All skills
microsoft avatar

/azure-prepare

@7995851 official

Prepare azd-based Azure projects for deployment: generates azure.yaml, infrastructure (Bicep/Terraform), and Dockerfiles for the Azure Developer CLI (azd) workflow. USE ONLY when the user explicitly wants to use azd as the deployment tool, or the project already has an azure.yaml file. DO NOT USE FOR: non-azd deployments, Python App Service code-only deploys (use python-appservice-deploy), or cross-cloud migration (use azure-cloud-migrate). WHEN: prepare app for azd, create azure.yaml, set up azd infrastructure, modernize app for Azure with azd, deploy with azd, function app, timer trigger, service bus trigger, event-driven function, managed identity, generate Bicep, generate Terraform, create and deploy to Azure.

Use this Skill: https://skilld.dev/gh/microsoft/github-copilot-for-azure/azure-prepare

This session only. Nothing lands on disk.

referencesservicesdurable-task-schedulerbicep.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Durable Task Scheduler — Bicep Patterns

Bicep templates for provisioning the Durable Task Scheduler, task hubs, and RBAC role assignments.

Scheduler + Task Hub

// Parameters — define these at file level or pass from a parent module
param schedulerName string
param location string = resourceGroup().location

@allowed(['Consumption', 'Dedicated'])
@description('Use Consumption for quickstarts/variable workloads, Dedicated for high-demand/predictable throughput')
param skuName string = 'Consumption'

resource scheduler 'Microsoft.DurableTask/schedulers@2025-11-01' = {
  name: schedulerName
  location: location
  properties: {
    sku: { name: skuName }
    ipAllowlist: ['0.0.0.0/0'] // Required: empty list denies all traffic
  }
}

resource taskHub 'Microsoft.DurableTask/schedulers/taskHubs@2025-11-01' = {
  parent: scheduler
  name: 'default'
}

SKU Selection

SKU Best For
Consumption quickstarts, variable or bursty workloads, pay-per-use
Dedicated High-demand workloads, predictable throughput requirements

💡 TIP: Start with Consumption for development and variable workloads. Switch to Dedicated when you need consistent, high-throughput performance.

⚠️ WARNING: The scheduler's ipAllowlist must include at least one entry (e.g., ['0.0.0.0/0'] for allow-all). An empty array [] denies all traffic, causing 403 errors on gRPC calls even with correct RBAC.

RBAC — Durable Task Data Contributor

The Function App's managed identity must have the Durable Task Data Contributor role on the scheduler resource. Without it, the app receives 403 PermissionDenied on gRPC calls.

// Assumes the UAMI principal ID is passed from the base template's identity module
param functionAppPrincipalId string

var durableTaskDataContributorRoleId = '0ad04412-c4d5-4796-b79c-f76d14c8d402'

resource durableTaskRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  name: guid(scheduler.id, functionAppPrincipalId, durableTaskDataContributorRoleId)
  scope: scheduler
  properties: {
    roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', durableTaskDataContributorRoleId)
    principalId: functionAppPrincipalId
    principalType: 'ServicePrincipal'
  }
}

RBAC — Dashboard Access for Developers

To allow developers to view orchestration status and history in the DTS dashboard, assign the same Durable Task Data Contributor role to the deploying user's identity. Without this, the dashboard returns 403 Forbidden.

// Accept the deploying user's principal ID (azd auto-populates this from AZURE_PRINCIPAL_ID)
param principalId string = ''

resource dashboardRoleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = if (!empty(principalId)) {
  name: guid(scheduler.id, principalId, durableTaskDataContributorRoleId)
  scope: scheduler
  properties: {
    roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', durableTaskDataContributorRoleId)
    principalId: principalId
    principalType: 'User'
  }
}

💡 TIP: This is the same role used for the Function App's managed identity, but assigned with principalType: 'User' to the developer. See the sample repo for a full example.

Connection String App Setting

Include these entries in the Function App resource's siteConfig.appSettings array:

// UAMI client ID from base template identity module - REQUIRED for UAMI auth
param uamiClientId string

{
  name: 'DURABLE_TASK_SCHEDULER_CONNECTION_STRING'
  value: 'Endpoint=${scheduler.properties.endpoint};TaskHub=${taskHub.name};Authentication=ManagedIdentity;ClientID=${uamiClientId}'
}

⚠️ IMPORTANT: The base templates use User Assigned Managed Identity (UAMI). You must include ClientID=<uami-client-id> in the connection string. Without it, the Durable Task SDK cannot resolve the correct identity.

⚠️ WARNING: Always use scheduler.properties.endpoint to get the scheduler URL. Do not construct it manually — the endpoint includes a hash suffix and region (e.g., https://myscheduler-abc123.westus2.durabletask.io).

Provision via CLI

💡 TIP: When hosting Durable Functions, use a Flex Consumption plan (FC1 SKU) rather than the legacy Consumption plan (Y1). Flex Consumption supports identity-based storage connections natively and handles deployment artifacts correctly.

# Install the durabletask CLI extension (if not already installed)
az extension add --name durabletask

# Create scheduler (consumption SKU for getting started)
az durabletask scheduler create \
    --resource-group myResourceGroup \
    --name my-scheduler \
    --location eastus \
    --sku consumption

Source: SKILL.md on GitHub

1 alert8d4 checks · Risk SAFE
  • Gen Agent Trust Hub8d

    The azure-prepare skill provides a comprehensive environment for preparing Azure applications for deployment. It focuses on generating infrastructure-as-code and deployment configuration while strictly enforcing security best practices like managed identity usage and secret management via Key Vault. No malicious patterns or security risks were identified.

  • Socket8d

    5 alerts: gptAnomaly, gptSecurity

  • Snyk8d

    Risk: LOW · No issues

  • Runlayer6mo

    68/196 files flagged

Signed by skilld at 7995851. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 3 weeks ago
metadata
{
  "author": "Microsoft",
  "version": "0.0.0-placeholder"
}
  • Infrastructure
  • azure
  • bicep
  • terraform
  • deployment
  • docker
  • functions
  • app-service

README badge

README badge for microsoft/github-copilot-for-azure/azure-prepare

Prepares Azure applications for deployment by generating infrastructure templates (Bicep or Terraform), azure.yaml configuration, and Dockerfiles. Covers new app creation, modernization, and hosting on App Service, Container Apps, or Functions—but excludes Python App Service deployments, copilot SDK apps, and cross-cloud migrations which have dedicated skills.

Generated from the current SKILL.md.

Does this skill handle Python App Service deployments?
No. Use the python-appservice-deploy skill instead for Python code-only App Service deploys.
Can I use this skill for cross-cloud migration?
No. This skill is for Azure-native preparation. Use azure-cloud-migrate for migrations from AWS, GCP, or other clouds.
Does this skill support Copilot SDK apps?
No. Use azure-hosted-copilot-sdk for apps with @github/copilot-sdk or CopilotClient.
What infrastructure templates does this skill support?
Azure Developer CLI (azd), Bicep, Terraform, and Azure CLI. The skill creates infrastructure code, Dockerfiles, and configuration files—actual deployment execution is handled by the azure-deploy skill.
Does this skill delete existing project files?
No. When adding features to existing projects, it modifies files rather than deletes them. It never removes the project or workspace directory itself.

Generated from the current SKILL.md. These answers refresh after source changes.