All skills
microsoft avatar

/azure-prepare

@7995851 official

Prepare azd-based Azure projects for deployment: generates azure.yaml, infrastructure (Bicep/Terraform), and Dockerfiles for the Azure Developer CLI (azd) workflow. USE ONLY when the user explicitly wants to use azd as the deployment tool, or the project already has an azure.yaml file. DO NOT USE FOR: non-azd deployments, Python App Service code-only deploys (use python-appservice-deploy), or cross-cloud migration (use azure-cloud-migrate). WHEN: prepare app for azd, create azure.yaml, set up azd infrastructure, modernize app for Azure with azd, deploy with azd, function app, timer trigger, service bus trigger, event-driven function, managed identity, generate Bicep, generate Terraform, create and deploy to Azure.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-prepare

This session only. Nothing lands on disk.

referencesazure-context.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Azure Context (Subscription & Location)

Detect and confirm Azure subscription and location before generating artifacts. Run region capacity check for customer selected location


Step 1: Check for Existing AZD Environment

If the project already uses AZD, check for an existing environment with values already set:

azd env list

If an environment is selected (marked with *), check its values:

azd env get-values

If AZURE_SUBSCRIPTION_ID and AZURE_LOCATION are already set, use ask_user to confirm reuse:

Question: "I found an existing AZD environment with these settings. Would you like to continue with them?"

  Environment: {env-name}
  Subscription: {subscription-name} ({subscription-id})
  Location: {location}

Choices: [
  "Yes, use these settings (Recommended)",
  "No, let me choose different settings"
]

If user confirms → skip to Record in Plan. Otherwise → continue to Step 2.


Step 2: Detect Defaults

Check for user-configured defaults:

azd config get defaults

Returns JSON with any configured defaults:

{
  "subscription": "25fd0362-aa79-488b-b37b-d6e892009fdf",
  "location": "eastus2"
}

Use these as recommended values if present.

If no defaults, fall back to az CLI:

az account show --query "{name:name, id:id}" -o json

Step 3: Confirm Subscription with User

Use ask_user with the actual subscription name and ID:

✅ Correct:

Question: "Which Azure subscription would you like to deploy to?"
Choices: [
  "Use current: jongdevdiv (25fd0362-aa79-488b-b37b-d6e892009fdf) (Recommended)",
  "Let me specify a different subscription"
]

❌ Wrong (never do this):

Choices: [
  "Use default subscription",  // ← Does not show actual name
  "Let me specify"
]

If user wants a different subscription:

az account list --output table

Step 4: Confirm Location with User

  1. Consult Region Availability for services with limited availability
  2. Present only regions that support ALL selected services
  3. Use ask_user:
  4. After customer selected region, do provisioning limit check, consult Resource Limits and Quotas. For this also invoke azure-quotas
Question: "Which Azure region would you like to deploy to?"
Based on your architecture ({list services}), these regions support all services:
Choices: [
  "eastus2 (Recommended)",
  "westus2",
  "westeurope"
]

⚠️ Do NOT include regions that don't support all services — deployment will fail.


Step 5: Check Resource Provisioning Limits

  1. List resource types and quantities that will be deployed from the planned architecture (e.g., 2x Standard D4s v3 VMs, 1x VNet, 3x Storage Accounts)

  2. Determine limits for each resource type using the user-selected subscription and region:

    • Reference ./resources-limits-quotas.md for documented limits
    • Use azure-quotas skill to check current quotas and usage for the selected subscription and region
    • If az quota list returns BadRequest error, the resource provider doesn't support quota API
  3. For resources that don't support quota API (e.g., Microsoft.DocumentDB, or when you get BadRequest from az quota list):

    • Invoke azure-resource-lookup skill to count existing deployments of that resource type in the selected subscription and region
    • Use the count to calculate: Total After Deployment = Current Count + Planned Deployment
    • Reference Azure service limits documentation for the limit value
    • Document in provisioning checklist as "Fetched from: azure-resource-lookup + Official docs"
  4. Validate deployment capacity:

    • Compare planned deployment quantities against available quota (limit - current usage)
    • If insufficient capacity is found, notify the customer and return to Step 4 to select a different region
    • Use azure-quotas skill to compare capacity across multiple regions and recommend alternatives

Record in Plan

After confirmation, record in .azure/deployment-plan.md:

## Azure Context
- **Subscription**: jongdevdiv (25fd0362-aa79-488b-b37b-d6e892009fdf)
- **Location**: eastus2

Step 6: Apply to AZD Environment

⛔ CRITICAL for Aspire and azd projects: After user confirms subscription and location, you MUST set these values in the azd environment immediately after running azd init or azd env new. Always use --no-prompt with these commands to prevent interactive prompts from blocking execution.

DO NOT wait until validation or deployment. The Azure CLI and azd maintain separate configuration contexts.

For Aspire projects using azd init --from-code:

# 1. Run azd init
azd init --from-code -e <environment-name> --no-prompt

# 2. IMMEDIATELY set the user-confirmed subscription
azd env set AZURE_SUBSCRIPTION_ID <subscription-id>

# 3. Set the location
azd env set AZURE_LOCATION <location>

# 4. Verify
azd env get-values

For non-Aspire projects using azd env new:

# 1. Create environment
azd env new <environment-name> --no-prompt

# 2. IMMEDIATELY set the user-confirmed subscription
azd env set AZURE_SUBSCRIPTION_ID <subscription-id>

# 3. Set the location
azd env set AZURE_LOCATION <location>

# 4. Verify
azd env get-values

Why this is critical:

  • az account show returns the Azure CLI's default subscription
  • azd maintains its own configuration with potentially different defaults
  • If you don't set AZURE_SUBSCRIPTION_ID explicitly, azd will use its own default
  • This can result in deploying to the wrong subscription despite user confirmation

Source: SKILL.md on GitHub

1 alert8d4 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The azure-prepare skill provides a comprehensive environment for preparing Azure applications for deployment. It focuses on generating infrastructure-as-code and deployment configuration while strictly enforcing security best practices like managed identity usage and secret management via Key Vault. No malicious patterns or security risks were identified.

  • Socket8d

    5 alerts: gptAnomaly, gptSecurity

  • Snyk8d

    Risk: LOW · No issues

  • Runlayer6mo

    68/196 files flagged

Signed by skilld at 7995851. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • Infrastructure
  • azure
  • bicep
  • terraform
  • deployment
  • docker
  • functions
  • app-service

README badge

README badge for microsoft/github-copilot-for-azure/azure-prepare

Prepares Azure applications for deployment by generating infrastructure templates (Bicep or Terraform), azure.yaml configuration, and Dockerfiles. Covers new app creation, modernization, and hosting on App Service, Container Apps, or Functions—but excludes Python App Service deployments, copilot SDK apps, and cross-cloud migrations which have dedicated skills.

Generated from the current SKILL.md.

Does this skill handle Python App Service deployments?
No. Use the python-appservice-deploy skill instead for Python code-only App Service deploys.
Can I use this skill for cross-cloud migration?
No. This skill is for Azure-native preparation. Use azure-cloud-migrate for migrations from AWS, GCP, or other clouds.
Does this skill support Copilot SDK apps?
No. Use azure-hosted-copilot-sdk for apps with @github/copilot-sdk or CopilotClient.
What infrastructure templates does this skill support?
Azure Developer CLI (azd), Bicep, Terraform, and Azure CLI. The skill creates infrastructure code, Dockerfiles, and configuration files—actual deployment execution is handled by the azure-deploy skill.
Does this skill delete existing project files?
No. When adding features to existing projects, it modifies files rather than deletes them. It never removes the project or workspace directory itself.

Generated from the current SKILL.md. These answers refresh after source changes.