microsoft / microsoft/GitHub-Copilot-for-Azure

Replace azure-deploy skill Terraform variable resolution check with a script

Open
#2,519 1 comment 0 reactions 1 assignee Claimed by @tmeschter View on GitHub
azure-deploy skills
Dominant language
Python
Stars
250
Forks
204
Avg merge
1d 12h
Merged PRs (30d)
67

Description

## Summary

Copilot has identified a portion of a skill that is a good candidate for replacement with a script.

The candidate is the **Terraform Go-template variable resolution check** in the `azure-deploy` skill — a deterministic pre-deploy gate that greps the infra tree for unresolved `{{ .Env.* }}` Go-style templates and fails if any are found.

## Candidate description

Before a Terraform deployment, the skill runs a fixed detection gate over the infrastructure files:

1. `grep -rn '{{ .Env.' infra/ --include='*.tf'` — if any match, emit an error and `exit 1`.
2. `grep ... '{{ .Env.' infra/main.tfvars.json` — if any match, emit an error and `exit 1`.

This is a strong script candidate because it is:
- **A pure detection grep that returns a present/absent answer** — no placeholders, no branching beyond pass/fail, no judgment to run.
- **Deterministic and idempotent** — same inputs always yield the same gate result.
- **A cross-platform gap to close** — it currently ships **bash only** (no PowerShell variant), so extracting it to a referenced script is also the opportunity to add the missing PowerShell version the repo's authoring rules require.

**Sketch — `check-tf-template-vars.{sh,ps1}`:**
- **Input:** optional `--infra-dir` (default `infra/`).
- **Output:** a pass result, or a non-zero exit listing each `file:line` containing an unresolved `{{ .Env.VAR }}` template so the agent can point the user at exactly what to fix.

> The remediation (rewrite `{{ .Env.VAR }}` → `${VAR}`, choose `TF_VAR_*` for unmapped variables) edits infra files and stays in prose. The script only detects and reports.

## Affected file and lines

- [`references/pre-deploy-checklist.md` — Step 9 Terraform variable resolution check (L217–L231)](https://github.com/microsoft/GitHub-Copilot-for-Azure/blob/3890cbfb65c548ce8daa96cabd1d8de63f7bbcca/plugin/skills/azure-deploy/references/pre-deploy-checklist.md#L217-L231)

## Next steps

1. **Evaluate the candidate** — confirm the steps are stable and parameterizable, and that the script captures everything the skill needs.
2. **Create both a bash _and_ a PowerShell version** of the script so the skill works across platforms.
3. **Run integration tests** to verify the scripts behave correctly and the skill still completes end-to-end.

## Background Information

### Why replace regular steps with scripts

Replacing a regular, well-defined series of steps with a script can:

- **Reduce token usage** — the skill no longer needs to spell out each command and parse large command output inline; the agent invokes one script and reads a compact result.
- **Improve reliability** — the logic is written and tested once, instead of being re-derived by the agent on every run.
- **Improve determinism** — the same inputs always produce the same steps and output, removing run-to-run variation.
- **Improve speed of execution** — a single script call replaces multiple round-trips of command generation, execution, and large-output parsing.

### Authoring notes for the scripts

- **Reference scripts with markdown links**, not just a bare path to the script file.
- **Include examples** in the skill showing how to run each script (sample invocation with arguments).
- **Briefly explain what each script does** where it is referenced.
- **The script output should explain what it did**, so the agent and user can understand the result without re-inspecting raw command output.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.