest
️✔️3.12
️✔️3.14
️✔️search
️✔️latest
️✔️3.12
️✔️3.14
️✔️security
️✔️latest
️✔️3.12
️✔️3.14
️✔️servicebus
️✔️latest
️✔️3.12
️✔️3.14
️✔️serviceconnector
️✔️latest
️✔️3.12
️✔️3.14
️✔️servicefabric
️✔️latest
️✔️3.12
️✔️3.14
️✔️signalr
️✔️latest
️✔️3.12
️✔️3.14
️✔️sql
️✔️latest
️✔️3.12
️✔️3.14
️✔️sqlvm
️✔️latest
️✔️3.12
️✔️3.14
️✔️storage
️✔️latest
️✔️3.12
️✔️3.14
️✔️synapse
️✔️latest
️✔️3.12
️✔️3.14
️✔️telemetry
️✔️latest
️✔️3.12
️✔️3.14
️✔️util
️✔️latest
️✔️3.12
️✔️3.14
️✔️vm
️✔️latest
️✔️3.12
️✔️3.14

Related command

az aks install-cli

Description

Offer native, opt-in installation of Microsoft Azure skills after the existing kubectl and kubelogin installation succeeds.

  • In an interactive, non-sudo session, offer installation with a default of No. Detect Claude Code, Codex, GitHub Copilot, and Pi; preselect detected agents and allow numbered selection/deselection.
  • Show user-level destinations and scope before final confirmation, including under --only-show-errors. Use native Knack prompts and typed Azure CLI errors.
  • Add --install-azure-skills true|false and --skills-agents. Explicit installation requires targets and bypasses prompts; omitted noninteractive execution and explicit false preserve binary-only behavior.
  • Retrieve the latest stable microsoft/azure-skills release by resolved commit, install complete skill trees/resources and license notices, and report provenance. Install no MCP configuration, hooks, or agent applications; add no runtime dependencies.
  • Reuse --gh-token for trusted GitHub metadata requests only. Bound transport/download/extraction, reject unsafe archive paths and destination indirection, and stage before publication.
  • First-install-only, not an updater: skip identical existing directories; preserve/report differing content. New skills can be added, but retries across releases can leave mixed versions. Do not overwrite user modifications or automatically remove skills.
  • Preserve completed binary installations on optional failure. Explicit skills failures return nonzero with partial-result and recovery guidance.

Codex uses the shared ~/.agents/skills directory, so deselecting another agent does not prevent that agent from discovering shared skills. Selection controls installation destinations, not agent enablement.

Testing Guide

After running the CLI from this branch:

# Existing command: offers skills only in an eligible interactive session.
az aks install-cli

# Explicit binary-only behavior.
az aks install-cli --install-azure-skills false

# Unattended opt-in for selected agents.
az aks install-cli --install-azure-skills true --skills-agents claude-code codex github-copilot pi

Run unprivileged when testing skills installation. If default binary destinations need elevated access, use user-writable --install-location and --kubelogin-install-location paths, including the binary filenames. A skills acceptance installs into the selected user-level directories; automated verification instead used temporary destinations.

Verification performed on Linux/Python 3.14 with worktree source overlays:

  • test_azure_skills, test_custom, and test_validators: 402 tests run, 400 passed, 2 known skips.
  • Ruff E/F checks using repository ignores, targeted pycodestyle E128 checks on all six changed Python files, and git diff --check: passed.
  • Live v1.2.49 (abaf74ac8f62fbe9f83d7ccb2bd991dca929a4da) smoke after the conformance changes: 28 installations, then 28 identical no-ops; all 926 original payload files byte-matched; notices retained; temporary state removed.
  • Real-console regression coverage exercises native selection/consent under both quiet-mode configurations. Earlier implementation validation also exercised seven pseudo-terminal scenarios.
  • Polish and independent task/whole-branch reviews completed. CodeRabbit CLI reviewed the full committed diff twice; its minor continuation-indentation findings were corrected and verified. The follow-up review included the repository command/error guidelines.

The two skips are native Windows junction coverage and an existing kubelogin custom-source test. Existing ResourceWarnings/datetime deprecations remain unchanged. Native Windows/macOS, Python 3.10 runtime, full azdev ACS/style/linter gates, and actual agent/MCP workflows have not been exercised locally; CI/platform review remains necessary.

History Notes

[AKS] az aks install-cli: Add optional native Azure skills installation for coding agents


Copilot AI lite review requested due to automatic review settings September 19, 2026 02:06
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The changes require final human review because they are too complex or risky for automated approval.

Review effort: Lite
Findings: None

What changed in this PR

Adds opt-in native Azure skills installation to az aks install-cli, preserving existing binary behavior while supporting agent detection, safe downloads, staging, and non-overwriting publication.

Changes:

  • Adds interactive and explicit skills-installation modes with agent selection.
  • Implements bounded GitHub release retrieval, archive validation, and secure publication.
  • Adds extensive tests, help text, and design/implementation documentation.
File Description
src/​azure-cli/​azure/​cli/​command_modules/​acs/​tests/​latest/​test_custom.py Updated as part of this pull request.
src/​azure-cli/​azure/​cli/​command_modules/​acs/​tests/​latest/​test_azure_skills.py Updated as part of this pull request.
src/​azure-cli/​azure/​cli/​command_modules/​acs/​custom.py Updated as part of this pull request.
src/​azure-cli/​azure/​cli/​command_modules/​acs/​_params.py Updated as part of this pull request.
src/​azure-cli/​azure/​cli/​command_modules/​acs/​_help.py Updated as part of this pull request.
src/​azure-cli/​azure/​cli/​command_modules/​acs/​_azure_skills.py Updated as part of this pull request.
docs/​superpowers/​specs/​2026-09-18-aks-azure-skills-design.md Updated as part of this pull request.
docs/​superpowers/​plans/​2026-09-18-aks-azure-skills.md Updated as part of this pull request.
docs/​superpowers/​implementation/​2026-09-19-aks-azure-skills.md Updated as part of this pull request.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants