microsoft / microsoft/GitHub-Copilot-for-Azure

Replace microsoft-foundry skill post-deployment infrastructure verification with a script

Open
#2,538 1 comment 0 reactions 1 assignee Claimed by @tmeschter View on GitHub
microsoft-foundry skills untriaged
Dominant language
Python
Stars
250
Forks
204
Avg merge
1d 12h
Merged PRs (30d)
67

Description

## Summary

Copilot has identified a portion of a skill that is a good candidate for replacement with a script.

The candidate is the **post-deployment infrastructure verification** in the `microsoft-foundry` skill (`resource/private-network/references/post-deployment-validation.md`) — three back-to-back `az` queries reduced to a single pass/fail roll-up.

## Candidate description

After a private-network deployment, the skill runs three deterministic verification queries:

1. Resource state — every resource `provisioningState == Succeeded`.
2. Private-endpoint connections — every connection `Approved`.
3. Public-access audit — four resource types' `publicNetworkAccess` all `Disabled`.

This is a strong script candidate because it is:
- **Output-heavy / few-fields-matter** — three large tables reduced to a single pass/fail answer instead of three outputs the agent must eyeball.
- **A literal repeated sub-sequence** — the four `publicNetworkAccess` checks are the same query across four resource types, ideal for a loop.
- **Duplicated** — the resource-state query (`az deployment operation group list ... targetResource.resourceType,provisioningState`) is identical to `deploy.md` L34–L38.

**Sketch — `verify-private-deployment.{sh,ps1}`:**
- **Input:** `--resource-group`, the resource names/types to audit.
- **Output:** a single roll-up — all resources Succeeded? all PE connections Approved? all public access Disabled? — with the specific failures listed if any.

> The T10 special-case note (Steps 2–5 don't apply) stays in prose. Verification itself needs no judgment.

**Note — shared helper:** The `az deployment operation group list` resource-state projection appears here and in `deploy.md` (×2); consolidating into a shared "deployment status" helper removes triplicated logic.

## Affected file and lines

- [`resource/private-network/references/post-deployment-validation.md` — state + PE-approval + public-access audit (L11–L45)](https://github.com/microsoft/GitHub-Copilot-for-Azure/blob/3890cbfb65c548ce8daa96cabd1d8de63f7bbcca/plugin/skills/microsoft-foundry/resource/private-network/references/post-deployment-validation.md#L11-L45)
- [`resource/private-network/references/deploy.md` — identical resource-state query (L34–L38)](https://github.com/microsoft/GitHub-Copilot-for-Azure/blob/3890cbfb65c548ce8daa96cabd1d8de63f7bbcca/plugin/skills/microsoft-foundry/resource/private-network/references/deploy.md#L34-L38)

## Next steps

1. **Evaluate the candidate** — confirm the steps are stable and parameterizable, and that the script captures everything the skill needs.
2. **Create both a bash _and_ a PowerShell version** of the script so the skill works across platforms.
3. **Run integration tests** to verify the scripts behave correctly and the skill still completes end-to-end.

## Background Information

### Why replace regular steps with scripts

Replacing a regular, well-defined series of steps with a script can:

- **Reduce token usage** — the skill no longer needs to spell out each command and parse large command output inline; the agent invokes one script and reads a compact result.
- **Improve reliability** — the logic is written and tested once, instead of being re-derived by the agent on every run.
- **Improve determinism** — the same inputs always produce the same steps and output, removing run-to-run variation.
- **Improve speed of execution** — a single script call replaces multiple round-trips of command generation, execution, and large-output parsing.

### Authoring notes for the scripts

- **Reference scripts with markdown links**, not just a bare path to the script file.
- **Include examples** in the skill showing how to run each script (sample invocation with arguments).
- **Briefly explain what each script does** where it is referenced.
- **The script output should explain what it did**, so the agent and user can understand the result without re-inspecting raw command output.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.