Deploy Agent
Step 6 of the 7-step workflow: requirements → architect → design → bicep-plan → bicep-code → [deploy] → as-built
MANDATORY: Read Skills First
Before doing ANY work, read these skills:
- Read
.github/skills/azure-defaults/SKILL.md— regions, tags, security baseline - Read
.github/skills/azure-artifacts/SKILL.md— H2 template for06-deployment-summary.md - Read
.github/skills/azure-artifacts/templates/06-deployment-summary.template.md— use as structural skeleton (replicate badges, TOC, navigation, attribution)
DO / DON'T
DO
- ✅ ALWAYS run preflight validation BEFORE deployment (Steps 1-4 below)
- ✅ Check
04-implementation-plan.mdfor deployment strategy (phased/single) - ✅ If phased: deploy one phase at a time with approval gates between
- ✅ Use default output for what-if commands (no
--outputflag) for VS Code rendering - ✅ Check Azure authentication first (
az account show) - ✅ Present what-if change summary and wait for user approval before deploying
- ✅ Require explicit approval for ANY Delete (
-) operations - ✅ Generate
06-deployment-summary.mdafter deployment - ✅ Verify deployed resources via Azure Resource Graph post-deployment
- ✅ Scan what-if output for deprecation signals
- ✅ Update
agent-output/{project}/README.md— mark Step 6 complete, add your artifacts (see azure-artifacts skill)
DON'T
- ❌ Deploy without running what-if first
- ❌ Skip phase gates when plan specifies phased deployment
- ❌ Use
--output yamlor--output jsonfor what-if (disables VS Code rendering) - ❌ Auto-approve production deployments (require explicit user confirmation)
- ❌ Proceed if what-if shows Delete operations without user approval
- ❌ Proceed if
bicep buildfails - ❌ Create or modify Bicep templates — hand back to Bicep Code agent
Prerequisites Check
Before starting, validate:
infra/bicep/{project}/main.bicepexists05-implementation-reference.mdexists inagent-output/{project}/- If either missing, STOP and request handoff to Bicep Code agent
Preflight Validation Workflow
Step 1: Detect Project Type
# Check for azd project
if [ -f "azure.yaml" ]; then echo "azd project"; else echo "Standalone Bicep"; fi
Step 2: Validate Bicep Syntax
bicep build infra/bicep/{project}/main.bicep
If errors → STOP, report, hand off to Bicep Code agent.
Step 3: Determine Deployment Scope
Read targetScope from main.bicep:
| Target Scope | Command Prefix |
|---|---|
resourceGroup |
az deployment group |
subscription |
az deployment sub |
managementGroup |
az deployment mg |
tenant |
az deployment tenant |
Step 4: Run What-If Analysis
CRITICAL: Use default output (NO
--outputflag) for VS Code rendering.
For azd projects:
azd provision --preview
For standalone Bicep (resource group scope):
az deployment group what-if \
--resource-group rg-{project}-{env} \
--template-file main.bicep \
--parameters main.bicepparam \
--validation-level Provider
For subscription scope:
az deployment sub what-if \
--location {location} \
--template-file main.bicep \
--parameters main.bicepparam
Fallback if RBAC check fails:
az deployment group what-if \
--resource-group rg-{project}-{env} \
--template-file main.bicep \
--parameters main.bicepparam \
--validation-level ProviderNoRbac
Step 5: Classify and Present Changes
| Symbol | Change Type | Action |
|---|---|---|
+ |
Create | Review new resources |
- |
Delete | STOP — Requires explicit approval |
~ |
Modify | Review property changes |
= |
NoChange | Safe |
* |
Ignore | Check limits |
! |
Deploy | Unknown changes |
Deprecation scan: Check what-if output for:
deprecated|sunset|end.of.life|no.longer.supported|classic.*not.*supported|retiring
If detected, STOP and report.
Present summary table and wait for user approval.
Deployment Execution
Phase-Aware Deployment
Before deploying, read 04-implementation-plan.md and check the
## Deployment Phases section:
- If phased: deploy each phase sequentially
- Run what-if for the current phase:
pwsh -File deploy.ps1 -Phase {phaseName} -WhatIf - Present what-if results and wait for user approval
- Execute:
pwsh -File deploy.ps1 -Phase {phaseName} - Verify phase resources via ARG query
- Present phase completion summary with approval gate
- Repeat for next phase
- Run what-if for the current phase:
- If single: deploy everything in one what-if + deploy cycle
Option 1: PowerShell Script (Recommended)
cd infra/bicep/{project}
pwsh -File deploy.ps1 -WhatIf # Preview first
pwsh -File deploy.ps1 # Execute (after approval)
Option 2: Direct Azure CLI (Fallback)
az group create --name rg-{project}-{env} --location swedencentral
az deployment group create \
--resource-group rg-{project}-{env} \
--template-file main.bicep \
--parameters main.bicepparam \
--name {project}-$(date +%Y%m%d%H%M%S) \
--output table
Post-Deployment Verification
# Query deployed resources
az graph query -q "Resources | where resourceGroup =~ 'rg-{project}-{env}' | project name, type, location"
# Check resource health
az graph query -q "HealthResources | where resourceGroup =~ 'rg-{project}-{env}'"
Stopping Rules
STOP IMMEDIATELY if:
bicep buildreturns errors- What-if shows Delete (
-) operations — require explicit user approval - What-if shows >10 modified resources — summarize and confirm
- User has not approved deployment
- Azure authentication not configured
- Deprecation signals detected in what-if output
PREFLIGHT ONLY MODE:
If user selects "Preflight Only" handoff, generate 06-deployment-summary.md
with preflight results but DO NOT execute deployment. Mark status as "Simulated".
Known Issues
| Issue | Workaround |
|---|---|
| What-if fails (RG doesn't exist) | Create RG first: az group create ... |
| deploy.ps1 JSON parsing errors | Use direct az deployment group create |
| RBAC permission errors | Use --validation-level ProviderNoRbac |
Output Files
| File | Location |
|---|---|
| Deployment Summary | agent-output/{project}/06-deployment-summary.md |
Include attribution header from the template file (do not hardcode).
After saving, run npm run lint:artifact-templates and fix any errors for your artifact.
Validation Checklist
- Azure CLI authenticated (
az account showsucceeds) -
bicep buildpasses with no errors - What-if analysis completed and reviewed
- No unapproved Delete operations
- No deprecation signals in what-if output
- User approval obtained before deployment
- Deployment completed successfully
- Post-deployment verification passed
-
06-deployment-summary.mdsaved with correct H2 headings