All skills
microsoft avatar

/azure-validate

@e0a67fd
by microsoftmicrosoft/skills3.1k stars
351

Pre-deployment validation for Azure readiness. Run deep checks on configuration, infrastructure (Bicep or Terraform), RBAC role assignments, managed identity permissions, and prerequisites before deploying. WHEN: validate my app, check deployment readiness, run preflight checks, verify configuration, check if ready to deploy, validate azure.yaml, validate Bicep, test before deploying, troubleshoot deployment errors, validate Azure Functions, validate function app, validate serverless deployment, verify RBAC roles, check role assignments, review managed identity permissions, what-if analysis, validate Container Apps deployment.

Use this Skill: https://skilld.dev/gh/microsoft/skills/azure-validate

This session only. Nothing lands on disk.

referencesrecipesterraformerrors.md

≈743 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Terraform Validation Errors

Error Fix
Backend init failed Check storage account access
Provider version conflict Update required_providers
State lock failed Wait or force unlock
Validation failed Check terraform validate output
Error: Cycle: See Cycle Errors below

Cycle Errors

terraform validate reports a cycle when two or more resources reference each other's attributes, creating a circular dependency.

Common Pattern: CORS Cross-Reference

Multi-service App Service deployments often introduce a cycle when the API's CORS configuration references the frontend hostname and the frontend's app settings reference the API hostname:

Error: Cycle: azurerm_linux_web_app.frontend, azurerm_linux_web_app.api

Cause — circular attribute references:

# API references frontend.default_hostname in CORS
resource "azurerm_linux_web_app" "api" {
  site_config {
    cors {
      allowed_origins = ["https://${azurerm_linux_web_app.frontend.default_hostname}"]
    }
  }
}

# Frontend references api.default_hostname in app_settings
resource "azurerm_linux_web_app" "frontend" {
  app_settings = {
    API_URL = "https://${azurerm_linux_web_app.api.default_hostname}"
  }
}

Fix Strategies

Option A (recommended): Use a Terraform variable for the frontend origin so CORS is restrictive by default and the cycle is broken. Define the variable with a sensible default and pass the real frontend URL after the first deployment:

variable "frontend_origin" {
  type        = string
  description = "Frontend origin for API CORS. Set after first deployment."
  default     = ""
}

resource "azurerm_linux_web_app" "api" {
  site_config {
    cors {
      allowed_origins     = var.frontend_origin != "" ? [var.frontend_origin] : ["*"]
      support_credentials = var.frontend_origin != "" ? true : false
    }
  }
}

⚠️ Warning: If using ["*"] as a temporary bootstrap value, you must set frontend_origin to the actual URL (e.g., https://app-web-*.azurewebsites.net) and re-run terraform apply in the same deployment session before reporting success. Do not leave wildcard CORS in a completed deployment.

Option B: Use azurerm_app_service_custom_hostname_binding or a null_resource with a local-exec provisioner to configure CORS after both resources are created, breaking the dependency chain.

Option C: Use lifecycle { ignore_changes = [site_config[0].cors] } on the API resource and configure CORS via a separate azurerm_web_app_active_slot or post-deployment script.

After Fixing

  1. Run terraform fmt -recursive to fix formatting
  2. Re-run terraform validate to confirm the cycle is resolved
  3. Run terraform plan to verify the configuration is correct

Debug

TF_LOG=DEBUG terraform plan

Source: SKILL.md on GitHub

1 warning15d4 checks · Risk SAFE
  • Gen Agent Trust Hub15d

    This skill provides a structured workflow for validating Azure deployments, covering Bicep, Terraform, and Azure Developer CLI (AZD) projects. It uses several helper scripts to automate configuration checks and infrastructure validation. The skill includes security considerations such as the execution of system commands and the processing of project source files, which are used within its intended validation scope.

  • Socket15d

    No alerts

  • Snyk15d

    Risk: LOW · No issues

  • Runlayer7mo

    14/14 files flagged

Signed by skilld at e0a67fd. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 19 hours ago.

Activeupdated 2 months ago
metadata
{
  "author": "Microsoft",
  "version": "1.2.2"
}

README badge

README badge for microsoft/skills/azure-validate