All skills
microsoft avatar

/scaffold

@617f8b5
by microsoftmicrosoft/skills3.1k stars
351

Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents

  • 27 files
  • 156.7 KB
  • Updated 2 months ago
  • GitHub

Use this Skill: https://skilld.dev/gh/microsoft/skills/scaffold

This session only. Nothing lands on disk.

referencesbicep-container-apps.md

โ‰ˆ2.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Bicep โ€” Container Apps Patterns

Container Apps-specific Bicep patterns. For shared patterns (skeleton, naming, tags, security defaults, data modules), see bicep-patterns.md.

Two-Phase Wiring

Container Apps + ACR requires two-phase deployment (circular dependency: CA needs ACR image, ACR needs CA identity for AcrPull):

  1. Phase 1: Deploy Container App with placeholder image (mcr.microsoft.com/azuredocs/containerapps-helloworld:latest). โ›” No registries block, no KV secretRef. The placeholder image is pulled from MCR (public). Use registries: [] and secrets: []. RBAC role assignments (AcrPull, KV Secrets User) ARE created in Phase 1 โ€” they don't affect the placeholder deployment and need 1โ€“2 minutes to propagate before Phase 2.
  2. Phase 2: Build + push app image to ACR, redeploy with real image + registries + KV secretRef entries. RBAC is already propagated from Phase 1.

โ›” Placeholder image listens on port 80, not your app's port. Set targetPort conditionally: var effectivePort = containerImage == 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest' ? 80 : appPort. Mismatched ports cause "Operation expired" (health probe can't reach container).

โ›” containerImage param must exist in BOTH main.bicep AND the container app module. Phase 2 passes --parameters containerImage='...' via CLI โ€” if main.bicep lacks the param, the override is silently ignored and the placeholder persists.

// In main.bicep: thread containerImage to module
param containerImage string = 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest'
module containerApp './modules/containerapp.bicep' = {
  params: { containerImage: containerImage /* ...other params... */ }
}

// In containerapp.bicep:
param containerImage string = 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest'
var isPlaceholder = containerImage == 'mcr.microsoft.com/azuredocs/containerapps-helloworld:latest'

resource containerApp 'Microsoft.App/containerApps@2024-03-01' = {
  identity: { type: 'SystemAssigned' }
  properties: {
    configuration: {
      ingress: {
        external: true
        targetPort: isPlaceholder ? 80 : appPort
        allowInsecure: false  // โ›” MANDATORY
      }
      registries: isPlaceholder ? [] : [{ server: acr.properties.loginServer, identity: 'system' }]
      secrets: isPlaceholder ? [] : [ /* KV secretRefs here */ ]
    }
    template: {
      containers: [{
        image: containerImage
        env: [{ name: 'PORT', value: string(isPlaceholder ? 80 : appPort) }]
      }]
    }
  }
}

โ›” Do NOT set revisionSuffix. Omit it entirely โ€” ARM auto-generates unique revision names. Hardcoding revisionSuffix: 'v1' causes Phase 2 redeploy to fail with "revision with suffix v1 already exists."

AcrPull Role Assignment

โ›” AcrPull role GUID: 7f951dda-4ed3-4680-a7ca-43fe172d538d. Copy verbatim โ€” wrong GUIDs cause RoleDefinitionDoesNotExist.

resource acrPullRole 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  name: guid(acr.id, containerApp.id, '7f951dda-4ed3-4680-a7ca-43fe172d538d')
  scope: acr
  properties: {
    roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', '7f951dda-4ed3-4680-a7ca-43fe172d538d')
    principalId: containerApp.identity.principalId
    principalType: 'ServicePrincipal'
  }
}

Log Analytics Workspace Key

โ›” Use resource.listKeys(), NOT reference(). reference() does not expose primarySharedKey.

// โœ… Correct
var laKey = logAnalyticsWorkspace.listKeys().primarySharedKey

// โŒ Wrong
var laKey = reference(logAnalyticsWorkspace.id, '2023-09-01').primarySharedKey

Log Analytics customerId vs resource ID

โ›” Output BOTH id and customerId from the log-analytics module. Container Apps Environment needs the GUID customerId. App Insights needs the ARM resource ID. Do NOT use split(workspaceId, '/')[8] โ€” that extracts the workspace name, not the GUID.

// log-analytics.bicep outputs:
output id string = logAnalyticsWorkspace.id                            // ARM resource ID
output customerId string = logAnalyticsWorkspace.properties.customerId // GUID
output sharedKey string = logAnalyticsWorkspace.listKeys().primarySharedKey

// container-app-environment.bicep:
param workspaceCustomerId string  // GUID, NOT resource ID
// โ›” MUST nest under appLogsConfiguration.destination='log-analytics' โ€” a bare top-level logAnalyticsConfiguration fails deploy (ManagedEnvironmentInvalidSchema). This nesting is the ONLY valid location at EVERY API version (the flat shape was never valid โ€” NOT version drift, so do not chase API-version pins). This is the CA's only log path (no diagnostic-settings module).
properties: {
  appLogsConfiguration: {
    destination: 'log-analytics'
    logAnalyticsConfiguration: {
      customerId: workspaceCustomerId
      sharedKey: workspaceSharedKey
    }
  }
}
// โŒ WRONG: customerId: split(workspaceId, '/')[8]

Ingress & Port Mapping

โ›” Container resource limits: Use decimal format for memory: '0.5Gi', '1Gi', '2Gi' โ€” NOT Kubernetes-style '512Mi'. CPU must be type string: '0.25', '0.5', '1'. Valid combos: 0.25/0.5Gi, 0.5/1Gi, 0.75/1.5Gi, 1/2Gi, 1.25/2.5Gi, 1.5/3Gi, 1.75/3.5Gi, 2/4Gi.

โ›” ACR module: retentionPolicy is Premium-only. For Basic/Standard ACR, omit retentionPolicy entirely โ€” ARM rejects it.

Key Vault Secret References

โ›” Container Apps does NOT support @Microsoft.KeyVault(SecretUri=...) syntax. That is App Service-only. Container Apps uses secretRef with managed identity.

Correct pattern โ€” Container Apps secrets from Key Vault:

โŒ WRONG โ€” environment().suffixes.keyvaultDns produces double-dot URL: keyVaultUrl: 'https://${kvName}${environment().suffixes.keyvaultDns}/secrets/...' That function returns .vault.azure.net (WITH leading dot) โ†’ kv-name..vault.azure.net โ†’ ContainerAppSecretKeyVaultUrlInvalid. โœ… Use keyVault.name + .vault.azure.net (hardcoded domain) or keyVaultModule.outputs.vaultUri.

โ›” Every secrets[].keyVaultUrl in a Container App MUST have a matching Microsoft.KeyVault/vaults/secrets child resource in the KV module. If the CA references sshpass via secretRef, the KV module must create that secret. Missing secrets โ†’ SecretNotFound at Phase 2 deploy.

resource containerApp 'Microsoft.App/containerApps@2024-03-01' = {
  identity: {
    type: 'SystemAssigned'
  }
  properties: {
    configuration: {
      secrets: [
        {
          name: 'db-connection-string'
          // โ›” Do NOT replace vault.azure.net with environment().suffixes.keyvaultDns โ€” it adds a leading dot โ†’ double-dot URL
          #disable-next-line no-hardcoded-env-urls
          keyVaultUrl: 'https://${keyVault.name}.vault.azure.net/secrets/db-connection-string'
          identity: 'system'  // Uses the CA's system-assigned managed identity
        }
      ]
    }
    template: {
      containers: [{
        env: [
          {
            name: 'DATABASE_URL'
            secretRef: 'db-connection-string'  // References the secret defined above
          }
        ]
      }]
    }
  }
}

โ›” Never use conditional logic (??, ternary, empty(), union()) to mix plain and secret env vars in a single Bicep loop or array. ARM evaluates ALL property paths in conditional expressions โ€” envVar.secretRef errors on items that don't have that property, producing InvalidTemplate. Instead, define plain and secret env vars as separate arrays and concatenate:

env: concat(
  [
    { name: 'PORT', value: '8000' }
    { name: 'NODE_ENV', value: 'production' }
  ],
  [
    { name: 'DATABASE_URL', secretRef: 'db-connection-string' }
    { name: 'REDIS_URL', secretRef: 'redis-connection-string' }
  ]
)

โ›” KV Secrets User role scoped to Key Vault resource โ€” NOT resourceGroup(). Scoping to resourceGroup() causes 403.

resource kvRole 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  scope: keyVault                    // โ›” scope to KV resource, not RG
  properties: {
    roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', '4633458b-17de-408a-b874-0445c86b69e6') // Key Vault Secrets User
    principalId: containerApp.identity.principalId  // โ›” object ID, NOT clientId
    principalType: 'ServicePrincipal'
  }
}

โŒ WRONG: principalId: .clientId (not the object ID) or identity: containerApp.id in secrets[] (use 'system' for system-assigned MI).

For KV secret seeding and dependency chain, see env-var-secrets.md.

Multi-Container Internal DNS

Container Apps in the same environment communicate via internal DNS: http://{container-app-name}. Set via env vars:

env: [
  { name: 'API_URL', value: 'http://${apiContainerApp.name}' }
  { name: 'WORKER_URL', value: 'http://${workerContainerApp.name}' }
]

No ingress needed for internal-only services โ€” set ingress.external: false or omit ingress entirely.

Networking

โ›” Subnets MUST be defined inline in VNet properties.subnets[], NOT as separate Microsoft.Network/virtualNetworks/subnets child resources. Separate child resources cause InUseSubnetCannotBeDeleted on redeploy when NICs are attached.

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at 617f8b5. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago

README badge

README badge for microsoft/skills/scaffold