All skills
microsoft avatar

/azure-app-onboard

@b8a1c66
by microsoftmicrosoft/skills3.1k stars
351

End-to-end orchestrator: from a business idea, app idea, or existing app to running Azure deployment with cost estimates and pre-deploy approval. Analyzes your app, auto-detects the right Azure services, scaffolds infrastructure code, and deploys — tailored to your app, not a template. Handles moving existing apps to Azure without rewriting or with minimal changes. WHEN: bring your app to Azure, plan my app, cost to run, is my code ready to deploy, deploy my app to the cloud, deploy all my services, what Azure services do I need, plan my Azure deployment, deploy my new app to Azure, one-click deploy, I have an app and want it on Azure, migrate my app to Azure, help me get started, build an app, no code yet, starter project. DO NOT USE FOR: use azd for deployment(use azure-deploy), optimizing existing costs (use cost-optimization), code readiness checks only (use azure-app-onboard-prereq).

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-app-onboard

This session only. Nothing lands on disk.

deployreferencescode-deployment-appservice.md

≈1.2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Code Deployment — App Service & Functions

After IaC deployment creates the Azure resources, deploy application code.

⛔ --subscription {subscriptionId} on EVERY az command.

⛔ Verify SCM_DO_BUILD_DURING_DEPLOYMENT=true is active BEFORE deploying. ARM timing can delay propagation. Check: az webapp config appsettings list -g {rg} -n {app} --query "[?name=='SCM_DO_BUILD_DURING_DEPLOYMENT'].value" -o tsv. If not true: az webapp config appsettings set -g {rg} -n {app} --settings SCM_DO_BUILD_DURING_DEPLOYMENT=true ENABLE_ORYX_BUILD=true. Wait 10s. If az webapp deploy reports "Build successful. Time: 0(s)", Oryx was skipped — use Kudu zipdeploy instead.

⛔ ORYX_DISABLE_COMPRESSION=true and WEBSITES_CONTAINER_START_TIME_LIMIT=1800 must be in Bicep app settings (from prepare-plan.json.deployStrategy.requiredAppSettings).

Pre-Deploy Verification (Step 6a)

⛔ TypeScript projects: Oryx with NODE_ENV=production skips devDependencies. If typescript, @types/*, or build tools are in devDependencies, move them to dependencies before zipdeploy. Alternative: set NPM_CONFIG_PRODUCTION=false as app setting so Oryx installs devDeps during build.

⛔ Wait for App Service to stabilize (F1: 30-120s cold start). Poll az webapp show -g {rg} -n {app} --query state every 10s, max 2 min. If not Running, check logs.

When deployStrategy.codeDeployPattern == "startup-install", surface: "⚠️ First cold start: 2-5 min (native module compilation)."

Zip Deploy (Step 6b)

SCM lifecycle: enable → deploy → re-disable.

Enable SCM:

az rest --method put --url "/subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.Web/sites/{app}/basicPublishingCredentialsPolicies/scm?api-version=2023-12-01" --headers "Content-Type=application/json" --body '{"properties":{"allow":true}}'

Choose deploy method:

Runtime Needs Oryx? Method
Python, Node.js, Ruby, PHP Yes Kudu zipdeploy (/api/zipdeploy)
.NET, Java, static front-end No az webapp deploy --type zip

⛔ OneDeploy NEVER triggers Oryx — use Kudu zipdeploy for runtimes needing server-side install. ⛔ NEVER use az webapp deployment source config-zip — deprecated. ⛔ az webapp deploy does NOT support --track-status.

Kudu Zipdeploy (Oryx-Dependent Runtimes)

For apps needing server-side package installation (Python, Node.js, Ruby, PHP), use Kudu zipdeploy directly:

# Get publishing credentials
$creds = az webapp deployment list-publishing-credentials --subscription {sub} -g {rg} -n {app} --query "{user:publishingUserName, pass:publishingPassword}" -o json | ConvertFrom-Json
$auth = [Convert]::ToBase64String([Text.Encoding]::ASCII.GetBytes("$($creds.user):$($creds.pass)"))

# Deploy via Kudu zipdeploy (triggers Oryx pip install)
Invoke-WebRequest -Uri "https://{app}.scm.azurewebsites.net/api/zipdeploy?isAsync=true" -Method POST -InFile $zipPath -Headers @{Authorization="Basic $auth"} -ContentType "application/zip" -UseBasicParsing

# Poll until build completes
for ($i = 1; $i -le 40; $i++) {
  Start-Sleep -Seconds 15
  $resp = Invoke-WebRequest -Uri "https://{app}.scm.azurewebsites.net/api/deployments/latest" -Headers @{Authorization="Basic $auth"} -UseBasicParsing
  $deploy = $resp.Content | ConvertFrom-Json
  if ($deploy.complete -eq $true) { break }
}

Prerequisites:

  • SCM_DO_BUILD_DURING_DEPLOYMENT=true must be set (verified in Step 6a)
  • Runtime manifest must be at the zip root — Oryx detects the runtime from it:
    • Python: requirements.txt (or pyproject.toml)
    • Node.js: package.json (+ lockfile)
    • Ruby: Gemfile
    • PHP: composer.json
  • Do NOT pre-install packages locally — let Oryx run the install remotely

SCM auth lifecycle (REST API toggle — no Bicep edits):

IaC has scm.allow: true (deploy convenience). Deploy phase: Deploy code → health check → re-disable via REST API → verify false. If re-disable fails, log but don't block — add postDeployRecommendation.

Zip creation: Use System.IO.Compression.ZipFile with relative paths from workspace root. On Windows, normalize entry paths: $entryName = $relativePath.Replace('\', '/') — ZipFile preserves backslashes which Linux App Service cannot resolve. Never use Compress-Archive -Path $files.FullName — absolute paths flatten the directory structure, causing app crashes (./src/app not found).

Database Post-Deploy Verification

⛔ You MUST read database-post-deploy.md for migration discovery, execution via App Service SSH, error handling, and PostgreSQL-specific checks.

Source: SKILL.md on GitHub

No alerts3d3 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill provides a comprehensive end-to-end orchestrator for deploying applications to Azure. It incorporates several security-focused patterns, such as secrets management via Azure Key Vault, managed identity integration, and robust preflight validation. There are some security considerations, such as a surface for indirect prompt injection during workspace analysis and broad default firewall rules, but these are managed through explicit user approval gates and documented trade-offs.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

Signed by skilld at b8a1c66. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "1.2.4"
}

README badge

README badge for microsoft/skills/azure-app-onboard