The SAP deployment automation framework on Azure is an open-source orchestration tool for deploying, installing and maintaining SAP environments. You can create infrastructure for SAP landscapes based on SAP HANA and NetWeaver with AnyDB on any of the SAP-supported operating system versions and deploy them into any Azure region.
The framework uses Terraform for infrastructure deployment, and Ansible for the operating system and application configuration.
SDAF supports three execution models. Each model deploys the same framework components, but the setup, configuration generation, identity, and approval processes differ.
| Execution model | Use this path when | Start here |
|---|---|---|
| GitHub Actions | Your deployment configuration and automation run from GitHub repositories and workflows. | Review the GitHub Actions execution model |
| Azure DevOps | Your organization uses Azure Repos, Azure Pipelines, service connections, variable groups, and agent pools. | Review the Azure DevOps execution model |
| Local or scripted execution | You run the SDAF scripts directly from a workstation, deployment host, or other automation environment. | Review the local execution model |
For selection criteria and capability differences, see Choose an SDAF deployment option.
The three execution models above are still the main way to run SDAF.
Alongside them, this repository now ships an optional AI-skills hub
plugin, azure-sap-automation, for supported agent CLIs (GitHub Copilot
CLI, Claude Code, Gemini CLI). SDAF itself does not require these plugins.
The hub plugin covers shared SDAF guidance that applies across local,
Azure DevOps, and GitHub Actions use. The Azure DevOps and GitHub Actions
bootstrap experiences stay in separate surface plugins:
azure-sap-automation-devops and azure-sap-automation-github. Install
those only when you use the matching platform.
If you install the plugins, match them to your execution model:
- Local / scripted — install the hub plugin (
azure-sap-automation) only. - Azure DevOps — install the hub plugin and the Azure DevOps
surface plugin (
azure-sap-automation-devops). - GitHub Actions — install the hub plugin and the GitHub Actions
surface plugin (
azure-sap-automation-github).
Each plugin is independently installable; nothing installs automatically,
and you run each command yourself. The hub install commands are below. For
the full 18-skill catalogue, install verification, example prompts,
limitations, and Azure DevOps or GitHub Actions surface-plugin commands,
see docs/PLUGINS.md.
copilot plugin marketplace add Azure/sap-automation
copilot plugin install azure-sap-automation@sap-automation/plugin marketplace add Azure/sap-automation
/plugin install azure-sap-automation@sap-automation
gemini extensions install https://github.com/Azure/sap-automationAll three execution models use shared configuration examples and SAP software
definitions. The
Azure/SAP-automation-samples
repository contains:
- Terraform examples under
Terraform/WORKSPACES. - SAP application definitions under
SAP. - Bill of materials (BOM) files under
BOM. - Ansible sample inputs under
Ansible.
Complete the SDAF lifecycle in dependency order:
- Plan Azure architecture, networking, identity, quota, sizing, and cost.
- Bootstrap the selected execution environment.
- Configure, review, deploy, and validate the control plane.
- Configure, review, deploy, and validate a workload zone.
- Configure, review, deploy, and validate an SAP system.
- Download SAP software and run operating-system, database, and SAP installation.
- Operate, update, recover, or remove the environment.
Warning
SDAF creates billable Azure resources and changes shared infrastructure. Review every Terraform plan, confirm state access, and validate destructive operations before approval.
Use the repository documentation hub for current repository-owned guidance. The hub explains repository responsibilities, deployment choices, documentation conventions, and the source used to validate capability statements.
Detailed platform procedures remain with the repository that owns the workflows, pipelines, scripts, or samples. For repository boundaries, see SDAF repositories.
Before you contribute, review the contributing guidelines.
Use GitHub issues for feature requests and bugs. Report security vulnerabilities by following SECURITY.md.
This project welcomes contributions and suggestions. Most contributions require you to agree to a Contributor License Agreement (CLA) declaring that you have the right to, and actually do, grant us the rights to use your contribution. For details, visit https://cla.opensource.microsoft.com.
When you submit a pull request, a CLA bot will automatically determine whether you need to provide a CLA and decorate the PR appropriately (e.g., status check, comment). Simply follow the instructions provided by the bot. You will only need to do this once across all repos using our CLA.
This project has adopted the Microsoft Open Source Code of Conduct. For more information see the Code of Conduct FAQ or contact opencode@microsoft.com with any additional questions or comments.
This project may contain trademarks or logos for projects, products, or services. Authorized use of Microsoft trademarks or logos is subject to and must follow Microsoft's Trademark & Brand Guidelines. Use of Microsoft trademarks or logos in modified versions of this project must not cause confusion or imply Microsoft sponsorship. Any use of third-party trademarks or logos are subject to those third-party's policies.
Copyright (c) Microsoft Corporation. Licensed under the MIT License. See LICENSE for more information.