# Azure Deploy > Ejecuta despliegues de aplicaciones YA PREPARADAS que tengan .azure/deployment-plan.md y archivos de infraestructura. Para crear una app nueva, usa azure-prepare en su lugar. Fuente: https://skillsagentes.com/skills/microsoft/azure-skills/azure-deploy Markdown: https://skillsagentes.com/skills/microsoft/azure-skills/azure-deploy.md Repositorio: https://github.com/microsoft/azure-skills Autor: microsoft Licencia: MIT Actualizado: el mes pasado Coste de contexto: 211 tok instalada, 1.7k tok al activarse, 33.3k tok con todos los archivos del bundle Bundle: 41 archivos, 130 KB Permisos que pide: ninguno declarado ## Instalación Un skill son archivos markdown: los mismos archivos valen para cualquier agente y lo único que cambia es el directorio de destino, es decir la bandera `--agent`. Añade `-g` para instalarlo en todos los proyectos de la máquina. ```bash # Claude Code npx -y skills add microsoft/azure-skills --skill azure-deploy --agent claude-code # Cursor npx -y skills add microsoft/azure-skills --skill azure-deploy --agent cursor # Codex npx -y skills add microsoft/azure-skills --skill azure-deploy --agent codex # Gemini CLI npx -y skills add microsoft/azure-skills --skill azure-deploy --agent gemini # Windsurf npx -y skills add microsoft/azure-skills --skill azure-deploy --agent windsurf # Cline npx -y skills add microsoft/azure-skills --skill azure-deploy --agent cline ``` ## Qué hace - Ejecuta despliegues de aplicaciones **ya preparadas**: corre `azd up`, `azd deploy`, `terraform apply` y comandos `az deployment` con recuperación de errores incorporada. - Exige dos prerrequisitos antes de nada: que `azure-prepare` haya dejado `.azure/deployment-plan.md`, y que `azure-validate` haya puesto el estado en `Validated`. - Prohíbe expresamente cambiar el estado del plan a `Validated` por su cuenta: solo `azure-validate` está autorizado a hacerlo tras ejecutar las comprobaciones reales. ## Cuándo usarla - Se pide ejecutar el despliegue, subir a producción, publicar en Azure o "ship it", sobre una app ya preparada y validada. ## Cuándo no - Cuando se pide "crear y desplegar", "construir y desplegar" o montar infraestructura nueva: eso es `azure-prepare`. ## Qué la activa - "ejecuta azd up" - "despliega a producción" - "terraform apply" - "publica esto en Azure" ## Antes de instalar - Requiere `.azure/deployment-plan.md` de azure-prepare y estado `Validated` de azure-validate; sin ambos, el archivo manda parar de inmediato. ## Archivos - SKILL.md — 6 KB - references/auth-best-practices.md — 6 KB - references/global-rules.md — 1 KB - references/live-role-verification.md — 4 KB - references/pre-deploy-checklist.md — 18 KB - references/recipes/README.md — 442 B - references/recipes/azcli/README.md — 2 KB - references/recipes/azcli/errors.md — 510 B - references/recipes/azcli/verify.md — 2 KB - references/recipes/azd/README.md — 4 KB - references/recipes/azd/ef-migrations.md — 5 KB - references/recipes/azd/errors.md — 16 KB - references/recipes/azd/functions-deploy.md — 3 KB - references/recipes/azd/post-deployment.md — 4 KB - references/recipes/azd/scripts/apply-migrations.ps1 — 2 KB - references/recipes/azd/scripts/apply-migrations.sh — 2 KB - references/recipes/azd/scripts/grant-and-migrate.ps1 — 4 KB - references/recipes/azd/scripts/grant-and-migrate.sh — 4 KB - references/recipes/azd/sql-entra-auth.md — 3 KB - references/recipes/azd/sql-managed-identity.md — 7 KB - references/recipes/azd/verify.md — 5 KB - references/recipes/bicep/README.md — 2 KB - references/recipes/bicep/errors.md — 529 B - references/recipes/bicep/verify.md — 794 B - references/recipes/cicd/README.md — 1 KB - references/recipes/cicd/errors.md — 559 B - references/recipes/cicd/examples/azdo-azd.yml — 509 B - references/recipes/cicd/examples/azdo-multistage.yml — 860 B - references/recipes/cicd/examples/github-azd.yml — 817 B - references/recipes/cicd/examples/github-bicep.yml — 687 B - references/recipes/cicd/verify.md — 777 B - references/recipes/terraform/README.md — 3 KB - references/recipes/terraform/errors.md — 881 B - references/recipes/terraform/verify.md — 782 B - references/region-availability.md — 3 KB - references/sdk/azd-deployment.md — 792 B - references/sdk/azure-identity-dotnet.md — 941 B - references/sdk/azure-identity-java.md — 1 KB - references/sdk/azure-identity-py.md — 1 KB - references/sdk/azure-identity-ts.md — 1 KB - references/troubleshooting.md — 8 KB ## SKILL.md Reproducido tal cual desde microsoft/azure-skills bajo MIT. Esta sección es el documento original y está en inglés. # Azure Deploy > **AUTHORITATIVE GUIDANCE — MANDATORY COMPLIANCE** > > **PREREQUISITE**: The **azure-validate** skill **MUST** be invoked and completed with status `Validated` BEFORE executing this skill. > **⛔ STOP — PREREQUISITE CHECK REQUIRED** > Before proceeding, verify BOTH prerequisites are met: > > 1. **azure-prepare** was invoked and completed → `.azure/deployment-plan.md` exists > 2. **azure-validate** was invoked and passed → plan status = `Validated` > > If EITHER is missing, **STOP IMMEDIATELY**: > - No plan? → Invoke **azure-prepare** skill first > - Status not `Validated`? → Invoke **azure-validate** skill first > > **⛔ DO NOT MANUALLY UPDATE THE PLAN STATUS** > > You are **FORBIDDEN** from changing the plan status to `Validated` yourself. Only the **azure-validate** skill is authorized to set this status after running actual validation checks. If you update the status without running validation, deployments will fail. > > **DO NOT ASSUME** the app is ready. **DO NOT SKIP** validation to save time. Skipping steps causes deployment failures. The complete workflow ensures success: > > `azure-prepare` → `azure-validate` → `azure-deploy` ## Triggers Activate this skill when user wants to: - Execute deployment of an already-prepared application (azure.yaml and infra/ exist) - Push updates to an existing Azure deployment - Run `azd up`, `azd deploy`, or `az deployment` on a prepared project - Ship already-built code to production - Deploy an application that already includes API Management (APIM) gateway infrastructure > **Scope**: This skill executes deployments. It does not create applications, generate infrastructure code, or scaffold projects. For those tasks, use **azure-prepare**. > **APIM / AI Gateway**: Use this skill to deploy applications whose APIM/AI gateway infrastructure was already created during **azure-prepare**. For creating or changing APIM resources, see [APIM deployment guide](https://learn.microsoft.com/azure/api-management/get-started-create-service-instance). For AI governance policies, invoke **azure-aigateway** skill. ## Rules 1. Run after azure-prepare and azure-validate 2. `.azure/deployment-plan.md` must exist with status `Validated` 3. **Pre-deploy checklist required** — [Pre-Deploy Checklist](references/pre-deploy-checklist.md) 4. ⛔ **Destructive actions require `ask_user`** — [global-rules](references/global-rules.md) 5. **Scope: deployment execution only** — This skill owns execution of `azd up`, `azd deploy`, `terraform apply`, and `az deployment` commands. These commands are run through this skill's error recovery and verification pipeline. --- ## Steps | # | Action | Reference | |---|--------|-----------| | 1 | **Check Plan** — Read `.azure/deployment-plan.md`, verify status = `Validated` AND **Validation Proof** section is populated | `.azure/deployment-plan.md` | | 2 | **Pre-Deploy Checklist** — MUST complete ALL steps | [Pre-Deploy Checklist](references/pre-deploy-checklist.md) | | 3 | **Load Recipe** — Based on `recipe.type` in `.azure/deployment-plan.md` | [recipes/README.md](references/recipes/README.md) | | 4 | **RBAC Health Check** — For Container Apps + ACR with managed identity: run `azd provision --no-prompt`, then verify `AcrPull` role has propagated before proceeding (see checklist) | [Pre-Deploy Checklist — Container Apps RBAC](references/pre-deploy-checklist.md#container-apps--acr--pre-deploy-rbac-health-check) | | 5 | **Execute Deploy** — Follow recipe steps | Recipe README | | 6 | **Post-Deploy** — Configure SQL managed identity and apply EF migrations if applicable | [Post-Deployment](references/recipes/azd/post-deployment.md) | | 7 | **Handle Errors** — See recipe's `errors.md` | — | | 8 | **Verify Success** — Confirm deployment completed and endpoints are accessible | [Verification](references/recipes/azd/verify.md) | | 9 | **Live Role Verification** — Query Azure to confirm provisioned RBAC roles are correct and sufficient | [live-role-verification.md](references/live-role-verification.md) | | 10 | **Report Results** — Present deployed endpoint URLs to the user as fully-qualified `https://` links | [Verification](references/recipes/azd/verify.md) | > **⛔ URL FORMAT RULE** > > When presenting endpoint URLs to the user, you **MUST** always use fully-qualified URLs with the `https://` scheme (e.g. `https://myapp.azurewebsites.net`, not `myapp.azurewebsites.net`). Many Azure CLI commands return bare hostnames without a scheme — always prepend `https://` before presenting them. > **⛔ VALIDATION PROOF CHECK** > > When checking the plan, verify the **Validation Proof** section (Section 7) contains actual validation results with commands run and timestamps. If this section is empty, validation was bypassed — invoke **azure-validate** skill first. ## SDK Quick References - **Azure Developer CLI**: [azd](references/sdk/azd-deployment.md) - **Azure Identity**: [Python](references/sdk/azure-identity-py.md) | [.NET](references/sdk/azure-identity-dotnet.md) | [TypeScript](references/sdk/azure-identity-ts.md) | [Java](references/sdk/azure-identity-java.md) ## MCP Tools | Tool | Purpose | |------|---------| | `mcp_azure_mcp_subscription_list` | List available subscriptions | | `mcp_azure_mcp_group_list` | List resource groups in subscription | | `mcp_azure_mcp_azd` | Execute AZD commands | | `azure__role` | List role assignments for live RBAC verification (step 9) | ## References - [Troubleshooting](references/troubleshooting.md) - Common issues and solutions - [Post-Deployment Steps](references/recipes/azd/post-deployment.md) - SQL + EF Core setup ## Dónde encaja - Categoría: [DevOps e infraestructura](https://skillsagentes.com/categorias/devops-infraestructura.md) — Despliegues, contenedores, IaC y flujos de gestión de incidentes. - Creador: [microsoft](https://skillsagentes.com/creators/microsoft.md) — 43 skills en el directorio - [Todas las skills](https://skillsagentes.com/skills.md) - [Ranking de instalaciones](https://skillsagentes.com/ranking.md) ## Otras skills del mismo repositorio - [Microsoft Foundry](https://skillsagentes.com/skills/microsoft/azure-skills/microsoft-foundry.md): Despliega, evalúa, ajusta y gestiona agentes de Foundry de punta a punta con azd: agentes hospedados, evaluación por lotes y continua, optimizador de prompts y fine-tuning (SFT/DPO/RFT). - [Azure Prepare](https://skillsagentes.com/skills/microsoft/azure-skills/azure-prepare.md): Prepara proyectos Azure basados en azd para desplegar: genera azure.yaml, la infraestructura (Bicep o Terraform) y los Dockerfiles del flujo del Azure Developer CLI. - [Azure Diagnostics](https://skillsagentes.com/skills/microsoft/azure-skills/azure-diagnostics.md): Depura incidencias de producción en Azure con AppLens, Azure Monitor, resource health y triaje seguro. Cubre App Service, Container Apps, Functions, AKS, VMs y mensajería. - [Azure Validate](https://skillsagentes.com/skills/microsoft/azure-skills/azure-validate.md): Validación previa al despliegue en Azure. Comprueba en profundidad la configuración, la infraestructura (Bicep o Terraform), los roles RBAC, los permisos de identidad administrada y los prerrequisitos. - [Deploy Model](https://skillsagentes.com/skills/microsoft/azure-skills/deploy-model.md): Skill unificado de despliegue de modelos de Azure OpenAI con enrutado por intención: despliegues rápidos con preset, despliegues personalizados y descubrimiento de capacidad entre regiones y proyectos. --- Skills Agentes · [Índice de páginas en markdown](https://skillsagentes.com/sitemap.md) · [Inicio](https://skillsagentes.com/index.md)