Azure / Azure/apiops-cli

apiops init: generate a Copilot prompt file to audit artifacts against APIM best practices

Offen
#202 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Feature P2
Vorherrschende Sprache
TypeScript
Sterne
26
Forks
9
Ø Merge
1 T. 3 Std.
Gemergte PRs (30 T.)
20

Beschreibung

## Problem or use case

After `apiops extract`, users have no guided way to check their extracted APIM artifacts against APIM best practices. The audit should look for anti-patterns (e.g. named values holding secrets that aren''t marked secret) that otherwise go unnoticed. We want a low-friction, Copilot-assisted audit that also offers to **fix** the issues it finds.

## Proposed solution

Have `apiops init` generate an additional Copilot prompt file — e.g. `.github/prompts/apiops-check-best-practices.prompt.md` — following the same generation pattern as the existing identity-setup prompt (`src/templates/copilot/identity-setup-prompt.ts`, written in `src/services/init-service.ts`). When opened with GitHub Copilot, the prompt guides the user through auditing the artifacts in the repo against a **focused** set of APIM best practices.

### Scope — only things apiops-cli tracks

Keep the checks centered on apiops-managed artifacts (policies, named values, backends, diagnostics/loggers, subscriptions, products). Explicitly **out of scope**: infra/SKU/networking/scale guidance from the WAF doc that doesn''t map to apiops artifacts.

### Checks (initial set)

1. **Hardcoded secrets in `policy.xml`** (headline check) — detect literal secrets in policy XML (`set-header` auth/keys, `set-query-parameter` `code`/`sig`, `authentication-basic` password, `validate-jwt` keys, connection-string fragments).
- **Offer to fix:** create a (secret) **named value** for the secret and rewrite the policy to reference it via `{{named-value}}`, per https://learn.microsoft.com/en-us/azure/api-management/api-management-howto-properties
2. **Named values holding secrets** that aren''t marked `secret: true` or aren''t Key Vault–backed → flag and offer to mark/migrate.
3. **Backend URLs / keys inlined in policies** instead of using named values/backends → suggest parameterizing.

(Start with check #1; #2–#3 can follow.)

### Reference

APIM best-practice guidance: https://learn.microsoft.com/en-us/azure/well-architected/service-guides/azure-api-management — used as a source, but the prompt should distill only the artifact-level items above rather than the full large-deployment guidance.

## Affected command

`apiops init` (generates the prompt file); the prompt itself assists with `apiops extract` output.

## Implementation notes

- New template under `src/templates/copilot/` (e.g. `best-practices-prompt.ts`) + embedded markdown, mirroring `identity-setup-prompt.ts`.
- Write the file in `init-service.ts` alongside the identity prompt (conflict-check + add to `generatedFiles.configs`), and mention it in the `init-command.ts` next-steps output.
- Relates to #198 (the CLI-side redact-and-warn for the same class of issue; this prompt is the interactive remediation counterpart).

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne mit src/templates/copilot/identity-setup-prompt.ts und src/services/init-service.ts, um dem bestehenden Muster für die Prompt-Generierung zu folgen. Untersuche dann src/commands/init-command.ts auf die Ausgabe der nächsten Schritte und die Handhabung von generatedFiles.configs. Als abgeschlossen gilt die Aufgabe, wenn apiops init den neuen Prompt neben dem Identity-Prompt erzeugt und das fokussierte Artefakt-Audit mit der Suche nach hartcodierten Secrets in policy.xml beginnt und eine Behebung anbietet.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
azure, typescript
Bereich
backend-api-design, cli
Issue-Typ
Feature
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
55/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.