Official agent skill

Azure Deploy

by microsoft in microsoft/GitHub-Copilot-for-Azure

Execute Azure deployments for ALREADY-PREPARED applications that have existing .azure/deployment-plan.md and infrastructure files.

OfficialMITAuto-check passedDevOps & Cloud

Install Azure Deploy

skills CLI
$ npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-deploy -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/GitHub-Copilot-for-Azure azure-deploy --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/GitHub-Copilot-for-Azure.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/azure-skills/skills/azure-deploy .claude/skills/azure-deploy && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-deploy
GitHub stars
255
Used in
1 other repo
Token cost
~1.6k tokens
SKILL.md length
570 words
Files
47 (incl. references)
Skills in repo
56
Repo updated
First seen
Licence
MIT

At a glance

Execute Azure deployments for ALREADY-PREPARED applications that have existing .azure/deployment-plan.md and infrastructure files.

  • Works in 5 steps: Run after azure-prepare and azure-validate → .azure/deployment-plan.md must exist… → Pre-deploy checklist required —… → …
  • The user asks to CREATE a new application — use azure-prepare instead
  • SKILL.md covers Triggers, Rules, Steps and SDK Quick References, plus 2 more sections
  • Runs PowerShell and Shell scripts from its folder; calls az and terraform

What it does

Azure Deploy is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization. Execute Azure deployments for ALREADY-PREPARED applications that have existing .azure/deployment-plan.md and infrastructure files. DO NOT use this skill when the user asks to CREATE a new application — use azure-prepare instead. This skill runs azd up, azd deploy, terraform apply, and az deployment commands with built-in error recovery. Requires .azure/deployment-plan.md from azure-prepare and validated status from azure-validate. WHEN: "run azd up", "run azd deploy", "execute deployment", "push to production"…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 51 other files, including reference files (for example `references/auth-best-practices.md`, `references/global-rules.md` and `references/live-role-verification.md`).

It sits in DevOps & Cloud, covering Deployment and Infrastructure as code. It works with Microsoft Azure, Terraform, Bicep and Azure API Management. The repository describes itself as: GitHub Copilot for Azure. The licence is MIT.

When your agent uses it

  • The user asks to CREATE a new application — use azure-prepare instead
  • : create and deploy
  • Build and deploy
  • Create a new app

Example prompts

  • “run azd up”
  • “run azd deploy”
  • “execute deployment”
  • “/azure-deploy”

Requirements

  • A Bash shell
  • PowerShell

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Run after azure-prepare and azure-validate
  2. .azure/deployment-plan.md must exist with status Validated
  3. Pre-deploy checklist required — Pre-Deploy Checklist
  4. ⛔ Destructive actions require ask_user — global-rules
  5. Scope: deployment execution only — This skill owns execution of azd up, azd deploy, terraform apply, and az deployment commands. These…

What it can do on your machine

Read from SKILL.md and the folder at commit fcf2f3b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (PowerShell and Shell, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • az
    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Deploy loads about 1.6k tokens when it runs, and up to ~33k if it reads all its reference files. Until then it costs about 205 tokens; SKILL.md has 570 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~205
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~33k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/GitHub-Copilot-for-Azure at commit fcf2f3b, republished under its MIT licence (© microsoft). 570 words, ~1,645 tokens.

Download SKILL.mdSave it as .claude/skills/azure-deploy/SKILL.md (or your agent's skills folder). This skill also uses 46 other files; get the full folder from GitHub.
name
azure-deploy
description
Execute Azure deployments for ALREADY-PREPARED applications that have existing .azure/deployment-plan.md and infrastructure files. DO NOT use this skill when the user asks to CREATE a new application — use azure-prepare instead. This skill runs azd up, azd deploy, terraform apply, and az deployment commands with built-in error recovery. Requires .azure/deployment-plan.md from azure-prepare and validated status from azure-validate. WHEN: "run azd up", "run azd deploy", "execute deployment", "push to production", "push to cloud", "go live", "ship it", "bicep deploy", "terraform apply", "publish to Azure", "launch on Azure". DO NOT USE WHEN: "create and deploy", "build and deploy", "create a new app", "set up infrastructure", "create and deploy to Azure using Terraform" — use azure-prepare for these.
license
MIT
metadata.author
Microsoft
metadata.version
0.0.0-placeholder

Azure Deploy

AUTHORITATIVE GUIDANCE — MANDATORY COMPLIANCE

PREREQUISITE: The azure-validate skill MUST be invoked and completed with status Validated BEFORE executing this skill.

⛔ STOP — PREREQUISITE CHECK REQUIRED Before proceeding, verify BOTH prerequisites are met:

  1. azure-prepare was invoked and completed → .azure/deployment-plan.md exists
  2. azure-validate was invoked and passed → plan status = Validated

If EITHER is missing, STOP IMMEDIATELY:

  • No plan? → Invoke azure-prepare skill first
  • Status not Validated? → Invoke azure-validate skill first

⛔ DO NOT MANUALLY UPDATE THE PLAN STATUS

You are FORBIDDEN from changing the plan status to Validated yourself. Only the azure-validate skill is authorized to set this status after running actual validation checks. If you update the status without running validation, deployments will fail.

DO NOT ASSUME the app is ready. DO NOT SKIP validation to save time. Skipping steps causes deployment failures. The complete workflow ensures success:

azure-prepare → azure-validate → azure-deploy

Triggers

Activate this skill when user wants to:

  • Execute deployment of an already-prepared application (azure.yaml and infra/ exist)
  • Push updates to an existing Azure deployment
  • Run azd up, azd deploy, or az deployment on a prepared project
  • Ship already-built code to production
  • Deploy an application that already includes API Management (APIM) gateway infrastructure

Scope: This skill executes deployments. It does not create applications, generate infrastructure code, or scaffold projects. For those tasks, use azure-prepare.

APIM / AI Gateway: Use this skill to deploy applications whose APIM/AI gateway infrastructure was already created during azure-prepare. For creating or changing APIM resources, see APIM deployment guide. For AI governance policies, invoke azure-aigateway skill.

Rules

  1. Run after azure-prepare and azure-validate
  2. .azure/deployment-plan.md must exist with status Validated
  3. Pre-deploy checklist required — Pre-Deploy Checklist
  4. ⛔ Destructive actions require ask_user — global-rules
  5. Scope: deployment execution only — This skill owns execution of azd up, azd deploy, terraform apply, and az deployment commands. These commands are run through this skill's error recovery and verification pipeline.

Show full SKILL.md (263 more words)Show less

Steps

#ActionReference
1Check Plan — Read .azure/deployment-plan.md, verify status = Validated AND Validation Proof section is populated.azure/deployment-plan.md
2Pre-Deploy Checklist — MUST complete ALL stepsPre-Deploy Checklist
3Load Recipe — Based on recipe.type in .azure/deployment-plan.mdrecipes/README.md
4RBAC Health Check — For Container Apps + ACR with managed identity: run azd provision --no-prompt, then verify AcrPull role has propagated before proceeding (see checklist)Pre-Deploy Checklist — Container Apps RBAC
5Execute Deploy — Follow recipe stepsRecipe README
6Post-Deploy — Configure SQL managed identity and apply EF migrations if applicablePost-Deployment
7Handle Errors — See recipe's errors.md—
8Verify Success — Confirm deployment completed and endpoints are accessibleVerification
9Live Role Verification — Query Azure to confirm provisioned RBAC roles are correct and sufficientlive-role-verification.md
10Report Results — Present deployed endpoint URLs to the user as fully-qualified https:// linksVerification

⛔ URL FORMAT RULE

When presenting endpoint URLs to the user, you MUST always use fully-qualified URLs with the https:// scheme (e.g. https://myapp.azurewebsites.net, not myapp.azurewebsites.net). Many Azure CLI commands return bare hostnames without a scheme — always prepend https:// before presenting them.

⛔ VALIDATION PROOF CHECK

When checking the plan, verify the Validation Proof section (Section 7) contains actual validation results with commands run and timestamps. If this section is empty, validation was bypassed — invoke azure-validate skill first.

SDK Quick References

MCP Tools

ToolPurpose
mcp_azure_mcp_subscription_listList available subscriptions
mcp_azure_mcp_group_listList resource groups in subscription
mcp_azure_mcp_azdExecute AZD commands
azure__roleList role assignments for live RBAC verification (step 9)

References

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 46 other files (references) in plugins/azure-skills/skills/azure-deploy of microsoft/GitHub-Copilot-for-Azure.

  • SKILL.md
  • references/auth-best-practices.md
  • references/global-rules.md
  • references/live-role-verification.md
  • references/pre-deploy-checklist.md
  • references/recipes/README.md
  • references/recipes/azcli/README.md
  • references/recipes/azcli/errors.md
  • references/recipes/azcli/verify.md
  • references/recipes/azd/README.md
  • references/recipes/azd/ef-migrations.md
  • references/recipes/azd/errors.md
  • references/recipes/azd/functions-deploy.md
  • references/recipes/azd/post-deployment.md
  • references/recipes/azd/scripts/apply-migrations.ps1
  • references/recipes/azd/scripts/apply-migrations.sh
  • … and 31 more

Open the folder on GitHubat commit fcf2f3b

Used in 3 other repositories

We found 4 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in microsoft/GitHub-Copilot-for-Azure, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Azure Deploy next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Deploy compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Deploy this skillmicrosoft/GitHub-Copilot-for-Azure2551 repos~1.6kAutomated safety check: PassMIT
Apex Azure Deployjonathan-vella/apex217—~2.3kAutomated safety check: PassMIT
APIOps Deployment for Azure APIMthomast1906/github-copilot-agent-skills202—~3.6kAutomated safety check: PassMIT
Apex Azure Validatejonathan-vella/apex217—~1.8kAutomated safety check: PassMIT
Azure Architecture Autopilotgithub/awesome-copilot40k1 repos~1.9kAutomated safety check: PassMIT
Azure Bicep Skilltimothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT

Similar skills

  • Apex Azure Deploy

    jonathan-vella/apex

    WORKFLOW SKILL — Execute Azure deployments (azd up, azd deploy, terraform apply) for already-prepared apps with built-in error recovery.

    217 GitHub stars~2.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • APIOps Deployment for Azure APIM

    thomast1906/github-copilot-agent-skills

    Supplies Bicep and Terraform templates, CI/CD pipeline patterns and phased promotion plans for deploying Azure API Management with APIOps workflows.

    202 GitHub stars~3.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Apex Azure Validate

    jonathan-vella/apex

    WORKFLOW SKILL — Pre-deployment validation for Azure: config, infrastructure (Bicep/Terraform), permissions, prerequisites.

    217 GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    DevOps & CloudAuto-check passed
  • Azure Bicep Skill

    timothywarner-org/claude-code

    A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

    224 GitHub stars~2.9k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Official

    Deploy test resources and run Azure SDK tests in live, record, or playback mode.

    134 GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from microsoft/GitHub-Copilot-for-Azure

All 56 skills in this repo
  • Capacity

    microsoft/GitHub-Copilot-for-Azure

    Official

    Discovers available Azure OpenAI model capacity across regions and projects.

    255 GitHub starsUsed in 2 repos~1.7k tokens
    Auto-check passed
  • Deploy Model

    microsoft/GitHub-Copilot-for-Azure

    Official

    Unified Azure OpenAI model deployment skill with intelligent intent-based routing.

    255 GitHub starsUsed in 1 repo~1.8k tokens
    Auto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 3 repos~4k tokens
    Auto-check passed
  • Microsoft Foundry

    microsoft/GitHub-Copilot-for-Azure

    Official

    Build, deploy, evaluate, optimize, fine-tune, and manage Microsoft Foundry agents, models, and resources end to end.

    255 GitHub starsUsed in 1 repo~6.7k tokens
    Auto-check passed
  • Azure Storage

    microsoft/GitHub-Copilot-for-Azure

    Official

    Azure Storage Services including Blob Storage, File Shares, Queue Storage, Table Storage, and Data Lake.

    255 GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check passed
  • Preset

    microsoft/GitHub-Copilot-for-Azure

    Official

    Intelligently deploys Azure OpenAI models to optimal regions by analyzing capacity across all available regions.

    255 GitHub starsUsed in 2 repos~1.2k tokens
    Auto-check passed

Categories

Questions about Azure Deploy

What does Azure Deploy do?

Execute Azure deployments for ALREADY-PREPARED applications that have existing .azure/deployment-plan.md and infrastructure files. Azure Deploy is an agent skill from microsoft/GitHub-Copilot-for-Azure, published by the product's own GitHub organization.md and infrastructure files.

When should I use Azure Deploy?

Azure Deploy fits situations like: the user asks to CREATE a new application — use azure-prepare instead; : create and deploy; build and deploy; create a new app.

How do I install Azure Deploy in Claude Code?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-deploy -a claude-code`. Or copy the skill folder (plugins/azure-skills/skills/azure-deploy in microsoft/GitHub-Copilot-for-Azure) into .claude/skills/azure-deploy in your project. Claude Code loads it when a task matches its description.

How do I install Azure Deploy in Codex?

Run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-deploy -a codex`. Or copy the skill folder (plugins/azure-skills/skills/azure-deploy in microsoft/GitHub-Copilot-for-Azure) into .agents/skills/azure-deploy in your project. Codex loads it when a task matches its description.

Can I use Azure Deploy in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/GitHub-Copilot-for-Azure --skill azure-deploy -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-deploy, .gemini/skills/azure-deploy, .github/skills/azure-deploy and .opencode/skills/azure-deploy in your project.

What does Azure Deploy need to run?

Going by SKILL.md and its folder, Azure Deploy needs PowerShell and a shell for the scripts in its folder and the command-line tools its instructions call (az and terraform). Our summary lists: A Bash shell; PowerShell.

Does Azure Deploy access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Azure Deploy safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Deploy use?

Azure Deploy is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Deploy use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 31k tokens, read only when the agent opens those files.

What are the alternatives to Azure Deploy?

Skills that share tags, products or a category with Azure Deploy: Apex Azure Deploy (jonathan-vella/apex, 217 stars), APIOps Deployment for Azure APIM (thomast1906/github-copilot-agent-skills, 202 stars), Apex Azure Validate (jonathan-vella/apex, 217 stars) and Azure Architecture Autopilot (github/awesome-copilot, 40k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Deploy?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/GitHub-Copilot-for-Azure, which has 255 GitHub stars. The repository holds 56 skills in this directory. The repository was last updated on October 8, 2026.

Source: microsoft/GitHub-Copilot-for-Azure on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.