Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 1b96b38c792fbedc… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Azure App Onboard Scaffold — IaC Generation + Self-Review
Generate deployment-ready infrastructure code from an architecture plan, verify it with adversarial self-review, and bridge to validation — all without deploying.
Quick Reference
| Property | Value |
|---|---|
| Parent | azure-app-onboard |
| Best for | Turning prepare-plan.json service list into Bicep templates with secure-by-default patterns |
| Inputs | prepare-plan.json (services, naming, quotas), context.json (overrides, components, repo info) |
| Outputs | scaffold-manifest.json, generated IaC files in infra/ |
| Pipeline position | Phase 3 of 4: prereq → prepare → scaffold → deploy |
| IaC format | Bicep (v1 default). Terraform when existing .tf detected or user override. |
When to Use This Skill
Invoked by the azure-app-onboard orchestrator at Phase 3 when prepare-plan.json exists with services[]. Not directly user-routable in v1.
Return to orchestrator: When complete, return control to
azure-app-onboard. Do NOT directly invoke deploy — the orchestrator manages phase transitions.
When NOT to Use
| Scenario | Use Instead |
|---|---|
User-triggered IaC (no prepare-plan.json) | azure-prepare |
| Subscription-scope landing zones | azure-enterprise-infra-planner |
Execute deployment (azd up) | azure-deploy (do NOT invoke from AppOnboard pipeline) |
MCP Tools
See shared tools for cross-phase tools and global parameters. See scaffold tools for full parameter tables.
| Tool | Sub-command | Purpose | Parameters |
|---|---|---|---|
mcp_azure_mcp_bicepschema | bicepschema_get | ARM resource type schemas | resource_type (Required), api_version (Optional) |
mcp_bicep_list_avm_metadata | (flat) | AVM module catalog | None |
mcp_bicep_get_bicep_best_practices | (flat) | Bicep best practices | None |
mcp_bicep_get_az_resource_type_schema | (flat) | ARM resource type JSON schema | azResourceType, apiVersion (Required) |
mcp_bicep_build_bicep | (flat) | Validate .bicep files (self-review L3) | filePath (Required) |
mcp_bicep_format_bicep_file | (flat) | Format .bicep files (LF enforcement) | filePath (Required) |
mcp_azure_mcp_deploy | deploy_iac_rules_get | IaC best practices and rules | deployment-tool, iac-type, resource-types |
mcp_azure_mcp_deploy | deploy_pipeline_guidance_get | CI/CD pipeline config | is-azd-project, pipeline-platform, deploy-option |
mcp_azure_mcp_get_azure_bestpractices | get_azure_bestpractices_get | SDK/Functions best practices | resource, action |
mcp_azure_mcp_azureterraformbestpractices | (flat) | Terraform patterns (TF path only) | resource_type (Required) |
Workflow
Session folder: .copilot-azure/sessions/{uuid}/ — reads prepare-plan.json + context.json, writes scaffold-manifest.json.
DETECT (Steps 1–4)
- Read
prepare-plan.json— verifyservices[]exists, readnamingconfig (especiallynaming.resourcePrefix,naming.suffix,naming.resources[]). Read resource group name fromcontext.json.azure.resourceGroup. ⛔ Use EXACTLY these names in generated IaC — do NOT invent names, derive them fromenvironmentName, or append your own suffixes. ⛔ Use EXACTLY the names fromprepare-plan.json.naming.resources[]as Bicep parameters. Do NOT derive names withtake(),substring(), or string manipulation. The plan is the source of truth. Missing → trigger prepare backfill viaazure-app-onboardorchestrator. - Read
context.json— checkoverrides[]foriacFormatpreference,detectedInfra[]for existing.tf,detectedInfraProviderfor cloud provider classification. - Check workspace for existing IaC — ⛔ Skip if
context.json.overrides[]containsignoreExistingInfra: true. Otherwise:- Azure IaC (
.bicep,azure.yaml,.tfwithazurerm):ask_user→ "Start fresh" (renameinfra/toinfra.bak/) or "Use existing" (route toazure-prepare, stop pipeline). - Non-Azure IaC (
.tfwith GCP/AWS): respectcontext.json.overrides[].iacFormatfrom prepare. Default: Bicep alongside existing TF. - Unknown TF (
detectedInfraProvider.terraform=="unknown"): ask user which provider before routing. - No IaC: continue.
- Azure IaC (
- Determine compute targets — Check which compute targets are in the plan (App Service/Functions, Container Apps, or both) and whether PostgreSQL/Redis is present. Do NOT read any reference files — pass this info to the sub-agent at Step 5.
4b. Pre-check API versions (main thread) — MCP tool access is unreliable in
taskagents — call these in the main thread before dispatching. Callmcp_bicep_list_az_resource_types_for_provider(orbicep-list_az_resource_types_for_provider) once per provider namespace inprepare-plan.json.services[](e.g.,Microsoft.Web,Microsoft.App,Microsoft.DBforPostgreSQL,Microsoft.Cache,Microsoft.KeyVault,Microsoft.ContainerRegistry). Extract the latest GA API version (no-preview) for each resource type. Build anapiVersionsmap and pass it to the IaC gen sub-agent at Step 5. Fallback: if MCP unavailable, runaz provider show --namespace {ns} --query "resourceTypes[?resourceType=='{type}'].apiVersions[?!contains(@, 'preview')] | [0][0]" -o tsvper resource type — this filters to GA-only and picks the latest. Pass"MCP unavailable"only if both MCP AND CLI fail. Sub-agent still validates generated Bicep viaaz bicep build.
ACTION (Steps 5–12)
⛔ File boundary: NEVER modify files outside
infra/,.copilot-azure/. Scaffold only writes files — no install/build commands.
⛔ Sub-agent delegation is MANDATORY for Steps 5, 6–9, and 10–12. Each step reads its
subagent-*.mdtemplate, then dispatches ataskcall. Do NOT read any reference file not explicitly named in these steps.⛔ Dispatch type:
taskONLY — NEVERgeneral-purpose.general-purposeleaks sub-agent context into the main thread, accelerating compaction and evicting the orchestrator workflow.taskisolates sub-agent context.⛔ How to dispatch — VERBATIM COPY required:
viewthesubagent-*.mdtemplate file- Your NEXT action MUST be a
tasktool call — notview,powershell,create, or ANY other tool- The task prompt MUST contain the COMPLETE and UNMODIFIED template text. Copy the template between
<<<TEMPLATE_START>>>/<<<TEMPLATE_END>>>delimiters exactly as shown below. Do NOT summarize, paraphrase, reword, or omit ANY part of it — the sub-agent needs every "Read [file]" and "Do:" instruction to produce correct output- AFTER the template block, append the data sections (plan JSON, overrides, etc.)
Anti-pattern (causes regressions): Writing your OWN prompt that lists workflow steps or describes what to generate. The template already contains the complete workflow — your job is to COPY it, not rewrite it.
- IaC generation — ⛔ You MUST dispatch
subagent-iac-gen.mdas atask. ⛔ agent_type:"task"— NEVER"general-purpose".<<<TEMPLATE_START>>> {paste the ENTIRE content of subagent-iac-gen.md here — unmodified} <<<TEMPLATE_END>>> ## Data (appended by orchestrator) ### prepare-plan.json {full JSON} ### context.json.overrides {overrides array} ### prereq-output.json.buildRequirements {buildRequirements object} ### prereq-output.json.warnings[] {warnings array} ### Compute targets {App Service/Functions, Container Apps, or both + whether PostgreSQL/Redis present} ### apiVersions {map from Step 4b, e.g. {"Microsoft.KeyVault/vaults": "2023-07-01", ...} — or "MCP unavailable" if skipped} ### Working directory {absolute path}- Expect: IaC files written to
infra/, file list returned forscaffold-manifest.json.files[] - The tag
app-onboard-skill: 'true'MUST appear verbatim in generated Bicep.
- Expect: IaC files written to
5b. Deploy checklist (parallel with Step 5) — Dispatch as a task in parallel with the IaC gen subagent above. ⛔ agent_type: "task" — NEVER "general-purpose".
<<<TEMPLATE_START>>>
You are a deploy-checklist generator. Do NOT invoke any skills.
1. Read the deploy-checklist-template at: plugin/skills/azure-app-onboard/deploy/references/deploy-checklist-template.md
2. Fill in {placeholders} with real values from prepare-plan.json (appName, rgName, subscriptionId, sessionId).
3. Delete sections that don't apply to this deployment's compute target (e.g., remove App Service section for Container Apps deploys). The template section headers indicate which to delete.
4. Write the result to the session folder using the `create` tool. This file survives conversation compaction — deploy re-reads it after every long-running command.
<<<TEMPLATE_END>>>
## Data (appended by orchestrator)
### prepare-plan.json
{full JSON}
### Session path
{.copilot-azure/sessions/{uuid}/}
### Compute targets
{App Service, Container Apps, Static Web Apps, or combination}
- Expect:
deploy-checklist.mdwritten to session folder. If this subagent fails, the validate subagent (Steps 10b–12.5) will catch the missing file.
6–9. Self-review — ⛔ You MUST dispatch subagent-review.md as a task. ⛔ agent_type: "task" — NEVER "general-purpose".
<<<TEMPLATE_START>>>
{paste the ENTIRE content of subagent-review.md here — unmodified}
<<<TEMPLATE_END>>>
## Data (appended by orchestrator)
### Generated IaC files
{full content of every .bicep/.tf file}
### prepare-plan.json (services, naming, deploymentVariables)
{relevant sections}
### prereq-output.json.warnings[]
{warnings array}
- Expect: findings JSON → write to
scaffold-manifest.json.selfReview - FLAGGED at L1/L3 → fix IaC before proceeding
VALIDATE → MANIFEST → APPROVE (Steps 10–12.5)
10a. Format IaC (main thread) — For each .bicep file in infra/ (including modules/): call mcp_bicep_format_bicep_file (or bicep-format_bicep_file) with { filePath: "<absolute path>" }.This enforces LF line endings via the bicepconfig.json written during IaC generation. Fallback: skip if unavailable.
10a-conf. Conformance gate (main thread — MANDATORY for Bicep) — ⛔ Skip this entire step when the scaffold emitted Terraform (infra/main.bicep absent) — these checks are Bicep-only (Terraform is syntax-validated via terraform validate in the validate subagent). Otherwise run the conformance script from this skill's scripts/ dir; it deterministically catches ARM-rejected values az bicep build can't (invalid Bicep values, wrong DB version, reserved DB login, enablePurgeProtection):
{scaffoldDir}/scripts/scaffold-conformance.ps1 -SessionPath ".copilot-azure/sessions/{uuid}" -InfraPath infra # pwsh (preferred)
bash {scaffoldDir}/scripts/scaffold-conformance.sh ".copilot-azure/sessions/{uuid}" infra # bash (only if pwsh unavailable; needs jq for the plan-dependent checks)
⛔ Prefer the .ps1 when pwsh is available — it runs every check unconditionally. The .sh twin skips the plan-dependent checks (DB-VERSION-MATCH, SERVICES-COMPLETE, DB-NAME-PRESENT, WARN-FIXED) when jq is absent.
⛔ Any BLOCK failure → fix the IaC, re-run (max 3); never present the deploy gate with an open BLOCK. Run it here in the main thread — do NOT delegate to the validate subagent or hand-judge the result when a shell exists. Pass the JSON to the validate subagent for scaffold-manifest.json.conformance.
10b–12.5. Validation + manifest — ⛔ You MUST dispatch subagent-validate.md as a task. ⛔ agent_type: "task" — NEVER "general-purpose".
<<<TEMPLATE_START>>>
{paste the ENTIRE content of subagent-validate.md here — unmodified}
<<<TEMPLATE_END>>>
## Data (appended by orchestrator)
### IaC file paths
{list of generated files}
### Self-review findings (from Steps 6–9)
{findings JSON}
### prepare-plan.json
{full JSON}
### prereq-output.json.warnings[]
{warnings array}
### prereq-output.json.healthEndpoint
{detected health path string or null}
### Conformance result
{JSON from Step 10a-conf}
### Session path
{.copilot-azure/sessions/{uuid}/}
- Expect:
scaffold-manifest.jsonwithvalidationResult, deploy checklist generated - Verify
deploy-checklist.mdexists (written at Step 5b) — if missing, create NOW fromdeploy-checklist-template.md. Verifydeploy-result.jsonexists — if missing, create fromdeploy-schemas.ts. - ⛔ Verify
context.jsonupdate (main-thread — do NOT delegate). Read.copilot-azure/sessions/{uuid}/context.json. IfcompletedPhasesdoes not include"scaffold"ORcurrentPhaseis not"deploy", write it yourself viaedit/create: append"scaffold"tocompletedPhases, setcurrentPhaseto"deploy", updatelastModifiedUtcto current UTC ISO 8601. This is a phase-boundary write required by pipeline-rules.md — do not skip it. - ⛔ Return to orchestrator for Step 8 (Deploy Approval Gate). YOUR NEXT ACTION MUST BE presenting the Deploy Gate per orchestrator SKILL.md — do NOT write a "summary of generated files" message, do NOT emit a completion report. The Deploy Gate prompt (
🚀 Ready to deploy? ...) is the ONLY correct next output.
Self-Healing Loop
On validation failure → read scaffold-healing-rules.md (healing cadence, PLAN_LEVEL_CHANGE, artifact consistency). Do NOT pre-read.
Error Handling
- Missing
prepare-plan.json: trigger backfill via orchestrator. - Existing IaC: handled in DETECT Step 3.
- MCP unavailable: fall back to reference patterns, flag as "unverified."
- FLAGGED findings and healing exhaustion: see scaffold-healing-rules.md.
Files
27- SKILL.md
06ea2eedf414.2 KB - references/bicep-app-service.md
955fc94e305.2 KB - references/bicep-container-apps.md
490c716d5f9.3 KB - references/bicep-patterns-data.md
ad66fbe6504.0 KB - references/bicep-patterns-security.md
28a9a99ed97.8 KB - references/bicep-patterns.md
55b4b915646.8 KB - references/bicep-swa.md
31c03f2379757 B - references/cicd-pipelines.md
89a3efa48c325 B - references/dockerfile-generation.md
e4830c9fc23.8 KB - references/env-var-secrets.md
fa3b7933494.1 KB - references/error-handling.md
02f0c51c471.5 KB - references/iac-generation-rules.md
7945b17a446.6 KB - references/mcp-tools.md
e7d02c54467.0 KB - references/rbac-roles.md
c2dd28651c3.8 KB - references/scaffold-healing-rules.md
f7668e47943.3 KB - references/scaffold-schemas.ts
6572f79eb13.5 KB - references/self-healing.md
98972ac08d2.3 KB - references/self-review-checklist.md
3b550118d99.0 KB - references/self-review-procedure.md
ee4c3307672.3 KB - references/subagent-iac-gen.md
8442932dd29.5 KB - references/subagent-review.md
fdd28230aa3.5 KB - references/subagent-validate.md
0919e9d82c7.2 KB - references/terraform-patterns.md
daa49423aa6.9 KB - references/validation-and-manifest.md
a2e969dcee5.1 KB - references/waf-checklist.md
3ad06a9ce52.3 KB - scripts/scaffold-conformance.ps1
82492a991712.8 KB - scripts/scaffold-conformance.sh
18b1ce6ba213.8 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from microsoft/skills8
Build Azure AI Foundry agents using the Microsoft Agent Framework Python SDK (agent-framework-azure-ai). Use when creating persistent agents with AzureAIAgentsProvider, using hosted tools (code interpreter, file search, web search), integrating MCP servers, managing conversation threads, or implemen
Set up AI Runway on AKS — from bare cluster to running model. Covers cluster verification, controller install, GPU assessment, provider setup, and first deployment. WHEN: \"setup AI Runway\", \"onboard AKS cluster\", \"install AI Runway\", \"airunway setup\", \"deploy model to AKS\", \"GPU inference
Diagnose Day-2 AKS GPU and KAITO incidents using profile-aware, read-only evidence. WHEN: 'Insufficient nvidia.com/gpu', GPU pod Pending, model-load OOM, DCGM/VRAM, KAITO Workspace not ready, or GPU autoscaling. DO NOT USE FOR: setup (airunway-aks-setup), non-GPU incidents (aks-troubleshooting), sta
Lookup documented AKS fixes only when the prompt includes an exact catalog signature and all of its qualifiers: VMCannotFitEphemeralOSDisk; NodePoolMcVersionIncompatible; 'NodeImageVersion is not accepted'; AKS SkuNotAvailable with size, location, and zone; ZonalAllocationFailed with insufficient zo
Collects bounded packet captures from AKS nodes and Azure network configuration for wire-level evidence. WHEN: \"capture packets on an AKS node\", \"take a pcap\", \"run tcpdump on AKS\", \"prove where packets drop\". Use for explicit packet-capture intent after read-only diagnostics, not general AK
Debug live Azure Kubernetes Service (AKS) incidents with a read-only, evidence-first investigation. WHEN: pod crashes or Pending, CrashLoopBackOff, OOMKilled, ImagePullBackOff, node NotReady, DNS or ingress failure, connectivity timeout, network policy, SNAT exhaustion, node-pool scaling blocked by
Guidance for instrumenting webapps with Azure Application Insights. Provides telemetry patterns, SDK setup, and configuration references. WHEN: how to instrument app, App Insights SDK, telemetry patterns, what is App Insights, Application Insights guidance, instrumentation examples, APM best practic
Instrument browser/web apps with the Application Insights JavaScript SDK (@microsoft/applicationinsights-web). Use for Real User Monitoring (RUM) — page views, clicks, AJAX/fetch dependencies, exceptions, custom events, and browser-side GenAI agent traces correlated to backend OpenTelemetry traces.
Related tooling skillsscan passed
Web performance regression detection. (gstack)
Lint ECC skills for Codex/Cursor-safe frontmatter and Claude-only substitutions before a skill PR.
Audit and improve CLAUDE.md files in repositories. Use when user asks to check, audit, update, improve, or fix CLAUDE.md files. Scans for all CLAUDE.md files, evaluates quality against templates, outputs quality report, then makes targeted updates. Also use when the user mentions "CLAUDE.md maintena
Helps you build and check a color system for your project. It generates palettes, names semantic tokens, converts between formats and measures contrast.
Creates a new Angular app using the Angular CLI. This skill should be used whenever a user wants to create a new Angular application and contains important guidelines for how to effectively create a modern Angular application.
Audit, diagnose, or optimize website loading and interaction performance, Core Web Vitals, and Lighthouse performance scores.