Azure validate skill

Pre-deployment validation for Azure readiness.

by microsoft·MIT license·★ 3,077 Stars on the repo·GitHub ↗

Use now

Files of Azure validate

microsoft/main1 file shown
SKILL.md
Show the full text68 lines
azure-validate/SKILL.md68 lines · 3.5 KB

Azure Validate

AUTHORITATIVE GUIDANCE — Follow these instructions exactly unless they contradict security policies given to you.

⛔ STOP — PREREQUISITE CHECK REQUIRED

Before proceeding, verify this prerequisite is met:

azure-prepare was invoked and completed → .azure/deployment-plan.md exists with status Approved or later

If the plan is missing, STOP IMMEDIATELY and invoke azure-prepare first.

The complete workflow ensures success:

azure-prepare → azure-validate → azure-deploy

Triggers

  • Check if app is ready to deploy
  • Validate azure.yaml or Bicep
  • Run preflight checks
  • Troubleshoot deployment errors

Rules

  1. Run after azure-prepare, before azure-deploy
  2. All checks must pass—do not deploy with failures
  3. ⛔ Destructive actions require ask_user — global-rules

Steps

Run the workflow script and follow its instructions. It walks you through each validation step one at a time, recording progress in .azure/validate-status.json. Use references/scripts/workflow.ps1 on Windows or references/scripts/workflow.sh on macOS/Linux.

Start by calling the script without the completed-step argument:

pwsh references/scripts/workflow.ps1 -WorkspacePath <workspace-path>
# macOS/Linux: bash references/scripts/workflow.sh --workspace-path <workspace-path>

Each run prints the next action and the value to pass next. Perform the action, then re-run with that value (-CompletedStep <value> for pwsh, --completed-step <value> for bash). Repeat until it reports the azure-validate workflow is complete.

The steps reference recipe details in references/recipes/README.md and role checks in references/role-verification.md.

⛔ VALIDATION AUTHORITY

This skill is the officially verified way to set plan status to Validated. You MUST follow the script's instructions to completion before setting status to Validated. Do NOT set status to Validated without doing so.


⚠️ NEXT STEP — DEPENDS ON USER INTENT

After ALL validations pass, check whether the user asked to deploy:

  • If the user explicitly requested deployment, you MUST invoke azure-deploy to execute it. Do NOT run azd up, azd deploy, or any deployment commands directly — let azure-deploy handle execution.
  • If the user only asked to validate or prepare (not deploy), STOP after recording proof and setting status to Validated. Report the validation results and do NOT invoke azure-deploy.

If any validation failed, fix the issues and re-run azure-validate before proceeding.

1---
2name: azure-validate
3description: "Pre-deployment validation for Azure readiness. Run deep checks on configuration, infrastructure (Bicep or Terraform), RBAC role assignments, managed identity permissions, and prerequisites before deploying. WHEN: validate my app, check deployment readiness, run preflight checks, verify configuration, check if ready to deploy, validate azure.yaml, validate Bicep, test before deploying, troubleshoot deployment errors, validate Azure Functions, validate function app, validate serverless deployment, verify RBAC roles, check role assignments, review managed identity permissions, what-if analysis, validate Container Apps deployment."
4license: MIT
5metadata:
6 author: Microsoft
7 version: "1.2.3"
8---
9 
10# Azure Validate
11 
12> **AUTHORITATIVE GUIDANCE** — Follow these instructions exactly unless they contradict security policies given to you.
13 
14> **⛔ STOP — PREREQUISITE CHECK REQUIRED**
15>
16> Before proceeding, verify this prerequisite is met:
17>
18> **azure-prepare** was invoked and completed → `.azure/deployment-plan.md` exists with status `Approved` or later
19>
20> If the plan is missing, **STOP IMMEDIATELY** and invoke **azure-prepare** first.
21>
22> The complete workflow ensures success:
23>
24> `azure-prepare` → `azure-validate` → `azure-deploy`
25 
26## Triggers
27 
28- Check if app is ready to deploy
29- Validate azure.yaml or Bicep
30- Run preflight checks
31- Troubleshoot deployment errors
32 
33## Rules
34 
351. Run after azure-prepare, before azure-deploy
362. All checks must pass—do not deploy with failures
373. ⛔ **Destructive actions require `ask_user`** — [global-rules](references/global-rules.md)
38 
39## Steps
40 
41Run the workflow script and follow its instructions. It walks you through each validation step one at a time, recording progress in `.azure/validate-status.json`. Use [references/scripts/workflow.ps1](references/scripts/workflow.ps1) on Windows or [references/scripts/workflow.sh](references/scripts/workflow.sh) on macOS/Linux.
42 
43Start by calling the script **without** the completed-step argument:
44 
45```bash
46pwsh references/scripts/workflow.ps1 -WorkspacePath <workspace-path>
47# macOS/Linux: bash references/scripts/workflow.sh --workspace-path <workspace-path>
48```
49 
50Each run prints the next action and the value to pass next. Perform the action, then re-run with that value (`-CompletedStep <value>` for pwsh, `--completed-step <value>` for bash). Repeat until it reports the azure-validate workflow is complete.
51 
52The steps reference recipe details in [references/recipes/README.md](references/recipes/README.md) and role checks in [references/role-verification.md](references/role-verification.md).
53 
54> **⛔ VALIDATION AUTHORITY**
55>
56> This skill is the officially verified way to set plan status to `Validated`. You MUST follow the script's instructions to completion before setting status to `Validated`.
57> Do NOT set status to `Validated` without doing so.
58 
59---
60 
61> **⚠️ NEXT STEP — DEPENDS ON USER INTENT**
62>
63> After ALL validations pass, check whether the user asked to deploy:
64> - **If the user explicitly requested deployment**, you **MUST** invoke **azure-deploy** to execute it. Do NOT run `azd up`, `azd deploy`, or any deployment commands directly — let azure-deploy handle execution.
65> - **If the user only asked to validate or prepare** (not deploy), STOP after recording proof and setting status to `Validated`. Report the validation results and do NOT invoke azure-deploy.
66>
67> If any validation failed, fix the issues and re-run azure-validate before proceeding.
68 

Discussion

Alternatives

Azure app onboardEnd-to-end orchestrator: from a business idea, app idea, or existing app to running Azure deployment with cost estimates and pre-deploy approval. Analyzes your app, auto-detects the right Azure services, scaffolds infrastructure code, and deploys — tailored to your app, not a template. Handles moving existing apps to Azure without rewriting or with minimal changes. WHEN: bring your app to Azure, plan my app, cost to run, is my code ready to deploy, deploy my app to the cloud, deploy all my services, what Azure services do I need, plan my Azure deployment, deploy my new app to Azure, one-click deploy, I have an app and want it on Azure, migrate my app to Azure, help me get started, build an app, no code yet, starter project. DO NOT USE FOR: use azd for deployment(use azure-deploy), optimizing existing costs (use cost-optimization), code readiness checks only (use azure-app-onboard-prereq).Infrastructure & ops · MITAzure App Onboard Prereq — Repository EvaluationAssess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work. Evaluates build health, app completeness, dependencies and local services, stack compatibility, and deployment feasibility. Answers questions about what your app needs before it can be deployed — frameworks, dependencies, and configuration. Checks whether dependencies are compatible and identifies deployment blockers and unsupported frameworks. WHEN: "evaluate my repo", "is my app ready to deploy", "what does my app need to deploy", "what do I need before deploying", "does my app need", "can I ship this to Azure", "scan my repo for issues", "is this app deployable", "check if my app is ready for Azure", "do I need a Dockerfile", "what's blocking my deployment", "are there any blockers", "are my dependencies compatible", "does Azure support my framework", "what needs to change before deploying", "check my app configuration".Infrastructure & ops · MITDocker MCP gatewayDocker's own CLI plugin: run any server from the Docker MCP Catalog in its own container, behind one connection, with secrets kept out of env vars.Coding · MITAzure cloud migrateAssess and migrate cross-cloud workloads to Azure with reports and code conversion. Supports Lambda→Functions, Beanstalk/Heroku/App Engine→App Service, Fargate/Kubernetes/Cloud Run/Spring Boot→Container Apps. WHEN: migrate Lambda to Functions, AWS to Azure, migrate Beanstalk, migrate Heroku, migrate App Engine, Cloud Run migration, Fargate to ACA, ECS/Kubernetes/GKE/EKS to Container Apps, Spring Boot to Container Apps, cross-cloud migration.Infrastructure & ops · MIT