azure/azqr-developer
Expert guidance for developing and contributing to Azure Quick Review (azqr) - A Go-based CLI tool for Azure resource compliance analysis
npx skills add https://github.com/Azure/azqr --skill azqr-developer
Expert guidance for autonomous agents and developers contributing to the Azure Quick Review (azqr) project.
Azure Quick Review (azqr) is a CLI tool written in Go that analyzes Azure resources for compliance with Azure's best practices and recommendations. The tool scans Azure resources using:
# Build the project
make build
# Run all tests (REQUIRED before submitting pull requests)
make test
# Clean build artifacts
make clean
# View all available targets
make help
azqr/
├── cmd/azqr/ # Main CLI application entry point
│ ├── main.go # Application entry point
│ └── commands/ # CLI command implementations (one file per Azure service)
├── cmd/server/ # Server mode implementation
├── internal/ # Internal packages
│ ├── scanner.go # Main scanning logic
│ ├── models/ # Data models and filters
│ ├── renderers/ # Output formatters (Excel, CSV, JSON)
│ ├── scanners/ # Service-specific scanners (one per Azure service)
│ ├── graph/ # Azure Resource Graph queries
│ └── aigov/ # AI Governance utilities
├── data/ # Static data files
│ └── recommendations.json # Generated recommendations data
├── examples/ # Example configurations and CI/CD pipelines
├── docs/ # Documentation website (Hugo-based)
└── Makefile # Build automation
Scanner, Renderer)All code must support multiple authentication methods:
fmt.Errorf with %w verberrWhen adding a new Azure service, follow this systematic approach:
internal/scanners/<service>/cmd/azqr/commands/<service>.gointernal/models/CRITICAL: Always run make test before submitting pull requests. This is non-negotiable.
The test command includes:
golangci-lint) - Code quality checks# Run the full test suite (ALWAYS run before PR)
make test
# Individual test components
make lint # Run linter
make vet # Run go vet
make tidy # Check module tidiness
# Build for current platform
make build
# Build for specific OS/architecture
GOOS=linux GOARCH=amd64 make build
GOOS=windows GOARCH=amd64 make build
# Build Docker image
make build-image
# Build with version information
PRODUCT_VERSION=1.0.0 make build
# Update recommendations.json after adding rules
make json
internal/scanners/<service>/make json to update recommendations.jsonmake testmake testinternal/throttling/ for rate limiting// internal/scanners/<service>/<service>.go
package <service>
import (
"context"
"github.com/Azure/azqr/internal/models"
)
// Scanner implements the service scanner interface
type Scanner struct {
// Scanner fields (config, client, etc.)
}
// Scan performs the compliance scan for the service
func (s *Scanner) Scan(ctx context.Context) ([]models.Recommendation, error) {
// Implementation
// 1. Fetch resources
// 2. Apply recommendation rules
// 3. Return findings
}
// cmd/azqr/commands/<service>.go
package commands
import (
"github.com/spf13/cobra"
)
func init() {
// Register command with root command
}
var <service>Cmd = &cobra.Command{
Use: "<service>",
Short: "Scan <Service Name>",
Long: "Detailed description of what this scanner does",
Run: <service>Run,
}
func <service>Run(cmd *cobra.Command, args []string) {
// Command implementation
// 1. Parse flags
// 2. Initialize scanner
// 3. Run scan
// 4. Output results
}
func TestScanner_Scan(t *testing.T) {
tests := []struct {
name string
setup func() // setup test environment
want int // expected number of recommendations
wantErr bool
}{
{
name: "success case",
setup: func() { /* setup */ },
want: 5,
wantErr: false,
},
{
name: "error case",
setup: func() { /* setup */ },
want: 0,
wantErr: true,
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
tt.setup()
// test implementation
})
}
}
# Set environment variable for detailed logging
export AZURE_SDK_GO_LOGGING=all
# Run with debug flag
./azqr scan --debug
Reader on Subscription/Management Group)az account show if using Azure CLI authpprof# Service Principal
AZURE_CLIENT_ID="<service-principal-id>"
AZURE_CLIENT_SECRET="<service-principal-secret>"
AZURE_TENANT_ID="<tenant-id>"
# Credential Chain Configuration
AZURE_TOKEN_CREDENTIALS="dev" # Use Azure CLI/Azure Developer CLI
AZURE_TOKEN_CREDENTIALS="prod" # Use env vars/workload identity/managed identity
AZURE_SDK_GO_LOGGING="all" # Enable detailed SDK logging
make test and ensure all tests pass (100% required)The project currently supports 50+ Azure services including:
When adding new services:
azqr generates reports in multiple formats:
--csv flag)make test before submitting a pull request - This is the most important rulemake json after adding rules10. Keep scanner implementations consistent with existing patterns
Take azure/azqr-developer from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.