All skills
microsoft avatar

/scaffold

@617f8b5
by microsoftmicrosoft/skills3.1k stars
351

Skills, MCP servers, Custom Agents, Agents.md for SDKs to ground Coding Agents

  • 27 files
  • 156.7 KB
  • Updated 2 months ago
  • GitHub

Use this Skill: https://skilld.dev/gh/microsoft/skills/scaffold

This session only. Nothing lands on disk.

referencesbicep-patterns-security.md

โ‰ˆ2k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Bicep Patterns โ€” Security Defaults

Mandatory security configuration for all AppOnboard-generated Bicep. Read during IaC generation before writing resource definitions. Apply during scaffold โ€” never defer to deploy.

For core patterns (file structure, skeleton, naming, tagging), see bicep-patterns.md. For data module templates (PostgreSQL, Redis), see subagent-iac-gen.md Step 6.

Key Vault Deployer RBAC

The deploying user/principal needs RBAC to write secrets (scaffold seeds initial values) and read them (verify wiring):

  • Key Vault Secrets Officer (b86a8fe4-44ce-4948-aee5-eccb2c155cd7) โ€” write secrets
  • Key Vault Secrets User (4633458b-17de-408a-b874-0445c86b69e6) โ€” read secrets (also needed by app MI)

If the app seeds data using a generated secret (admin password, API key), either display it to the user at deploy time OR ensure the deployer has read RBAC on the Key Vault.

โ›” Include a role assignment for the deploying user (context.json.azure.userObjectId) with Key Vault Secrets Officer scoped to the Key Vault resource. Without this, az keyvault secret set fails with 403 during deploy secret seeding.

Security Defaults

Source: Adapted from Azure security best practices. See Azure security baseline for updates.

Identity โ€” Managed Identity Everywhere

โ›” Managed identity decision โ€” evaluate top to bottom, first match wins.

Condition Include MI?
F1 or D1 SKU on Linux NO (MI sidecar causes OOM โ€” use @secure() param + KV deployer RBAC instead)
Any Key Vault, database, storage, queue, or ACR access YES
None of the above YES (default secure)
  • System-assigned managed identity for all services (default). User-assigned only when shared identity is explicitly needed.
  • โ›” Never generate administratorLogin or administratorLoginPassword for SQL โ€” including inside conditional branches. Use Entra-only auth (see SQL Server pattern below).
  • App-to-service auth: managed identity + RBAC role assignments. Zero secrets in code or config.
identity: {
  type: 'SystemAssigned'
}

SQL Server โ€” Entra-Only Authentication

For full SQL auth reference (connection strings, managed identity SQL grants, CI/CD principal types), see azure-prepare/references/services/sql-database/auth.md.

param principalId string
param principalName string
@allowed(['User', 'Group', 'Application'])
param principalType string = 'User'

// Preview API required โ€” azureADOnlyAuthentication via administrators block
// is not available in GA API versions (GA path uses a separate child resource).
resource sqlServer 'Microsoft.Sql/servers@2024-05-01-preview' = {
  name: '${resourcePrefix}-sql-${uniqueHash}'
  location: location
  properties: {
    administrators: {
      administratorType: 'ActiveDirectory'
      principalType: principalType
      login: principalName
      sid: principalId
      tenantId: subscription().tenantId
      azureADOnlyAuthentication: true
    }
    minimalTlsVersion: '1.2'
  }
}

โš ๏ธ If deploying from CI/CD with a service principal, set principalType to 'Application'. The default 'User' only works for interactive deployments.

Secrets โ€” Key Vault References

Store secrets in Key Vault. Reference via app settings โ€” never inline.

โ›” No plaintext secrets in Bicep appSettings. Values like SECRET_KEY, JWT_SECRET, API_KEY, session secrets, and database passwords MUST NOT be hardcoded โ€” not even as placeholders. Never use uniqueString() for secrets (deterministic/predictable). These appear in ARM deployment history and persist in source control.

Container Apps exception: Phase 1 of two-phase deployment uses secrets: [] โ€” NO secrets at all (not plaintext, not KV). KV secretRef entries are activated in Phase 2 after RBAC propagates. See bicep-container-apps.md ยง Two-Phase Wiring.

โ›” Container Apps KV URL โ€” do NOT use environment().suffixes.keyvaultDns. That function returns .vault.azure.net (WITH leading dot) โ†’ double-dot URL โ†’ ContainerAppSecretKeyVaultUrlInvalid. Use 'https://${kvName}.vault.azure.net/secrets/...' with #disable-next-line no-hardcoded-env-urls to suppress the linter.

Correct patterns:

  1. Key Vault reference (preferred): '@Microsoft.KeyVault(VaultName=${kvName};SecretName=secret-key)'
  2. Deploy-time seeding (free-tier): Omit from Bicep; run az webapp config appsettings set --settings SECRET_KEY=$(openssl rand -base64 32) post-deploy
  3. Bicep @secure() parameter: Pass via CLI --parameters secretKey=$(openssl rand -base64 32) โ€” never committed to parameters.json

โŒ NEVER: { name: 'SECRET_KEY', value: 'hard-to-guess-string' } or value: 'change-me' in Bicep

// App Service / Functions โ€” Key Vault reference pattern
appSettings: [
  {
    name: 'DB_CONNECTION_STRING'
    value: '@Microsoft.KeyVault(VaultName=${kvName};SecretName=db-connection-string)'
  }
]

Key Vault module โ€” emit this resource EXACTLY; add no other properties. enablePurgeProtection is deliberately absent (ARM rejects false; true blocks cleanup).

resource kv 'Microsoft.KeyVault/vaults@{apiVersion}' = {
  name: kvName
  location: location
  tags: tags
  properties: {
    sku: { family: 'A', name: 'standard' }
    tenantId: subscription().tenantId
    enableRbacAuthorization: true          // RBAC, not access policies
    enableSoftDelete: true
    softDeleteRetentionInDays: 7
    networkAcls: { defaultAction: 'Allow', bypass: 'AzureServices' }
  }
}

Transport โ€” HTTPS Only

All web-facing resources:

// App Service
httpsOnly: true
siteConfig: {
  minTlsVersion: '1.2'
}

// Storage
supportsHttpsTrafficOnly: true
allowBlobPublicAccess: false
minimumTlsVersion: 'TLS1_2'

App Service / Functions โ€” Publishing Credential Lockdown

โ›” Every App Service and Functions app MUST include both basicPublishingCredentialsPolicies child resources. Missing these means deploy cannot toggle SCM auth post-deployment โ€” the REST API call targets a resource that doesn't exist in ARM.

// SCM โ€” allow: true for deploy phase (deploy re-disables via REST API after code upload)
resource scmAuth 'Microsoft.Web/sites/basicPublishingCredentialsPolicies@2023-12-01' = {
  parent: appService
  name: 'scm'
  properties: {
    allow: true
  }
}

// FTP โ€” always disabled
resource ftpAuth 'Microsoft.Web/sites/basicPublishingCredentialsPolicies@2023-12-01' = {
  parent: appService
  name: 'ftp'
  properties: {
    allow: false
  }
}

Deploy lifecycle: Scaffold sets scm.allow: true so az webapp deploy works. After code upload + health check, deploy phase runs az rest --method put .../basicPublishingCredentialsPolicies/scm with allow: false to re-harden. If scaffold omits these resources, deploy's Step 7 SCM re-disable REST API call fails silently.

Cosmos DB โ€” Data Plane RBAC

โ›” Cosmos DB uses its own role system โ€” see rbac-roles.md ยง Cosmos DB for role IDs and behavioral rules. Do NOT use Microsoft.Authorization/roleAssignments for Cosmos data access.

RBAC โ€” Deterministic Role Assignments

For the common roles GUID table, see rbac-roles.md.

resource roleAssignment 'Microsoft.Authorization/roleAssignments@2022-04-01' = {
  name: guid(scopeResourceId, principalId, roleDefinitionId)
  scope: targetResource
  properties: {
    roleDefinitionId: subscriptionResourceId('Microsoft.Authorization/roleDefinitions', roleDefinitionId)
    principalId: managedIdentity.properties.principalId
    principalType: 'ServicePrincipal'  // REQUIRED โ€” prevents AAD graph lookup delays
  }
}

Source: SKILL.md on GitHub

No third-party reports yet.

Signed by skilld at 617f8b5. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 20 hours ago.

Activeupdated 2 months ago

README badge

README badge for microsoft/skills/scaffold