mcpbeat

Azure Validate

microsoft/azure-validate

Pre-deployment validation for Azure readiness. Run deep checks on configuration, infrastructure (Bicep or Terraform), RBAC role assignments, managed identity permissions, and prerequisites before deploying. WHEN: validate my app, check deployment readiness, run preflight checks, verify configuration, check if ready to deploy, validate azure.yaml, validate Bicep, test before deploying, troubleshoot deployment errors, validate Azure Functions, validate function app, validate serverless deployment, verify RBAC roles, check role assignments, review managed identity permissions, what-if analysis, validate Container Apps deployment.

21k tokens
context cost
the whole folder, loaded on every use
25
files
ships runnable scripts
1
copies elsewhere
how many repositories repackaged it
6 d ago
last touched
this folder, not the whole repository

Install

one command, takes just this skill from the repository
npx skills add https://github.com/microsoft/skills --skill azure-validate

What comes with it

78 308 bytes besides the instruction
references/aspire-functions-secrets.md
references/global-rules.md
references/policy-validation.md
references/recipes/README.md
references/recipes/azcli/README.md
references/recipes/azcli/errors.md
references/recipes/azd/README.md
references/recipes/azd/aspire.md
references/recipes/azd/environment.md
references/recipes/azd/errors.md
references/recipes/azd/scripts/set-aspire-aca-env.ps1
references/recipes/azd/scripts/set-aspire-aca-env.sh
references/recipes/bicep/README.md
references/recipes/bicep/errors.md
references/recipes/scripts/validate-deployment.ps1
references/recipes/scripts/validate-deployment.sh
references/recipes/terraform/README.md
references/recipes/terraform/errors.md
references/recipes/terraform/scripts/validate-terraform.ps1
references/recipes/terraform/scripts/validate-terraform.sh
references/region-availability.md
references/role-verification.md
references/scripts/scan-aspire-functions-secrets.ps1
references/scripts/scan-aspire-functions-secrets.sh

The instruction itself

4 sections, as written by the author

Azure Validate

> AUTHORITATIVE GUIDANCE — Follow these instructions exactly unless they contradict security policies given to you.

> ⛔ STOP — PREREQUISITE CHECK REQUIRED

>

> Before proceeding, verify this prerequisite is met:

>

> azure-prepare was invoked and completed → .azure/deployment-plan.md exists with status Approved or later

>

> If the plan is missing, STOP IMMEDIATELY and invoke azure-prepare first.

>

> The complete workflow ensures success:

>

> azure-prepareazure-validateazure-deploy

Triggers

  • Check if app is ready to deploy
  • Validate azure.yaml or Bicep
  • Run preflight checks
  • Troubleshoot deployment errors

Rules

  • Run after azure-prepare, before azure-deploy
  • All checks must pass—do not deploy with failures
  • Destructive actions require ask_user — global-rules

Steps

| # | Action | Reference |

|---|--------|-----------|

| 1 | Load Plan — Read .azure/deployment-plan.md for recipe and configuration. If missing → run azure-prepare first | .azure/deployment-plan.md |

| 2 | Add Validation Steps — Copy recipe "Validation Steps" to .azure/deployment-plan.md as children of "All validation checks pass" | recipes/README.md, .azure/deployment-plan.md |

| 3 | Run Validation — Execute recipe-specific validation commands | recipes/README.md |

| 4 | Build Verification — Build the project and fix any errors before proceeding | See recipe |

| 5 | Static Role Verification — Review Bicep/Terraform for correct RBAC role assignments in code | role-verification.md |

| 6 | Record Proof — Populate Section 7: Validation Proof with commands run and results | .azure/deployment-plan.md |

| 7 | Resolve Errors — Fix failures before proceeding | See recipe's errors.md |

| 8 | Update Status — Only after ALL checks pass, set status to Validated | .azure/deployment-plan.md |

| 9 | Deploy (only if the user asked to deploy) — If the user explicitly requested deployment, invoke azure-deploy. Otherwise STOP and report validation results | — |

> ⛔ VALIDATION AUTHORITY

>

> This skill is the officially verified way to set plan status to Validated. You MUST follow these steps to make sure every prerequisite is fulfilled before setting status to Validated:

> 1. Run actual validation commands (azd provision --preview, bicep build, terraform validate, etc.)

> 2. Populate Section 7: Validation Proof with the commands you ran and their results

> 3. Only then set status to Validated

>

> Do NOT set status to Validated without running checks and recording proof.


> ⚠️ NEXT STEP — DEPENDS ON USER INTENT

>

> After ALL validations pass, check whether the user asked to deploy:

> - If the user explicitly requested deployment, you MUST invoke azure-deploy to execute it. Do NOT run azd up, azd deploy, or any deployment commands directly — let azure-deploy handle execution.

> - If the user only asked to validate or prepare (not deploy), STOP after recording proof and setting status to Validated. Report the validation results and do NOT invoke azure-deploy.

>

> If any validation failed, fix the issues and re-run azure-validate before proceeding.

Repackaged in 1 other repositories

same content, different owner
microsoft/azure-skills open on GitHub →

How to use it

Copy the folder

Take microsoft/azure-validate from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.