Subscription Resolution — Defensive Fallback
The azure-app-onboard orchestrator resolves the subscription at Step 1 (login hard gate) and writes subscriptionId, subscriptionName, tenantId to context.json.azure before any sub-skill runs. In normal operation, context.json.azure.subscriptionId is always set by the time prepare runs.
At prepare phase entry, verify context.json.azure.subscriptionId is set. If it is (expected path), use it — done.
If context.json.azure is somehow empty, resolve now rather than halting the flow:
- Check env vars — if
AZURE_SUBSCRIPTION_IDis set, use it directly (withAZURE_TENANT_IDif set). WritesubscriptionId,subscriptionName,tenantIdtocontext.json.azure, done. - Run
az account show—az account show --query "{id:id, name:name, tenantId:tenantId}" -o json. If it succeeds, auto-select — writesubscriptionId,subscriptionName,tenantIdtocontext.json.azure. Do NOT runaz account listor present a picker. - Fallback:
mcp_azure_mcp_subscription_list+ picker — only ifaz account showfails. Callmcp_azure_mcp_subscription_listto retrieve all subscriptions (returnssubscriptionId,displayName,isDefault).- 1 subscription → auto-select, no question. Write
subscriptionId,subscriptionName,tenantIdtocontext.json.azure. - 2+ subscriptions → present a picker via
ask_user: list each subscription as a choice"{displayName} ({subscriptionId})"with the default marked. The user selects one. WritesubscriptionId,subscriptionName,tenantIdtocontext.json.azure.
- 1 subscription → auto-select, no question. Write
- MCP tool fails → attempt
az login(interactive browser login). If that fails (no browser, remote session), fall back toaz login --use-device-code. On success, retry from step 2. Cap login at 3 attempts total — if login still fails after the 3rd attempt, HALT once with a clear, actionable message: the exactaz login --tenant <tenant>command to run, and that re-invoking the skill resumes this session (completed phases are preserved). Do NOT retry past 3 attempts, and do NOT proceed without a resolved subscription.