Provides deployment commands and troubleshooting for Azure Container Apps.

MITAuto-check: warningsDevOps & Cloud

Install Deploying To Azure

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add microsoft-foundry/foundry-agent-webapp --skill deploying-to-azure -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft-foundry/foundry-agent-webapp deploying-to-azure --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft-foundry/foundry-agent-webapp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/deploying-to-azure .claude/skills/deploying-to-azure && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deploying-to-azure
GitHub stars
127
Token cost
~2.2k tokens
SKILL.md length
650 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

Provides deployment commands and troubleshooting for Azure Container Apps.

  • Works in 4 steps: preprovision → AI Foundry auto-discovery… → provision → Deploy Azure resources via… → postprovision → Sets identifierUri on… → …
  • Running azd commands
  • SKILL.md covers Subagent Delegation for…, Quick Commands, Deployment Phases and Docker Multi-Stage Build, plus 10 more sections
  • Calls az

What it does

Deploying To Azure is an agent skill from microsoft-foundry/foundry-agent-webapp. Provides deployment commands and troubleshooting for Azure Container Apps. Use when running azd commands, deploying containers, debugging deployment failures, or updating infrastructure in this repository.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Containers, Deployment and Debugging. It works with Microsoft Azure, Docker and Bicep. The repository describes itself as: GitHub Copilot enabled repo for building and deploying a web application with Entra ID authentication and integrated with Azure AI Foundry Agents. The licence is MIT.

When your agent uses it

  • Running azd commands
  • Deploying containers
  • Debugging deployment failures
  • Updating infrastructure in this repository

Example prompts

  • “Use the deploying-to-azure skill to provide deployment commands and troubleshooting for Azure Container Apps”
  • “/deploying-to-azure”

Requirements

  • Docker

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. preprovision → AI Foundry auto-discovery + tenant detection. For CI: azd env set ENTRA_SERVICE_MANAGEMENT_REFERENCE ""
  2. provision → Deploy Azure resources via Bicep (infrastructure + Entra app via Microsoft Graph Bicep extension + placeholder container image)
  3. postprovision → Sets identifierUri on Entra app + updates redirect URIs + assigns RBAC to AI Foundry + generates local dev config
  4. predeploy → Builds container (local Docker or ACR cloud build)

What it can do on your machine

Read from SKILL.md and the folder at commit f6cb362. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • ai.azure.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deploying To Azure loads about 2.2k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 650 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:80
    - Custom npm registries: Add `.npmrc` to `frontend/` directory
  • NoteMentions a .env fileSKILL.md:102
    _ID not set` | Run `azd up` to generate `.env` files |
  • NoteMentions a .env fileSKILL.md:147
    4. Generates local dev config files (`.env.local` for frontend, `.env` for backend)
  • NoteMentions a .env fileSKILL.md:174
    # Remove local .env files to prevent localhost config
  • NoteMentions a .env fileSKILL.md:175
    RUN rm -f .env.local .env.development .env

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft-foundry/foundry-agent-webapp at commit f6cb362, republished under its MIT licence (© microsoft-foundry). 650 words, ~2,207 tokens.

Download SKILL.mdSave it as .claude/skills/deploying-to-azure/SKILL.md (or your agent's skills folder).
name
deploying-to-azure
description
Provides deployment commands and troubleshooting for Azure Container Apps. Use when running azd commands, deploying containers, debugging deployment failures, or updating infrastructure in this repository.

Deploying to Azure

Subagent Delegation for Deployment Analysis

Container logs and deployment output can be massive (1000+ lines). Delegate to subagent for:

  • Analyzing full deployment logs
  • Debugging container startup failures
  • RBAC permission troubleshooting
  • Multi-resource status checks
Delegation Pattern
text
runSubagent(
  prompt: "ANALYSIS task - analyze deployment issue.
    
    **Problem**: [describe the deployment failure]
    
    **Run these commands**:
    1. az containerapp logs show --name <app> --resource-group <rg> --tail 200
    2. az containerapp show --name <app> --resource-group <rg> --query 'properties.provisioningState'
    
    **Find**:
    - Error messages or stack traces
    - Resource provisioning failures
    - Configuration mismatches
    
    **Return** (max 15 lines):
    - Root cause (1-2 sentences)
    - Key error lines only (max 5)
    - Suggested fix command
    
    Do NOT include full log output.",
  description: "Debug: [deployment issue]"
)
When to Delegate vs Inline
Delegate to SubagentKeep Inline
Full log analysis (100+ lines)Quick status check
Multi-resource debuggingSingle az command
RBAC permission auditContainer image query
Startup failure diagnosisProvisioning state check

Quick Commands

CommandPurposeTime
azd upFull deployment (Entra app + infrastructure + container)10-12 min
azd deployCode-only deployment (Docker rebuild + push)3-5 min
azd provisionRe-run infrastructure + AI Foundry discovery5-7 min

Deployment Phases

  1. preprovision → AI Foundry auto-discovery + tenant detection. For CI: azd env set ENTRA_SERVICE_MANAGEMENT_REFERENCE "<guid>"
  2. provision → Deploy Azure resources via Bicep (infrastructure + Entra app via Microsoft Graph Bicep extension + placeholder container image)
  3. postprovision → Sets identifierUri on Entra app + updates redirect URIs + assigns RBAC to AI Foundry + generates local dev config
  4. predeploy → Builds container (local Docker or ACR cloud build)

Implementation:

  • infra/entra-app.bicep (Entra app registration via Microsoft Graph Bicep extension)
  • deployment/hooks/preprovision.ps1 (AI Foundry discovery)
  • deployment/hooks/postprovision.ps1 (Entra config + RBAC + local config generation)
  • deployment/hooks/predeploy.ps1 (container build + push)
  • deployment/hooks/modules/Get-AIFoundryAgents.ps1 (agent discovery via REST)

Docker Multi-Stage Build

Build order: React → .NET → Runtime

  • Frontend: deployment/docker/frontend.Dockerfile
  • Backend: deployment/docker/backend.Dockerfile
  • Custom npm registries: Add .npmrc to frontend/ directory

AI Foundry Resource Configuration

Auto-discovery (azd up): Searches subscription for AI Foundry resources → prompts to select if multiple → discovers agents via REST API → configures RBAC.

Change resource: Run azd provision to re-run discovery, or:

powershell
azd env set AI_FOUNDRY_RESOURCE_GROUP <rg>
azd provision

Container Infrastructure

  • Health Probes: Liveness (GET /api/health every 30s) and startup (GET /api/health every 10s, 5s initial delay) probes configured on the Container App
  • ACR Pull: Uses a user-assigned managed identity with AcrPull role — no admin credentials or secrets. The MI is created in main-infrastructure.bicep before the Container App, avoiding the chicken-and-egg problem.
  • Resource Defaults: 0.5 vCPU, 1GB RAM, 0-3 replicas (all parameterized in container-app.bicep)

Troubleshooting

IssueFix
VITE_ENTRA_SPA_CLIENT_ID not setRun azd up to generate .env files
AI_AGENT_ENDPOINT not configuredRun azd provision to re-discover AI Foundry
No AI Foundry resources foundCreate at https://ai.azure.com
Multiple AI Foundry resourcesRun azd provision to select different resource
Container not updatingCheck az containerapp logs show --name $app --resource-group $rg
Container fails health checkVerify /api/health endpoint returns 200 — check container logs for startup errors

Useful Commands

powershell
# Check current container image
az containerapp show --name $app --resource-group $rg `
    --query "properties.template.containers[0].image"

# View container logs
az containerapp logs show --name $app --resource-group $rg --tail 100

# Check RBAC assignments
$principalId = az containerapp show --name $app --resource-group $rg `
    --query "identity.principalId" -o tsv
az role assignment list --assignee $principalId

Show full SKILL.md (261 more words)Show less

Preprovision Hook Details

File: deployment/hooks/preprovision.ps1

What it does:

  1. Discovers AI Foundry resources in subscription (prompts if multiple)
  2. Discovers agents via REST API using Get-AIFoundryAgents.ps1
  3. Auto-detects tenant ID
  4. Sets azd environment variables

Note: Entra app registration is handled by Bicep (infra/entra-app.bicep), not this hook.

Postprovision Hook Details

File: deployment/hooks/postprovision.ps1

What it does:

  1. Sets identifierUri (api://{clientId}) on Entra app — can't be done in Bicep because it references the auto-generated appId
  2. Updates Entra app redirect URIs (localhost + Container App FQDN)
  3. Assigns Cognitive Services User role to Container App's managed identity on AI Foundry resource (via Azure CLI, not Bicep)
  4. Generates local dev config files (.env.local for frontend, .env for backend)

Why RBAC via CLI?: Using Azure CLI for role assignment prevents azd from tracking the external AI Foundry resource group, avoiding accidental deletion on azd down.

Predeploy Hook Details

File: deployment/hooks/predeploy.ps1

What it does:

  1. Detects if Docker is available and running
  2. Uses local Docker build + push if available (~2 min)
  3. Falls back to ACR cloud build if Docker unavailable (~4-5 min)
  4. Updates Container App with new image (if it exists)
  5. Sets SERVICE_WEB_IMAGE_NAME env var for Bicep

Dockerfile Example

File: deployment/docker/frontend.Dockerfile (production build)

dockerfile
# Stage 1: Build React Frontend
FROM node:22-alpine AS frontend-builder
ARG ENTRA_SPA_CLIENT_ID
ARG ENTRA_TENANT_ID
WORKDIR /app/frontend
COPY frontend/ ./
RUN npm ci
# Remove local .env files to prevent localhost config
RUN rm -f .env.local .env.development .env
ENV NODE_ENV=production
ENV VITE_ENTRA_SPA_CLIENT_ID=$ENTRA_SPA_CLIENT_ID
ENV VITE_ENTRA_TENANT_ID=$ENTRA_TENANT_ID
RUN npm run build

# Stage 2: Build .NET Backend
FROM mcr.microsoft.com/dotnet/sdk:10.0 AS backend-builder
WORKDIR /app
COPY backend/WebApp.sln ./
COPY backend/WebApp.Api/WebApp.Api.csproj ./backend/WebApp.Api/
COPY backend/WebApp.ServiceDefaults/WebApp.ServiceDefaults.csproj ./backend/WebApp.ServiceDefaults/
RUN dotnet restore backend/WebApp.Api/WebApp.Api.csproj
COPY backend/ ./backend/
RUN dotnet publish backend/WebApp.Api/WebApp.Api.csproj -c Release -o /app/publish

# Stage 3: Runtime - Single container serving API + static files
FROM mcr.microsoft.com/dotnet/aspnet:10.0-alpine
WORKDIR /app
COPY --from=backend-builder /app/publish ./
COPY --from=frontend-builder /app/frontend/dist ./wwwroot
EXPOSE 8080
ENV ASPNETCORE_URLS=http://+:8080
ENV ASPNETCORE_ENVIRONMENT=Production
ENTRYPOINT ["dotnet", "WebApp.Api.dll"]
  • writing-csharp-code - Backend coding patterns for Container App configuration
  • writing-bicep-templates - Infrastructure templates for Azure resources
  • troubleshooting-authentication - Entra ID and RBAC debugging

Official Documentation

© microsoft-foundry, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/deploying-to-azure of microsoft-foundry/foundry-agent-webapp.

Open the folder on GitHubat commit f6cb362

Compare with similar skills

Deploying To Azure next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deploying To Azure compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deploying To Azure this skillmicrosoft-foundry/foundry-agent-webapp127—~2.2kAutomated safety check: WarnMIT
Aspiremicrosoft/aspire.dev1964 repos~1.1kAutomated safety check: PassMIT
Aspire DeploymentCommunityToolkit/Aspire629—~4.5kAutomated safety check: NotesMIT
Medusa Cloud Local Buildmedusajs/medusa-agent-skills227—~1kAutomated safety check: NotesNone
Azure Anomaly DetectorMicrosoftDocs/Agent-Skills777—~1.1kAutomated safety check: PassCC-BY-4.0
Azure Preparemicrosoft/GitHub-Copilot-for-Azure2551 repos~3.2kAutomated safety check: PassMIT

Similar skills

  • Aspire

    microsoft/aspire.dev

    Official

    Orchestrates Aspire distributed applications using the Aspire CLI for running, debugging, and managing distributed apps.

    196 GitHub starsUsed in 4 repos~1.1k tokens
    DevOps & CloudAuto-check passed
  • Aspire Deployment

    CommunityToolkit/Aspire

    WORKFLOW SKILL — Deploy Aspire apps from AppHost models to Docker Compose, Kubernetes, Azure, AWS, or preview Radius.

    629 GitHub stars~4.5k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Medusa Cloud Local Build

    medusajs/medusa-agent-skills

    Reproduces a Medusa Cloud build on your machine with mcloud local build, to debug build-failed deployments without pushing or waiting on Cloud.

    227 GitHub stars~1k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Azure Anomaly Detector

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure AI Anomaly Detector development including troubleshooting, best practices, limits & quotas, configuration, and deployment.

    777 GitHub stars~1.1k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Azure Prepare

    microsoft/GitHub-Copilot-for-Azure

    Official

    Prepare azd-based Azure projects for deployment: generates azure.yaml, infrastructure (Bicep/Terraform), and Dockerfiles for the Azure Developer CLI (azd) workflow.

    255 GitHub starsUsed in 1 repo~3.2k tokens
    DevOps & CloudAuto-check passed
  • Azure App Onboard Prereq

    microsoft/GitHub-Copilot-for-Azure

    Official

    Assess whether source code is ready to deploy to Azure — the check BEFORE infrastructure work.

    255 GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from microsoft-foundry/foundry-agent-webapp

All 19 skills in this repo
  • Committing Code

    microsoft-foundry/foundry-agent-webapp

    Provides commit message format and workflow for this repository.

    127 GitHub stars~512 tokensUpdated 5 mo ago
    Auto-check passed
  • Implementing Chat Streaming

    microsoft-foundry/foundry-agent-webapp

    Provides SSE streaming patterns for the chat API and frontend.

    127 GitHub stars~1.9k tokensUpdated 5 mo ago
    Auto-check passed
  • Planning Features

    microsoft-foundry/foundry-agent-webapp

    Provides structured plan template for feature implementation.

    127 GitHub stars~548 tokensUpdated 5 mo ago
    Auto-check passed
  • Researching Azure AI SDK

    microsoft-foundry/foundry-agent-webapp

    Provides research patterns for Foundry Agent Service SDK. An agent skill from microsoft-foundry/foundry-agent-webapp.

    127 GitHub stars~4.7k tokensUpdated 5 mo ago
    Auto-check passed
  • Syncing MCP Servers

    microsoft-foundry/foundry-agent-webapp

    Synchronize MCP server configuration between VS Code (.vscode/mcp.json) and Copilot CLI (~/.copilot/mcp-config.json).

    127 GitHub stars~1.3k tokensUpdated 5 mo ago
    Auto-check passed
  • Testing CLI Compatibility

    microsoft-foundry/foundry-agent-webapp

    Validate that Copilot CLI can see all repo skills, MCP servers, and custom instructions.

    127 GitHub stars~736 tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about Deploying To Azure

What does Deploying To Azure do?

Provides deployment commands and troubleshooting for Azure Container Apps. Deploying To Azure is an agent skill from microsoft-foundry/foundry-agent-webapp. Provides deployment commands and troubleshooting for Azure Container Apps.

When should I use Deploying To Azure?

Deploying To Azure fits situations like: running azd commands; deploying containers; debugging deployment failures; updating infrastructure in this repository.

How do I install Deploying To Azure in Claude Code?

Run `npx skills add microsoft-foundry/foundry-agent-webapp --skill deploying-to-azure -a claude-code`. Or copy the skill folder (.github/skills/deploying-to-azure in microsoft-foundry/foundry-agent-webapp) into .claude/skills/deploying-to-azure in your project. Claude Code loads it when a task matches its description.

How do I install Deploying To Azure in Codex?

Run `npx skills add microsoft-foundry/foundry-agent-webapp --skill deploying-to-azure -a codex`. Or copy the skill folder (.github/skills/deploying-to-azure in microsoft-foundry/foundry-agent-webapp) into .agents/skills/deploying-to-azure in your project. Codex loads it when a task matches its description.

Can I use Deploying To Azure in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft-foundry/foundry-agent-webapp --skill deploying-to-azure -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deploying-to-azure, .gemini/skills/deploying-to-azure, .github/skills/deploying-to-azure and .opencode/skills/deploying-to-azure in your project.

What does Deploying To Azure need to run?

Going by SKILL.md and its folder, Deploying To Azure needs the command-line tools its instructions call (az). Our summary lists: Docker.

Does Deploying To Azure access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and ai.azure.com. This is read from the text; nothing was executed.

Is Deploying To Azure safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Deploying To Azure use?

Deploying To Azure is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deploying To Azure use?

About 2.2k tokens (SKILL.md is roughly 8.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Deploying To Azure?

Skills that share tags, products or a category with Deploying To Azure: Aspire (microsoft/aspire.dev, 196 stars), Aspire Deployment (CommunityToolkit/Aspire, 629 stars), Medusa Cloud Local Build (medusajs/medusa-agent-skills, 227 stars) and Azure Anomaly Detector (MicrosoftDocs/Agent-Skills, 777 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deploying To Azure?

microsoft-foundry (a GitHub organization) maintains it in microsoft-foundry/foundry-agent-webapp, which has 127 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on April 21, 2026.

Source: microsoft-foundry/foundry-agent-webapp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.