Validation, Manifest & Approval โ Steps 10โ12.5
Step 10 โ CI/CD
Do NOT auto-generate workflow files or create branches/PRs. Scaffold only writes IaC files. This step activates only when context.json.repo.remote is non-null AND user explicitly requests branch/PR creation. When repo.remote is absent or user declines, write IaC directly to working tree. If the user asks for CI/CD, or after deploy completes, suggest it as a follow-up: call mcp_azure_mcp_deploy โ deploy_pipeline_guidance_get with is-azd-project: false, pipeline-platform: "github-actions", deploy-option: "provision-and-deploy" and present the guidance for the user to apply.
Step 11 โ Validate Generated IaC
โ Validation MUST happen BEFORE the manifest is written. The manifest requires
validationResultโ you cannot write it without completing validation first. Do NOT writescaffold-manifest.jsonuntil validation has run.
โ Do NOT call other skills during scaffold/deploy โ see pipeline-rules.md.
Run these checks directly. All must pass.
11a. Bicep compilation:
az bicep build --file infra/main.bicep --stdout > $null(Bash: redirect to /dev/null instead of $null.) Pass: exit 0. Fail: fix errors and retry.
11b. Static RBAC review โ review generated Bicep for correct role assignments per rbac-roles.md. Every managed identity โ resource pair must have a Microsoft.Authorization/roleAssignments resource with the correct role GUID.
11c. Write validationResult โ after all checks pass, write:
{
"validationResult": {
"status": "Validated",
"checks": [
{ "name": "bicep build", "result": "PASS" },
{ "name": "RBAC review", "result": "PASS" }
]
}
}Terraform path: Replace 11a with terraform init -backend=false && terraform validate.
- If validation finds FIXABLE errors: edit IaC โ re-run self-review (L1โL4) โ re-validate (max 3 attempts). โ You MUST read scaffold-healing-rules.md before entering the healing loop โ it defines error classification (FIXABLE vs BLOCKING) and auto-fix strategies.
- If BLOCKING errors remain after 3 attempts: surface to user and halt.
Step 12 โ Write scaffold-manifest.json
โ You MUST read scaffold-schemas.ts to get the exact ScaffoldManifest interface. Write to the session folder with ALL fields populated: files[], selfReview.findings[], AND validationResult (from Step 11). This is a single write โ validation is already complete.
โ Phase exit gate:
scaffold-manifest.json.validationResultMUST NOT be null. If validation ran:{ status: 'Validated'/'Partial'/'Failed', details }(perValidationResultinscaffold-schemas.ts). Null = incomplete scaffold.
You MUST also update context.json per AppOnboardContext in session-schemas.ts: append "scaffold" to completedPhases, set currentPhase to "deploy", update lastModifiedUtc.
Step 12.5 โ Deploy Approval Gate
Present the user with: files generated, selfReview findings, validation results (pass/fail per check from Step 11), services + SKUs, secure-defaults applied. End with: "Ready to deploy? (Yes / Run manually / Edit plan / Cancel)" โ do not continue until the user approves.
โ Self-check before presenting the deploy gate. Does
scaffold-manifest.jsoncontain avalidationResultfield withstatusset? If NO โ you skipped Step 11. Go back and run validation. Do NOT present the deploy gate withvalidationResult: null.
โ Quota gate โ MANDATORY. Read
prepare-plan.json.quotaValidation. Ifverified == false,method == "unverifiable", ormethodis not"cli"for quota-constrained services: readsku-quota-validation.mdยง Deploy Gate Re-Validation and follow the procedure. โ Do NOT useaz vm list-usage,az appservice list-locations, ormcp_azure_mcp_quotafor quota checks โ see Anti-Patterns insku-quota-validation.md.
โ Azure service compatibility warnings. Read
prereq-output.json.warnings[]for any warnings withfixPhase: "deploy-gate". Surface EACH at the deploy gate: "โ ๏ธ Azure compatibility: {warning.summary}. Fix: {warning.fix}. Approve? (Yes / Skip / Cancel)". If the user skips, add topostDeployRecommendations[].
โ Phase exit โ NOT complete until ALL done:
scaffold-manifest.jsonwritten withfiles[],selfReview.findings[], ANDvalidationResultcontext.json:"scaffold"appended tocompletedPhases,currentPhaseโ"deploy",lastModifiedUtcupdateddeploy-checklist.mdexists in session folder โ written by the parallel checklist subagent at scaffold Step 5b (before IaC gen completes). Verify it exists. If missing (subagent failed), write it now fromdeploy-checklist-template.mdโ fill in real values fromprepare-plan.json, delete unrelated compute sections.