All skills
github avatar

/azure-deployment-preflight

@a3c13fa official
by githubgithub/awesome-copilot40k stars
5,040

Performs comprehensive preflight validation of Bicep deployments to Azure, including template syntax validation, what-if analysis, and permission checks. Use this skill before any deployment to Azure to preview changes, identify potential issues, and ensure the deployment will succeed. Activate when users mention deploying to Azure, validating Bicep files, checking deployment permissions, previewing infrastructure changes, running what-if, or preparing for azd provision.

Use this Skill: https://skilld.dev/gh/github/awesome-copilot/azure-deployment-preflight

This session only. Nothing lands on disk.

referencesVALIDATION-COMMANDS.md

≈2.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Validation Commands Reference

This reference documents all commands used for Azure deployment preflight validation.

Azure Developer CLI (azd)

azd provision --preview

Preview infrastructure changes for azd projects without deploying.

azd provision --preview [options]

Options:

Option Description
--environment, -e Name of the environment to use
--no-prompt Accept defaults without prompting
--debug Enable debug logging
--cwd Set working directory

Examples:

# Preview with default environment
azd provision --preview

# Preview specific environment
azd provision --preview --environment dev

# Preview without prompts (CI/CD)
azd provision --preview --no-prompt

Output: Shows resources that will be created, modified, or deleted.

azd auth login

Authenticate to Azure for azd operations.

azd auth login [options]

Options:

Option Description
--check-status Check login status without logging in
--use-device-code Use device code flow
--tenant-id Specify tenant
--client-id Service principal client ID

azd env list

List available environments.

azd env list

Azure CLI (az)

az deployment group what-if

Preview changes for resource group deployments.

az deployment group what-if \
  --resource-group <rg-name> \
  --template-file <bicep-file> \
  [options]

Required Parameters:

Parameter Description
--resource-group, -g Target resource group name
--template-file, -f Path to Bicep file

Optional Parameters:

Parameter Description
--parameters, -p Parameter file or inline values
--validation-level Provider (default), ProviderNoRbac, or Template
--result-format FullResourcePayloads (default) or ResourceIdOnly
--no-pretty-print Output raw JSON for parsing
--name, -n Deployment name
--exclude-change-types Exclude specific change types from output

Validation Levels:

Level Description Use Case
Provider Full validation with RBAC checks Default, most thorough
ProviderNoRbac Full validation, read permissions only When lacking deploy permissions
Template Static syntax validation only Quick syntax check

Examples:

# Basic what-if
az deployment group what-if \
  --resource-group my-rg \
  --template-file main.bicep

# With parameters and full validation
az deployment group what-if \
  --resource-group my-rg \
  --template-file main.bicep \
  --parameters main.bicepparam \
  --validation-level Provider

# Fallback without RBAC checks
az deployment group what-if \
  --resource-group my-rg \
  --template-file main.bicep \
  --validation-level ProviderNoRbac

# JSON output for parsing
az deployment group what-if \
  --resource-group my-rg \
  --template-file main.bicep \
  --no-pretty-print

az deployment sub what-if

Preview changes for subscription-level deployments.

az deployment sub what-if \
  --location <location> \
  --template-file <bicep-file> \
  [options]

Required Parameters:

Parameter Description
--location, -l Location for deployment metadata
--template-file, -f Path to Bicep file

Examples:

az deployment sub what-if \
  --location eastus \
  --template-file main.bicep \
  --parameters main.bicepparam \
  --validation-level Provider

az deployment mg what-if

Preview changes for management group deployments.

az deployment mg what-if \
  --location <location> \
  --management-group-id <mg-id> \
  --template-file <bicep-file> \
  [options]

Required Parameters:

Parameter Description
--location, -l Location for deployment metadata
--management-group-id, -m Target management group ID
--template-file, -f Path to Bicep file

az deployment tenant what-if

Preview changes for tenant-level deployments.

az deployment tenant what-if \
  --location <location> \
  --template-file <bicep-file> \
  [options]

Required Parameters:

Parameter Description
--location, -l Location for deployment metadata
--template-file, -f Path to Bicep file

az login

Authenticate to Azure CLI.

az login [options]

Options:

Option Description
--tenant, -t Tenant ID or domain
--use-device-code Use device code flow
--service-principal Login as service principal

az account show

Display current subscription context.

az account show

az group exists

Check if resource group exists.

az group exists --name <rg-name>

Bicep CLI

bicep build

Compile Bicep to ARM JSON and validate syntax.

bicep build <bicep-file> [options]

Options:

Option Description
--stdout Output to stdout instead of file
--outdir Output directory
--outfile Output file path
--no-restore Skip module restore

Examples:

# Validate syntax (output to stdout, no file created)
bicep build main.bicep --stdout > /dev/null

# Build to specific directory
bicep build main.bicep --outdir ./build

# Validate multiple files
for f in *.bicep; do bicep build "$f" --stdout; done

Error Output Format:

/path/to/file.bicep(22,51) : Error BCP064: Found unexpected tokens in interpolated expression.
/path/to/file.bicep(22,51) : Error BCP004: The string at this location is not terminated.

Format: <file>(<line>,<column>) : <severity> <code>: <message>

bicep --version

Check Bicep CLI version.

bicep --version

Parameter File Detection

Bicep Parameters (.bicepparam)

Modern Bicep parameter files (recommended):

using './main.bicep'

param location = 'eastus'
param environment = 'dev'
param tags = {
  environment: 'dev'
  project: 'myapp'
}

Detection pattern: <template-name>.bicepparam

JSON Parameters (.parameters.json)

Traditional ARM parameter files:

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "location": { "value": "eastus" },
    "environment": { "value": "dev" }
  }
}

Detection patterns:

  • <template-name>.parameters.json
  • parameters.json
  • parameters/<env>.json

Using Parameters with Commands

# Bicep parameters file
az deployment group what-if \
  --resource-group my-rg \
  --template-file main.bicep \
  --parameters main.bicepparam

# JSON parameters file
az deployment group what-if \
  --resource-group my-rg \
  --template-file main.bicep \
  --parameters @parameters.json

# Inline parameter overrides
az deployment group what-if \
  --resource-group my-rg \
  --template-file main.bicep \
  --parameters main.bicepparam \
  --parameters location=westus

Determining Deployment Scope

Check the Bicep file's targetScope declaration:

// Resource Group (default if not specified)
targetScope = 'resourceGroup'

// Subscription
targetScope = 'subscription'

// Management Group
targetScope = 'managementGroup'

// Tenant
targetScope = 'tenant'

Scope to Command Mapping:

targetScope Command Required Parameters
resourceGroup az deployment group what-if --resource-group
subscription az deployment sub what-if --location
managementGroup az deployment mg what-if --location, --management-group-id
tenant az deployment tenant what-if --location

Version Requirements

Tool Minimum Version Recommended Version Key Features
Azure CLI 2.14.0 2.76.0+ --validation-level switch
Azure Developer CLI 1.0.0 Latest --preview flag
Bicep CLI 0.4.0 Latest Best error messages

Check versions:

az --version
azd version
bicep --version

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill is functional and handles infrastructure validation as intended, but it contains an inherent indirect prompt injection surface and command execution capabilities because it processes arbitrary workspace files and executes local command-line tools.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    4/4 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at a3c13fa. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 8 months ago
  • Infrastructure
  • azure
  • bicep
  • deployment
  • validation
  • what-if
  • azd
  • azure-cli
  • iac

README badge

README badge for github/awesome-copilot/azure-deployment-preflight

Validates Bicep deployments to Azure before execution, running syntax checks, what-if analysis, and permission verification across both Azure CLI and Azure Developer CLI workflows. Detects project type automatically, captures all issues in a structured preflight report, and handles permission fallbacks when RBAC access is limited.

Generated from the current SKILL.md.

Does this skill work with both Azure CLI and Azure Developer CLI?
Yes. The skill detects whether the project uses azd (by checking for azure.yaml) and runs azd provision --preview for azd projects, or az deployment what-if commands for standalone Bicep files.
What happens if I don't have permission to deploy?
The skill falls back from --validation-level Provider to ProviderNoRbac and notes the permission limitation in the report, so you can still see syntax errors and some validation results.
Does this actually deploy anything to Azure?
No. The skill uses what-if analysis and azd provision --preview, which preview changes without making them. No resources are created or modified.
What if Bicep CLI is not installed?
The skill skips the Bicep syntax check step but continues with Azure-side validation via what-if, which will catch syntax errors during the deployment preview.
Does this handle management group and tenant scope deployments?
Yes. The skill detects the targetScope declaration in the Bicep file and runs the appropriate what-if command for resourceGroup, subscription, managementGroup, or tenant scope.

Generated from the current SKILL.md. These answers refresh after source changes.