All skills
microsoft avatar

/azure-validate

@e0a67fd
by microsoftmicrosoft/skills3.1k stars
351

Pre-deployment validation for Azure readiness. Run deep checks on configuration, infrastructure (Bicep or Terraform), RBAC role assignments, managed identity permissions, and prerequisites before deploying. WHEN: validate my app, check deployment readiness, run preflight checks, verify configuration, check if ready to deploy, validate azure.yaml, validate Bicep, test before deploying, troubleshoot deployment errors, validate Azure Functions, validate function app, validate serverless deployment, verify RBAC roles, check role assignments, review managed identity permissions, what-if analysis, validate Container Apps deployment.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-validate

This session only. Nothing lands on disk.

referencesrecipesterraformREADME.md

≈1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Terraform Validation

Validation steps for Terraform deployments.

Prerequisites

  • ./infra/main.tf exists
  • State backend accessible

Run the preflight script

Run the pre-built validation script instead of executing each check by hand. It runs the full deterministic preflight sequence in one call and prints a compact PASS / FAIL / SKIP summary plus captured error text for any failed step — jump straight to remediation without re-parsing raw command output.

Script Purpose
scripts/validate-terraform.sh Bash preflight runner
scripts/validate-terraform.ps1 PowerShell preflight runner

The script runs, in order: Terraform installed → Azure CLI installed → authenticated (az account show) → terraform init → fmt -check → validate → plan → state list → Go-style {{ .Env.* }} template-variable scan → main.tfvars.json JSON-syntax check. A subscription-selection step is added when a subscription id is supplied. It runs every check even if an earlier one fails, and exits non-zero when any step fails.

Usage:

./scripts/validate-terraform.sh [infra-dir] [subscription-id]   # infra-dir defaults to ./infra
.\scripts\validate-terraform.ps1 [-InfraDir <path>] [-SubscriptionId <id>]

Examples:

./scripts/validate-terraform.sh                 # validate ./infra
./scripts/validate-terraform.sh ./infra 00000000-0000-0000-0000-000000000000
.\scripts\validate-terraform.ps1 -InfraDir ./infra

Reading the output: the summary table lists every step as PASS, FAIL, or SKIP (skipped when a prerequisite such as Terraform or the infra directory is missing). Each FAIL is expanded in a FAILURE DETAILS section with the captured error text. Fix failed steps using the guidance below, then re-run the script.

Remediation

The script only runs and reports — fixing failures is manual. Guidance per step:

Terraform / Azure CLI not installed

Not authenticated / wrong subscription

az login
az account set --subscription <subscription-id>

Format check failed

terraform fmt -recursive

Init / validate / plan / state failures

Read the captured error text in the script output, then consult Error handling.

Azure Policy Validation

The script does not cover policy checks. See Policy Validation Guide for retrieving and validating Azure policies for your subscription.

Template Variable Resolution (AZD+Terraform)

⚠️ CRITICAL for azd+Terraform projects. azd substitutes ${VAR} references in main.tfvars.json via envsubst, but does NOT interpolate Go-style template variables ({{ .Env.* }}). Unresolved Go-style template strings passed to Terraform cause cascading deployment failures, state conflicts, and timeouts.

When the template-variable scan reports FAIL:

  1. Fix the syntax in main.tfvars.json — replace {{ .Env.VAR }} with ${VAR}:
    { "environment_name": "${AZURE_ENV_NAME}", "location": "${AZURE_LOCATION}" }
  2. For additional variables, use TF_VAR_* environment variables:
    azd env set TF_VAR_environment_name "$(azd env get-value AZURE_ENV_NAME)"
  3. Verify that variables.tf declares all required variables.
  4. Re-run the script to confirm terraform validate / plan and the scan now pass.

Prefer putting static defaults in variables.tf default values. Using terraform.tfvars (HCL) for static defaults is acceptable if your team prefers it; this restriction is specifically about avoiding Go-style template expressions in .tfvars.json files.

References

Next

All checks pass → azure-deploy

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a structured workflow for validating Azure deployments, covering Bicep, Terraform, and Azure Developer CLI (AZD) projects. It uses several helper scripts to automate configuration checks and infrastructure validation. The skill includes security considerations such as the execution of system commands and the processing of project source files, which are used within its intended validation scope.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    14/14 files flagged

Signed by skilld at e0a67fd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "1.2.2"
}

README badge

README badge for microsoft/skills/azure-validate