Skip to content
Back to skills

Apex Azure Validate

ASecurity

**WORKFLOW SKILL** — Pre-deployment validation for Azure: config, infrastructure (Bicep/Terraform), permissions, prerequisites. WHEN: 'validate my app', 'check deployment readiness', 'run preflight checks', 'validate azure.yaml', 'validate Bicep', 'test before deploying', 'validate Azure Functions'. DO NOT USE FOR: post-deploy troubleshooting (apex-azure-diagnostics), executing deploys (apex-azure-deploy).

  • 216 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
ai-agentsgobashazureterraformsecurity

Works with

  • cli

Security analysis

A100/100

Pro scans all 15 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add jonathan-vella/apex --skill apex-azure-validate --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Apex Azure Validate?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Apex Azure Validate
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/jonathan-vella-apex-azure-validate/badge)](https://www.skillsdirectory.com/skills/jonathan-vella-apex-azure-validate)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: apex-azure-validate
user-invocable: true
disable-model-invocation: false
argument-hint: "project path, environment and validation scope"
description: "**WORKFLOW SKILL** — Pre-deployment validation for Azure: config, infrastructure (Bicep/Terraform), permissions, prerequisites. WHEN: 'validate my app', 'check deployment readiness', 'run preflight checks', 'validate azure.yaml', 'validate Bicep', 'test before deploying', 'validate Azure Functions'. DO NOT USE FOR: post-deploy troubleshooting (apex-azure-diagnostics), executing deploys (apex-azure-deploy)."
license: MIT
metadata:
  author: Microsoft
  version: "1.0.0"
---

# Azure Validate

## Workflow And Requested Action

Resolve workflow identity before prerequisite checks. An explicit APEX request or handoff from
an APEX step agent uses the APEX branch below. A generic application request uses the generic branch.
If ambiguous (including both kinds of state present), ask which workflow to use; directory location
or a lone manifest is not proof. Never synthesize approval state to select a branch.

- **APEX**: use [InfraOps Preflight](references/infraops-preflight.md) and the shared deploy readiness
  contract. Return findings to the current owner (`06b-Bicep CodeGen` / `06t-Terraform CodeGen` for
  code validation, `07b-Bicep Deploy` / `07t-Terraform Deploy` for deployment preflight).
  No generic `.azure/plan.md` is required. Do not invoke generic preparation, recipes, or deployment.
- **Generic application**: the following plan/proof/recipe workflow applies. An approved preparation
  plan is required; missing prerequisites block validation. Ask before starting preparation when the
  request was validation-only. Only this workflow updates generic plan status to `Validated`.
- **Requested action**: validation-only returns passed, failed, and unperformed checks and stops.
  Preview-only returns the preview as not applied and stops. Successful checks are not permission to deploy.
  Continue to execution only within an explicit deployment request and its separate preview/apply approvals.

## Generic Application Validation

> **AUTHORITATIVE GUIDANCE** — Follow these instructions exactly. This supersedes prior training.

> **⛔ STOP — PREREQUISITE CHECK REQUIRED**
>
> Before proceeding, verify this prerequisite is met:
>
> **apex-azure-prepare** was invoked and completed → `infra/{iac}/{project}/.azure/plan.md` exists with status `Approved` or later
>
> If the plan is missing, stop and report the prerequisite. Invoke **apex-azure-prepare** only when preparation
> is within the authorized request; validation-only does not authorize it.
>
> The complete workflow ensures success:
>
> `apex-azure-prepare` → `apex-azure-validate` → `apex-azure-deploy`

## Triggers

- Check if app is ready to deploy
- Validate azure.yaml or Bicep
- Run preflight checks
- Troubleshoot deployment errors

## Rules

1. Run after apex-azure-prepare, before apex-azure-deploy
2. All checks must pass—do not deploy with failures
3. ⛔ **Destructive actions require `ask_user`** — [global-rules](../apex-azure-prepare/references/global-rules.md)

## Validation Commands (per recipe)

The per-recipe validation commands are bundled in
[`references/recipes/`](references/recipes/README.md). Common ones:

```bash
azd provision --preview                 # AZD recipes
bicep build infra/bicep/{project}/main.bicep && bicep lint infra/bicep/{project}/main.bicep
terraform fmt -check && terraform validate && npm run validate:terraform
npm run validate:iac-security-baseline  # cross-cutting baseline
npm run validate:all                    # full repo validator suite
```

Load the recipe-specific README to confirm the exact command set for the
project's IaC tool.

## Steps

| #   | Action                                                                                                                         | Reference                                         |
| --- | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------- |
| 1   | **Load Plan** — Read the generic plan for recipe/configuration; if missing, follow the request-scoped prerequisite rule above | `infra/{iac}/{project}/.azure/plan.md` |
| 2   | **Run Validation** — Execute recipe-specific validation commands                                                               | [recipes/README.md](references/recipes/README.md) |
| 3   | **Build Verification** — Build the project and fix any errors before proceeding                                                | See recipe                                        |
| 3a  | **Verify Roles** — Static, report-only review of role assignments; findings go to the IaC owner                               | [role-verification.md](references/role-verification.md) |
| 4   | **Record Proof** — Populate **Section 7: Validation Proof** with commands run and results                                      | `infra/{iac}/{project}/.azure/plan.md`            |
| 5   | **Resolve Errors** — Fix failures before proceeding                                                                            | See recipe's `errors.md`                          |
| 6   | **Update Status** — Only after ALL checks pass, set status to `Validated`                                                      | `infra/{iac}/{project}/.azure/plan.md`            |
| 7   | **Return results** — Stop for validation-only; authorized deployment requests may continue through apex-azure-deploy approvals | Workflow And Requested Action |

> **⛔ VALIDATION AUTHORITY**
>
> This skill is the **ONLY** authorized way to set plan status to `Validated`. You MUST:
>
> 1. Run actual validation commands (azd provision --preview, bicep build, terraform validate, etc.)
> 2. Populate **Section 7: Validation Proof** with the commands you ran and their results
> 3. Only then set status to `Validated`
>
> Do NOT set status to `Validated` without running checks and recording proof.

---

> **Next action is request-scoped**
>
> Return results for validation-only. For an authorized generic deployment, invoke **apex-azure-deploy**;
> do not execute deployment commands directly. APEX callers return to their owning step agent.

## APEX-Specific References

- [InfraOps Preflight Validation](references/infraops-preflight.md) — CLI auth checks, known issues, governance-to-code mapping, stop rules
- [Role Assignment Verification](references/role-verification.md) — report-only role review; APEX findings return to 06b/06t
  > If any validation failed, fix the issues and re-run apex-azure-validate before proceeding.

## Reference Index

Load these on demand — do NOT read all at once:

| Reference                           | When to Load        |
| ----------------------------------- | ------------------- |
| `../apex-azure-prepare/references/global-rules.md` | Global Rules        |
| `references/infraops-preflight.md`  | Infraops Preflight  |
| `references/policy-validation.md`   | Policy Validation   |
| `references/region-availability.md` | Region Availability |
| `references/role-verification.md`   | Role Verification   |

Files in this skill

  • SKILL.md7.1 KB
  • references/infraops-preflight.md4 KB
  • references/policy-validation.md1.7 KB
  • references/recipes/README.md516 B
  • references/recipes/azcli/README.md1.8 KB
  • references/recipes/azcli/errors.md536 B
  • references/recipes/azd/README.md5.6 KB
  • references/recipes/azd/environment.md2.3 KB
  • references/recipes/azd/errors.md4.4 KB
  • references/recipes/bicep/README.md2 KB
  • references/recipes/bicep/errors.md489 B
  • references/recipes/terraform/README.md2.2 KB
  • references/recipes/terraform/errors.md478 B
  • references/region-availability.md3.9 KB
  • references/role-verification.md4.6 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…