All skills
microsoft avatar

/azure-app-onboard-prereq

@ae5e585
by microsoftmicrosoft/skills3.1k stars
351

Assess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work. Evaluates build health, app completeness, dependencies and local services, stack compatibility, and deployment feasibility. Answers questions about what your app needs before it can be deployed — frameworks, dependencies, and configuration. Checks whether dependencies are compatible and identifies deployment blockers and unsupported frameworks. WHEN: "evaluate my repo", "is my app ready to deploy", "what does my app need to deploy", "what do I need before deploying", "does my app need", "can I ship this to Azure", "scan my repo for issues", "is this app deployable", "check if my app is ready for Azure", "do I need a Dockerfile", "what's blocking my deployment", "are there any blockers", "are my dependencies compatible", "does Azure support my framework", "what needs to change before deploying", "check my app configuration".

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-app-onboard-prereq

This session only. Nothing lands on disk.

referencescompleteness-check.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Completeness Check

⛔ No build/install/test commands during this check. Use static analysis only.

Verify repository has required components for a deployable app.

1. Entry Point

Verify main/index file exists for each component.

Stack Expected Entry Point
Node.js main or start script in package.json
Python app.py, main.py, manage.py, or entry in pyproject.toml
.NET Program.cs or Startup.cs with <OutputType>Exe</OutputType>
Java Class with public static void main or @SpringBootApplication
Go main.go in package main
Static index.html at root or in output folder
Outcome Verdict
Entry point found and file exists on disk ✅ PASS
Ambiguous (multiple candidates) ⚠️ WARN
No entry point ❌ FAIL
Entry point declared but file missing ❌ FAIL — MODULE_NOT_FOUND

2. Dependency Manifest

Outcome Verdict
Manifest found with dependencies ✅ PASS
Manifest exists but empty deps ⚠️ WARN
No manifest found ❌ FAIL (unless static site)

⛔ Oryx reads manifests ONLY at repo root. Subdirectory manifests → ⚠️ WARN (🔧 Fix): create root wrapper (Python: -r {subdir}/requirements.txt, Node: workspaces). Add to batch-then-approve.

3. Configuration

Outcome Verdict
Config properly externalized ✅ PASS
Hardcoded values but no secrets ⚠️ WARN
Hardcoded secrets in source (no env var fallback) ❌ FAIL
Env var + hardcoded fallback default ⚠️ WARN
.env with placeholder values + runtime validation ✅ PASS

Compose file credentials: Literal *PASSWORD=<value> with NO ${VAR} → ❌ FAIL. ${VAR:-default} → ⚠️ WARN. ${VAR} only → ✅ PASS. ⛔ Do NOT downgrade based on filename ("dev-only") — treat every compose file as potentially production-bound.

4. Documentation

README with build/run instructions → ✅ PASS. Sparse/no README → ⚠️ WARN.

5. Listening Port

Web apps must bind a port. Detect via app.listen, PORT env var, framework port config, WebApplication.CreateBuilder() (implicit 5000/5001 .NET 6+).

Outcome Verdict
Port binding detected ✅ PASS
Non-web (CLI, worker, function) ✅ PASS — N/A
Web app with no port binding ❌ FAIL

6. Static Asset Integrity

Parse href/src from HTML tags. Check relative to HTML file directory. Ignore external URLs.

Outcome Verdict
All referenced assets found ✅ PASS
Broken favicon only ⚠️ WARN
Broken <link>, <script>, <img> reference 🔧 Recommended Fix — set fixPhase: "prereq"

7. Container Readiness

Outcome Verdict
Dockerfile + .dockerignore present ✅ PASS
Dockerfile, no .dockerignore ⚠️ WARN
Multi-process container detected ⚠️ WARN
CMD.*uv run or CMD.*poetry run ⚠️ WARN — dep sync at startup fails as non-root. fix: "Replace with direct command" fixPhase: prereq
EXPOSE port mismatch with app 🔧 Fix — mismatch causes 502. Extract to buildRequirements.exposedPort

Stack-Specific Checks

Verify these patterns. Assess severity with tier definitions from readiness-gate.md — only ❌ FAIL if causes deploy failure or startup crash.

  • Node.js: engines field, session store type (MemoryStore = ephemeral), health endpoint
  • Express: trust proxy when secure cookies are used behind reverse proxy
  • Any web app: health endpoint (/health, /healthz), README documentation
  • Static sites: health endpoint is N/A (responds 200 on /)

⛔ Default these to ⚠️ WARN / fixPhase: "postdeploy" — an app that deploys and runs (missing trust proxy, README, in-memory sessions) is not blocked. Escalate to ❌ FAIL / prereq only when the case actually breaks THIS deploy: engines when the app needs a runtime the platform default won't provide, or a health endpoint when a probe is wired to a route the app lacks.

Do not short-circuit. Iterate ALL sub-checks (1–7 + stack-specific) per component.

Severity tiers are defined in readiness-gate.md. Use the verdict tables in checks 1–7 above for deterministic outcomes. For judgment calls, assess based on deployment impact to this specific app.

Source: SKILL.md on GitHub

1 warning1mo3 checks · Risk SAFE
  • Gen Agent Trust Hub1mo

    This skill is an Azure deployment readiness evaluator authored by Microsoft. It performs static analysis of repositories to identify deployment blockers and can offer to fix them or generate starter code. While the skill has capabilities to execute build commands and modify files, these actions are strictly protected by user consent gates and are limited to the skill's intended purpose of onboarding applications to Azure.

  • Socket1mo

    No alerts

  • Snyk1mo

    Risk: MEDIUM · 1 issue

Signed by skilld at ae5e585. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
metadata
{
  "author": "Microsoft",
  "version": "1.2.2"
}

README badge

README badge for microsoft/skills/azure-app-onboard-prereq