All skills
microsoft avatar

/azure-prepare

@b8a1c66
by microsoftmicrosoft/skills3.1k stars
351

Prepare azd-based Azure projects for deployment: generates azure.yaml, infrastructure (Bicep/Terraform), and Dockerfiles for the Azure Developer CLI (azd) workflow. USE ONLY when the user explicitly wants to use azd as the deployment tool, or the project already has an azure.yaml file. DO NOT USE FOR: non-azd deployments, Python App Service code-only deploys (use python-appservice-deploy), or cross-cloud migration (use azure-cloud-migrate). WHEN: prepare app for azd, create azure.yaml, set up azd infrastructure, modernize app for Azure with azd, deploy with azd, function app, timer trigger, service bus trigger, event-driven function, managed identity, generate Bicep, generate Terraform, create and deploy to Azure.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-prepare

This session only. Nothing lands on disk.

referencesrecipesazdiac-rules.md

≈1.5k tokens on demand. Your agent reads this file only when SKILL.md points to it.

AZD IAC Rules

IaC rules for AZD projects. Additive — for Bicep, apply mcp_bicep_get_bicep_best_practices, mcp_bicep_list_avm_metadata, and mcp_bicep_get_az_resource_type_schema first; for Terraform, apply mcp_azure_mcp_azureterraformbestpractices first; then apply these azd-specific rules.

AVM Module Selection Order (MANDATORY)

Always prefer modules in provider-specific order:

For Bicep:

  1. AVM Bicep Pattern Modules (AVM+AZD first when available)
  2. AVM Bicep Resource Modules
  3. AVM Bicep Utility Modules

For Terraform:

  1. AVM Terraform Pattern Modules
  2. AVM Terraform Resource Modules
  3. AVM Terraform Utility Modules

If no pattern module exists for the active provider, default immediately to AVM modules in the same provider order (resource, then utility) instead of using non-AVM modules.

Retrieval Strategy (azure-documentation MCP primary + optional Context7)

  • Primary (authoritative): Use mcp_azure_mcp_documentation (azure-documentation) for current Azure guidance and AVM integration documentation.
  • Primary (module catalog): Use mcp_bicep_list_avm_metadata plus official AVM indexes to select concrete modules.
  • Secondary (supplemental): Use Context7 only for implementation examples when mcp_azure_mcp_documentation does not provide enough detail. If Context7 is not available, instruct the user to install it: npx -y @upstash/context7-mcp@latest.

Validation Plan

Before finalizing generated guidance:

  1. Verify the selected module path uses the required AVM order above.
  2. Verify AVM+AZD pattern modules were checked first, and fallback moved to AVM resource/utility modules when no pattern module exists.
  3. Verify Terraform guidance follows pattern -> resource -> utility ordering.
  4. Include selected module names and source links in the plan/output for traceability.

File Structure

Requirement Details
Location ./infra/ folder
Entry point main.bicep with targetScope = 'subscription'
Parameters main.parameters.json (ARM JSON — see format below)
Modules ./infra/modules/*.bicep with targetScope = 'resourceGroup'

Parameter File Format

main.parameters.json uses ARM JSON syntax. Do not use .bicepparam syntax (using, param, readEnvironmentVariable()) in this file — azd will fail with a JSON parse error.

{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentParameters.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "environmentName": { "value": "${AZURE_ENV_NAME}" },
    "location": { "value": "${AZURE_LOCATION}" }
  }
}

Use azd env set to supply values. During azd provision, azd substitutes ${VAR} placeholders with values from the environment.

Naming Convention

⚠️ Before generating any resource name in Bicep, check Resource naming rules for that resource type's valid characters, length limits, and uniqueness scope. Some resources forbid dashes or special characters, require globally unique names, or have short length limits. Adapt the pattern below accordingly.

Default pattern: {resourceAbbreviation}-{name}-{uniqueHash}

For resources that disallow dashes, omit separators: {resourceAbbreviation}{name}{uniqueHash}

var resourceSuffix = take(uniqueString(subscription().id, environmentName, location), 6)
// Adapt separator/format per resource naming rules
var defaultName = '${name}-${resourceSuffix}'
var alphanumericName = replace('${name}${resourceSuffix}', '-', '')

Forbidden: Hard-coded tenant IDs, subscription IDs, resource group names

Required Tags

Tag Apply To Value
azd-env-name Resource group {environmentName}
azd-service-name Hosting resources Service name from azure.yaml

Module Parameters

All modules must accept: name (string), location (string), tags (object)

Security

Rule Details
No secrets Use Key Vault references
Managed Identity Least privilege
Diagnostics Enable logging
API versions Use latest

Recommended Outputs

azd reads output values from main.bicep and stores UPPERCASE names as environment variables (accessible via azd env get-values).

Output When
AZURE_RESOURCE_GROUP Always (required)
AZURE_CONTAINER_REGISTRY_ENDPOINT If using containers
AZURE_KEY_VAULT_NAME If using secrets
AZURE_LOG_ANALYTICS_WORKSPACE_ID If using monitoring
API_URL, WEB_URL, etc. One per service endpoint

Templates

main.bicep:

targetScope = 'subscription'

param environmentName string
param location string

var resourceSuffix = take(uniqueString(subscription().id, environmentName, location), 6)
var tags = { 'azd-env-name': environmentName }

resource rg 'Microsoft.Resources/resourceGroups@2023-07-01' = {
  name: 'rg-${environmentName}'
  location: location
  tags: tags
}

module resources './modules/resources.bicep' = {
  name: 'resources'
  scope: rg
  params: { location: location, tags: tags }
}

// Outputs — UPPERCASE names become azd env vars
output AZURE_RESOURCE_GROUP string = rg.name
output API_URL string = resources.outputs.apiUrl

Child module:

targetScope = 'resourceGroup'

param name string
param location string = resourceGroup().location
param tags object = {}

var resourceSuffix = take(uniqueString(subscription().id, resourceGroup().name, name), 6)

⚠️ Container resources: CPU must use json() wrapper: cpu: json('0.5'), memory as string: memory: '1Gi'

Source: SKILL.md on GitHub

2 warnings3d4 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill includes security considerations related to the processing of untrusted project files and the retrieval of external development templates. While these operations are essential for modernizing and preparing Azure applications, they represent a surface area for indirect prompt injection and depend on the integrity of external template repositories.

  • Socket3d

    5 alerts: gptAnomaly, gptSecurity

  • Snyk3d

    Risk: LOW · No issues

  • Runlayer7mo

    86/87 files flagged

Signed by skilld at b8a1c66. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated last week
metadata
{
  "author": "Microsoft",
  "version": "1.3.4"
}

README badge

README badge for microsoft/skills/azure-prepare