Error Classification
Three error categories for deploy-time failures.
Multi-Error Triage
โ When 3+ errors, classify ALL before fixing ANY. Group by root cause. Present: "Deploy failed with {N} errors from {M} root causes."
Categories
IAC_ERROR โ Route Back to Scaffold
| Example | Fix |
|---|---|
| Invalid property name | Call mcp_bicep_build_bicep with { filePath: "infra/main.bicep" } for structured error details, then fix. Fallback: az bicep build |
| Wrong SKU for region | Substitute from rejectedAlternatives[] |
| Missing required field | Call mcp_bicep_build_bicep for structured error, fix from diagnostics. Fallback: az bicep build |
| Policy violation | Substitute per policy |
| API version not found | Call mcp_bicep_list_az_resource_types_for_provider with { providerNamespace: "..." }. Use latest GA โ no -preview. Fallback: az provider show |
listKeys() in output |
โ Security risk โ replace with KV secret + MI reference |
| KV soft-delete collision | Rename KV (append suffix). If not viable โ user purges manually |
Redis InvalidRequestBody for properties.sku.name |
Bicep type issue โ create via az redis create --sku Basic --vm-size c0, switch Bicep to existing keyword |
Flow: Deploy โ classifies IAC_ERROR โ scaffold self-healing โ re-validate โ retry.
INFRA_TRANSIENT โ Retry with Backoff
| Example | Strategy |
|---|---|
| ARM 429, 409 conflict, RBAC delay, network timeout | 30s โ 60s โ 120s (3 max) |
Container Apps Operation expired |
Check root cause first: image pull failure, port mismatch, health probe timeout, crash loop. Port mismatch โ IAC_ERROR. Image pull โ retry. Crash โ ENVIRONMENT_BLOCKING. |
After 3 failures โ escalate to user.
ENVIRONMENT_BLOCKING โ Surface to User
| Example | Action |
|---|---|
| 403 on sub-scope deploy | โ Try 403 Scope Fallback first (RG-scope). Only block if retry also fails |
| 403 on RG-scope | Surface: az role assignment create --role Contributor --assignee {objectId} --scope {rg} |
| AuthorizationFailed / deny assignment | Get user objectId, suggest role assignment command. Deny assignments โ contact admin |
| Quota exhausted | โ PLAN_LEVEL_CHANGE โ HALT, present region fallback with re-approval |
| Region doesn't support resource | โ PLAN_LEVEL_CHANGE โ same as quota |
LocationIsOfferRestricted |
โ PLAN_LEVEL_CHANGE โ read quotaValidation.offerRestrictions[] for unblocked regions |
| MI sidecar OOM on F1/B1 | Upgrade SKU, remove MI, or switch to Container Apps |
| AADSTS530084 / TF auth failure | Re-scaffold as Bicep + az deployment group create. Never fall back to imperative CLI |
โ During ALL healing: NEVER run
az group delete,az postgres flexible-server delete,az redis delete,az webapp delete, or any destructive resource deletion. Track failed RGs indeploy-result.json.orphanedResourceGroups[]instead. The user deletes at handoff. If you need a clean region retry, use a NEW RG name (append-2) โ do NOT delete-and-recreate.
Healing Trace
Log to deploy-result.json.healingAttempts[]: { attempt, phase, errors: [{ source, detail, classification }], action, result, planLevelChange, changeType, originalValue, newValue }.
โ Repeat failure (same error 2+): Read iac-resources.md ยง Deploy Troubleshooting and
fetch_webpagethe matching URL.
After 3 failed cycles: write partial: true, surface remaining errors. Do NOT auto-rollback.