All skills
microsoft avatar

/deploy

@b8a1c66
by microsoftmicrosoft/skills3.1k stars
351

Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents

  • 16 files
  • 84.7 KB
  • Updated last week
  • GitHub

Use this Skill: https://skilld.dev/gh/microsoft/skills/deploy

This session only. Nothing lands on disk.

SKILL.md

โ‰ˆ22 tokens always: the name and description. โ‰ˆ1.9k when used: this file. โ‰ˆ19k more on demand in 14 files.

Deploy โ€” IaC Execution & Health Verification

Quick Reference

Property Value
Best for Executing validated IaC against Azure, health-checking deployed resources
Inputs prepare-plan.json + scaffold-manifest.json from .copilot-azure/sessions/{id}/
Outputs deploy-result.json written to session directory
Parent azure-app-onboard

When to Use This Skill

Invoked by the azure-app-onboard orchestrator at Phase 4 when scaffold-manifest.json exists with files[] and validationResult. Not directly user-routable.

Return to orchestrator: When complete, return control to azure-app-onboard for handoff (Step 10). Do NOT start new phases.

When NOT to Use

Scenario Use Instead
Plan architecture, map services, estimate costs prepare
Generate IaC files from a plan azure-app-onboard Step 7 (scaffold)
Run azd up or execute existing deployment templates azure-deploy
Debug a running app after deployment azure-diagnostics
Optimize existing Azure spending cost-optimization from the optional azure-cost plugin

If cost-optimization is unavailable, explain that it is provided by the optional azure-cost plugin and direct the user to their client's supported plugin installation flow; do not imply the handoff completed.

Workflow

โ›” Sub-agent delegation is MANDATORY for Step 0. Read subagent-preflight.md, then dispatch as a task with the COMPLETE and UNMODIFIED template text between <<<TEMPLATE_START>>> / <<<TEMPLATE_END>>> delimiters. Do NOT summarize or rewrite the template โ€” the sub-agent needs every "Read [file]" instruction to produce a correct deploy-checklist.md. Append session artifact data AFTER the template block. If your next action after reading the template is anything other than task, you are executing it inline instead of delegating.

โ›” Healing loop: ask user after 3 attempts, then every 5 (counter = healingAttempts[].length).

โ›” Region lock: Before az deployment retry, compare --location against prepare-plan.json.deploymentVariables.location. If changed โ†’ re-approval gate required. Update plan after approval.

โ›” After compaction or any az deployment/az webapp deploy/az acr build/failed health check: re-read deploy-checklist.md. If missing โ†’ fill from deploy-checklist-template.md. On significant context loss: also re-read this SKILL.md.

# Step Action Artifact Reference
0 Dispatch preflight sub-agent โ›” You MUST dispatch subagent-preflight.md as a task. โ›” agent_type: "task" โ€” NEVER "general-purpose". Read the template, then your NEXT action MUST be task. If after reading the template your next action is powershell, view, or anything other than task, STOP โ€” you are executing inline instead of delegating. Writes deploy-checklist.md. view it immediately after return. deploy-checklist.md โ›” You MUST read subagent-preflight.md
1 Read upstream artifacts Load prepare-plan.json + scaffold-manifest.json. Check validationResult. Resolve subscription + deployment variables. โ€” โ€”
3 Preflight checks Auth, mandatory what-if preview, RBAC, RG per deploy-checklist.md ยง Preflight. โ€” โ›” You MUST read deploy-checklist.md (re-read if compaction occurred)
4 Deploy approval gate Present cost + resource summary per deploy-checklist.md ยง Deploy approval gate format. โ€” โ€”
5b Write deploy-result.json skeleton โ›” Read deploy-schemas.ts, write skeleton (status: "in-progress"). Must exist BEFORE first az command. deploy-result.json โ›” You MUST read deploy-schemas.ts
6 Execute deployment โ›” BEFORE az deployment sub create: Generate portal link โ€” $dn="{deploymentName}"; $r="/subscriptions/{subId}/providers/Microsoft.Resources/deployments/$dn"; $l="https://portal.azure.com/#view/Microsoft_Azure_Resources/DeploymentDetails.MenuView/~/overview/id/$($r.Replace('/','%2F'))"; Write-Output "LINK=$l". โ›” Auto-open link in browser: Start-Process $l 2>$null. Print bare URL in chat (ctrl-clickable).<br>Auto-generate ALL @secure() params (openssl rand -base64 32 | tr -d '/+='), NEVER ask_user for passwords; on retry reuse from deploy-secrets.env or Key Vault โ€” NEVER regenerate (see deploy-safety.md ยง Deploy Checklist). THEN deploy IaC. โ€” โ›” You MUST read deploy-checklist.md ยง Execute deployment
6b Deploy application code โ›” Deploy code for EVERY service in prepare-plan.json.services[]. Follow deploy-checklist.md ยง Code deploy. โ€” โ›” You MUST read deploy-checklist.md ยง Code deploy
7 Health-check + SCM re-disable HTTP GET per endpoint (max 3 iterations). โ›” Multi-service apps: Also inspect the response body for error patterns (connection refused, MODULE_NOT_FOUND, localhost, SET-IN-DEPLOY-PHASE) โ€” HTTP 200 alone does not mean functional when the app depends on another service or KV secrets. Then โ›” for EVERY App Service/Functions app run BOTH commands โ€” no exceptions: az rest --method put --url "/subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.Web/sites/{app}/basicPublishingCredentialsPolicies/scm?api-version=2023-12-01" --headers "Content-Type=application/json" --body '{"properties":{"allow":false}}' then verify: az rest --method get --url "/subscriptions/{sub}/resourceGroups/{rg}/providers/Microsoft.Web/sites/{app}/basicPublishingCredentialsPolicies/scm?api-version=2023-12-01" --query properties.allow -o tsv (must return false). deploy-result.json full โ›” You MUST read deploy-checklist.md ยง Health check
8 Finalize artifacts โ›” Read deploy-schemas.ts. โ›” Re-read deploy-checklist.md ยง Artifact verification โ€” follow ALL 5 checks. โ›” No "live"/handoff message until you overwrite the skeleton deploy-result.json โ€” flip status off "in-progress" (โ†’ succeeded/failed) and fill healthStatus, endpoints, completedUtc, deploymentNames, healingAttempts. Write deployment-summary.md (status table + health + portal link(s) + cleanup commands โ€” same content as your handoff message). Update context.json โ€” add "deploy" to completedPhases, currentPhase: null, lastModifiedUtc. Read back to confirm status != "in-progress" and "deploy" โˆˆ completedPhases. โ›” Then STOP โ€” return to orchestrator. No further CLI commands. deploy-result.json final + deployment-summary.md + context.json update โ›” You MUST read deploy-schemas.ts + โ›” Re-read deploy-checklist.md ยง Artifact verification
9 Error handling + healing โ›” Only if Steps 6/6b/7 returned nonzero exit code or health check failed. Skip entirely on clean deploys. Classify errors, healing loop, PLAN_LEVEL_CHANGE re-approval per deploy-checklist.md ยง During healing. โ›” Even on unrecoverable failure: write deploy-result.json with status: "failed" and errorDetails before returning to orchestrator โ€” the artifact must always exist. โ€” โ›” You MUST read error-classification.md

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at b8a1c66. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 19 hours ago.

Activeupdated last week

README badge

README badge for microsoft/skills/deploy