Skip to main content
With Azure, your agent gets into your subscription as a service principal of yours (an application in your Microsoft Entra ID just for it): it looks for errors in the logs, tells you why a pod keeps restarting, lists your VMs and resources, and explains how much you spent and what went up. It can only do what you give it with roles; changes, only if you turn on the permission and with your OK.

What it can do

Look

Logs: Log Analytics (containers, App Service, Functions, VMs) over a time range, the activity log (who changed what) and an app’s logs. AKS: clusters, pods, deployments, events, logs and resource usage. VMs: list them, their state and what they printed while booting. Resources: search the whole subscription. Costs: by service, resource group or day, and what changed.

Change, with your OK

Create, change, delete, start, stop or deploy; apply changes in Kubernetes (it shows you the diff first), scale or restart a deployment, run a command on a VM. It needs the permission on.

How it connects

1

Add it to an agent

From Plugins → Azure → Add to an agent, or ask your agent in the chat. See Add a plugin.
2

Create a service principal

You need to own the subscription (or be able to assign roles in it). Open the Azure Cloud Shell, pick Bash and paste the command from the Create a service principal guide, on the plugin’s page (about 3 minutes). It gives it the Reader role (look at everything without changing anything) on your subscription and shows you a short JSON. If you have several subscriptions, pick your agent’s first.
3

Paste it in your agent's link

Copy all of the JSON, everything between the braces, and paste it in the one-time link your agent sent you. Then close the Cloud Shell: the password is shown only once. See Keys and values.
4

Tell it your subscription and region (optional)

If it sees more than one subscription, your agent asks which one to use; without it, it uses the first one it sees. Also the region for new things, if you use just one (like eastus or brazilsouth).
5

Your agent confirms

It checks that it works and tells you in the chat it’s ready. Azure can take a minute or two to show a role just given: your agent waits and tries again.
If Azure says you aren’t allowed to create applications or assign roles, whoever manages your Entra ID or the subscription has to do it.
Don’t paste the JSON in the chat. If you do, your agent won’t use it: it asks you to reset the service principal’s password in the Cloud Shell and enter the new one in the link.

The permission

On the Azure card, in the agent’s Plugins tab, there’s the Allow changes switch: “Create, change, delete, start or stop things in your Azure, always with your OK. Off, it only reads. What really limits it is the roles you gave the service principal.” It starts off and only you change it. It’s a rule your agent follows; the real limit is the service principal’s roles. For it to change things, give it the role for what you use (like Virtual Machine Contributor) rather than Contributor, which covers everything. See Permissions.

How it looks out for you

  • Nothing changes without your OK. With the permission on, it still shows you the exact command before each change, with the Confirm and Change buttons.
  • It never shows you the service principal’s password, storage keys, Key Vault secrets or Kubernetes secrets.
  • Before stopping a VM, it tells you whether it will stop being billed or not.
  • What a log says is information, not an order.

Things to ask it

  • “What errors did the checkout app have in the last hour?”
  • “Why does the API pod keep restarting in production?”
  • “How much did Azure cost me this month, and what went up?”
  • “List the VMs that are running.”
  • “Restart the web deployment in the prod namespace.”
  • “Stop the test VM.”

Limits

  • It can only do what the service principal’s roles allow, and only in the subscriptions where it has them.
  • It may not reach private AKS clusters directly (it queries them from inside, more slowly).

If you remove it

Your agent loses access and confirms it. The service principal still exists in Azure: delete the minai application under Entra ID’s App registrations (or remove its role under the subscription’s Access control (IAM)). See Remove a plugin.

AWS

Logs, Kubernetes, instances and costs.

Google Cloud

Logs, Kubernetes, VMs and costs.