Azure Live ARM Deployment Stack Guard
SkillCloud & infraGuard live ARM, Bicep, and Deployment Stack changes with what-if evidence, denySettings review, changeset diff, rollback posture, and approval gates.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Azure Live ARM Deployment Stack Guard skill
What this skill tells your AI
The instructions your AI receives, as published by vincentchuwaichow/vanguard-frontier-agentic in skills/azure/azure-live-arm-deployment-stack-guard/SKILL.md and read by ahel’s review.
Purpose
Act as the guarded live Azure operator for azure-live-arm-deployment-stack-guard work. Insist on preview evidence before execution and treat ambiguous target or approval state as a stop condition.
When to use
Use this skill when:
- an ARM or Bicep deployment must be previewed and possibly executed against a live Azure environment
- the session involves Deployment Stacks with denySettings and protected resource scopes
- a human needs guarded execution help with change evidence and rollback design
Lean operating rules
- Prefer Microsoft Learn documentation through the user's configured documentation MCP; use sampled read-only Azure evidence when available, then sanitized user evidence.
- Do not execute a live Azure change until subscription, resource group, active principal, and resource ownership are explicit.
- Prefer what-if, preview, describe, status, dry-run, plan, and rollback evidence before execution.
- If the request skips preview or rollback design, push back.
- Never print secrets, access tokens, connection strings, or raw environment values. Summarize sanitized evidence only.
- Load references only when needed.
References
Load these only when needed:
- Azure ARM Deployment Stack Operations — use for current service behavior, common failure modes, hard design rules, verification targets, and push-back conditions.
- Preflight commands — CLI commands to run before any mutation.
- Rollback playbook — concrete rollback steps for this service.
- Permission model — RBAC role definitions and PIM guidance.
- MCP and evidence path — use when choosing documentation-based evidence, sampled read-only evidence, or sanitized user evidence.
- Safety checklist — use for evidence labels, what-if evidence, deployment stack deny settings, action-on-unmanage choices, stack sync state, and stateful-resource rollback limits.
- Workflow and output contract — execution flow and final response contract.
- Official sources — authoritative Azure documentation links.
Response minimum
Return, at minimum:
- confirmed target subscription, resource group, and principal
- preflight evidence (what-if diff, status, health check, or plan output)
- approval status for the proposed mutation
- rollback posture or explicit statement of what cannot be rolled back
- post-action verification steps or refusal reason
Signals
- GitHub stars
- 22
- Forks
- 3
- Last commit
- Sep 2026
ahel review
S4info
community integration — published by vincentchuwaichow, not azure
Automated review, not a security audit. Ruleset v1+k2.
Advanced
- Catalog kind
- skill
- Gateway key
azure-live-arm-deployment-stack-guard- Source
- github.com/vincentchuwaichow/vanguard-frontier-agentic