All skills
github avatar

/azure-deployment-preflight

@a3c13fa official
by githubgithub/awesome-copilot40k stars
5,040

Performs comprehensive preflight validation of Bicep deployments to Azure, including template syntax validation, what-if analysis, and permission checks. Use this skill before any deployment to Azure to preview changes, identify potential issues, and ensure the deployment will succeed. Activate when users mention deploying to Azure, validating Bicep files, checking deployment permissions, previewing infrastructure changes, running what-if, or preparing for azd provision.

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/azure-deployment-preflight

This session only. Nothing lands on disk.

referencesREPORT-TEMPLATE.md

≈1.9k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Preflight Report Template

Use this template structure when generating preflight-report.md in the project root.


Template

# Azure Deployment Preflight Report

**Generated:** {timestamp}
**Status:** {overall-status}

---

## Summary

| Property | Value |
|----------|-------|
| **Template File(s)** | {bicep-files} |
| **Parameter File(s)** | {param-files-or-none} |
| **Project Type** | {azd-project | standalone-bicep} |
| **Deployment Scope** | {resourceGroup | subscription | managementGroup | tenant} |
| **Target** | {resource-group-name | subscription-name | mg-id} |
| **Validation Level** | {Provider | ProviderNoRbac} |

### Validation Results

| Check | Status | Details |
|-------|--------|---------|
| Bicep Syntax | {✅ Pass | ❌ Fail | ⚠️ Warnings | ⏭️ Skipped} | {details} |
| What-If Analysis | {✅ Pass | ❌ Fail | ⏭️ Skipped} | {details} |
| Permission Check | {✅ Pass | ⚠️ Limited | ❌ Fail} | {details} |

---

## Tools Executed

### Commands Run

| Step | Command | Exit Code | Duration |
|------|---------|-----------|----------|
| 1 | `{command}` | {0 | non-zero} | {duration} |
| 2 | `{command}` | {0 | non-zero} | {duration} |

### Tool Versions

| Tool | Version |
|------|---------|
| Azure CLI | {version} |
| Bicep CLI | {version} |
| Azure Developer CLI | {version-or-n/a} |

---

## Issues

{if-no-issues}
✅ **No issues found.** The deployment is ready to proceed.
{end-if}

{if-issues-exist}
### Errors

{for-each-error}
#### ❌ {error-title}

- **Severity:** Error
- **Source:** {bicep-build | what-if | permissions}
- **Location:** {file-path}:{line}:{column} (if applicable)
- **Message:** {error-message}
- **Remediation:** {suggested-fix}
- **Documentation:** {link-if-available}

{end-for-each}

### Warnings

{for-each-warning}
#### ⚠️ {warning-title}

- **Severity:** Warning
- **Source:** {source}
- **Message:** {warning-message}
- **Recommendation:** {suggested-action}

{end-for-each}
{end-if}

---

## What-If Results

{if-what-if-succeeded}

### Change Summary

| Change Type | Count |
|-------------|-------|
| 🆕 Create | {count} |
| 📝 Modify | {count} |
| 🗑️ Delete | {count} |
| ✓ No Change | {count} |
| ⚠️ Ignore | {count} |

### Resources to Create

{if-resources-to-create}
| Resource Type | Resource Name |
|---------------|---------------|
| {type} | {name} |
{end-if}

{if-no-resources-to-create}
*No resources will be created.*
{end-if}

### Resources to Modify

{if-resources-to-modify}
#### {resource-type}/{resource-name}

| Property | Current Value | New Value |
|----------|---------------|-----------|
| {property-path} | {current} | {new} |

{end-if}

{if-no-resources-to-modify}
*No resources will be modified.*
{end-if}

### Resources to Delete

{if-resources-to-delete}
| Resource Type | Resource Name |
|---------------|---------------|
| {type} | {name} |

> ⚠️ **Warning:** Resources listed for deletion will be permanently removed.
{end-if}

{if-no-resources-to-delete}
*No resources will be deleted.*
{end-if}

{end-if-what-if-succeeded}

{if-what-if-failed}
### What-If Analysis Failed

The what-if operation could not complete. See the Issues section for details.
{end-if}

---

## Recommendations

{generate-based-on-findings}

1. {recommendation-1}
2. {recommendation-2}
3. {recommendation-3}

---

## Next Steps

{if-all-passed}
The preflight validation passed. You can proceed with deployment:

**For azd projects:**
```bash
azd provision
# or
azd up
```

**For standalone Bicep:**
```bash
az deployment group create \
  --resource-group {rg-name} \
  --template-file {bicep-file} \
  --parameters {param-file}
```
{end-if}

{if-issues-exist}
Please resolve the issues listed above before deploying. After fixes:

1. Re-run preflight validation to verify fixes
2. Proceed with deployment once all checks pass
{end-if}

---

*Report generated by Azure Deployment Preflight Skill*

Status Values

Overall Status

Status Meaning Visual
Pass All checks succeeded, safe to deploy ✅
Pass with Warnings Checks succeeded but review warnings ⚠️
Fail One or more checks failed ❌

Individual Check Status

Status Meaning
✅ Pass Check completed successfully
❌ Fail Check found errors
⚠️ Warnings Check passed with warnings
⏭️ Skipped Check was skipped (tool unavailable, etc.)

Example Report

# Azure Deployment Preflight Report

**Generated:** 2026-01-16T14:32:00Z
**Status:** ⚠️ Pass with Warnings

---

## Summary

| Property | Value |
|----------|-------|
| **Template File(s)** | `infra/main.bicep` |
| **Parameter File(s)** | `infra/main.bicepparam` |
| **Project Type** | azd project |
| **Deployment Scope** | subscription |
| **Target** | my-subscription |
| **Validation Level** | Provider |

### Validation Results

| Check | Status | Details |
|-------|--------|---------|
| Bicep Syntax | ✅ Pass | No errors found |
| What-If Analysis | ⚠️ Warnings | 1 resource ignored due to nested template limits |
| Permission Check | ✅ Pass | Full deployment permissions verified |

---

## Tools Executed

### Commands Run

| Step | Command | Exit Code | Duration |
|------|---------|-----------|----------|
| 1 | `bicep build infra/main.bicep --stdout` | 0 | 1.2s |
| 2 | `azd provision --preview --environment dev` | 0 | 8.4s |

### Tool Versions

| Tool | Version |
|------|---------|
| Azure CLI | 2.76.0 |
| Bicep CLI | 0.25.3 |
| Azure Developer CLI | 1.9.0 |

---

## Issues

### Warnings

#### ⚠️ Nested Template Limit Reached

- **Severity:** Warning
- **Source:** what-if
- **Message:** 1 resource was ignored because nested template expansion limits were reached
- **Recommendation:** Review the ignored resource manually after deployment

---

## What-If Results

### Change Summary

| Change Type | Count |
|-------------|-------|
| 🆕 Create | 3 |
| 📝 Modify | 1 |
| 🗑️ Delete | 0 |
| ✓ No Change | 2 |
| ⚠️ Ignore | 1 |

### Resources to Create

| Resource Type | Resource Name |
|---------------|---------------|
| Microsoft.Resources/resourceGroups | rg-myapp-dev |
| Microsoft.Storage/storageAccounts | stmyappdev |
| Microsoft.Web/sites | app-myapp-dev |

### Resources to Modify

#### Microsoft.KeyVault/vaults/kv-myapp-dev

| Property | Current Value | New Value |
|----------|---------------|-----------|
| properties.sku.name | standard | premium |
| tags.environment | staging | dev |

### Resources to Delete

*No resources will be deleted.*

---

## Recommendations

1. Review the storage account name `stmyappdev` to ensure it meets naming requirements
2. Confirm the Key Vault SKU upgrade from standard to premium is intentional
3. The ignored nested template resource should be verified after deployment

---

## Next Steps

The preflight validation passed with warnings. Review the warnings above, then proceed:

```bash
azd provision --environment dev
```

---

*Report generated by Azure Deployment Preflight Skill*

Formatting Guidelines

  1. Use consistent emoji for visual scanning
  2. Include line numbers when referencing Bicep errors
  3. Provide actionable remediation for each issue
  4. Link to documentation when available
  5. Order issues by severity (errors first, then warnings)
  6. Include command examples in Next Steps

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is functional and handles infrastructure validation as intended, but it contains an inherent indirect prompt injection surface and command execution capabilities because it processes arbitrary workspace files and executes local command-line tools.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at a3c13fa. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 8 months ago
  • Infrastructure
  • azure
  • bicep
  • deployment
  • validation
  • what-if
  • azd
  • azure-cli
  • iac

README badge

README badge for github/awesome-copilot/azure-deployment-preflight

Validates Bicep deployments to Azure before execution, running syntax checks, what-if analysis, and permission verification across both Azure CLI and Azure Developer CLI workflows. Detects project type automatically, captures all issues in a structured preflight report, and handles permission fallbacks when RBAC access is limited.

Generated from the current SKILL.md.

Does this skill work with both Azure CLI and Azure Developer CLI?
Yes. The skill detects whether the project uses azd (by checking for azure.yaml) and runs azd provision --preview for azd projects, or az deployment what-if commands for standalone Bicep files.
What happens if I don't have permission to deploy?
The skill falls back from --validation-level Provider to ProviderNoRbac and notes the permission limitation in the report, so you can still see syntax errors and some validation results.
Does this actually deploy anything to Azure?
No. The skill uses what-if analysis and azd provision --preview, which preview changes without making them. No resources are created or modified.
What if Bicep CLI is not installed?
The skill skips the Bicep syntax check step but continues with Azure-side validation via what-if, which will catch syntax errors during the deployment preview.
Does this handle management group and tenant scope deployments?
Yes. The skill detects the targetScope declaration in the Bicep file and runs the appropriate what-if command for resourceGroup, subscription, managementGroup, or tenant scope.

Generated from the current SKILL.md. These answers refresh after source changes.