All skills
microsoft avatar

/azure-validate

@e0a67fd
by microsoftmicrosoft/skills3.1k stars
351

Pre-deployment validation for Azure readiness. Run deep checks on configuration, infrastructure (Bicep or Terraform), RBAC role assignments, managed identity permissions, and prerequisites before deploying. WHEN: validate my app, check deployment readiness, run preflight checks, verify configuration, check if ready to deploy, validate azure.yaml, validate Bicep, test before deploying, troubleshoot deployment errors, validate Azure Functions, validate function app, validate serverless deployment, verify RBAC roles, check role assignments, review managed identity permissions, what-if analysis, validate Container Apps deployment.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-validate

This session only. Nothing lands on disk.

referencesrecipesazcliREADME.md

≈719 tokens on demand. Your agent reads this file only when SKILL.md points to it.

AZCLI Validation

Validation steps for Azure CLI deployments.

Prerequisites

  • ./infra/main.bicep exists
  • Docker available (if containerized)

Validation Steps

  • 1. Core Validation (CLI, auth, build, validate, what-if) — run validate-deployment script
  • 2. Docker Build (if containerized)
  • 3. Azure Policy Validation

Validation Details

1. Core Validation Script

The core validation checks are a fixed, deterministic sequence. Run the shared validate-deployment helper instead of executing and parsing each command by hand. It confirms the Azure CLI is installed and authenticated, compiles the Bicep template (az bicep build), validates it against the target scope (az deployment ... validate), and runs a what-if preview — printing a compact PASS/FAIL summary plus a what-if change count (Create/Modify/Delete).

Subscription scope:

../scripts/validate-deployment.sh --scope sub --location <location>
../scripts/validate-deployment.ps1 -Scope sub -Location <location>

Resource group scope:

../scripts/validate-deployment.sh --scope group --resource-group <rg-name>
../scripts/validate-deployment.ps1 -Scope group -ResourceGroup <rg-name>

Defaults: --template ./infra/main.bicep, --parameters ./infra/main.parameters.json (skipped if absent). Pass --subscription <id> to target a specific subscription.

Interpreting results:

  • OVERALL: PASS — all five checks passed; record the summary in Section 7 (Validation Proof).
  • Any step FAIL — the script prints the failing command's error. Remediate:
    • Authenticated fails → az login, then az account set --subscription <id>.
    • Azure CLI installed fails → install via mcp_azure_mcp_extension_cli_install(cli-type: "az").
    • Otherwise see Error handling.

2. Docker Build (if containerized)

Before building, validate the Docker build context:

  1. Read the Dockerfile in ./src/<service>
  2. If the Dockerfile contains npm ci, verify package-lock.json exists in the same directory
  3. If package-lock.json is missing, generate it:
cd ./src/<service>
npm install --package-lock-only

Then build:

docker build -t <image>:test ./src/<service>

3. Azure Policy Validation

See Policy Validation Guide for instructions on retrieving and validating Azure policies for your subscription.

References

Next

All checks pass → azure-deploy

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a structured workflow for validating Azure deployments, covering Bicep, Terraform, and Azure Developer CLI (AZD) projects. It uses several helper scripts to automate configuration checks and infrastructure validation. The skill includes security considerations such as the execution of system commands and the processing of project source files, which are used within its intended validation scope.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    14/14 files flagged

Signed by skilld at e0a67fd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "1.2.2"
}

README badge

README badge for microsoft/skills/azure-validate