Skip to content

chore: exclude legacy infra/old/ from PSRule validation#2

Draft
Copilot wants to merge 7 commits intomainfrom
copilot/add-ps-rule-exclusion-for-legacy-files
Draft

chore: exclude legacy infra/old/ from PSRule validation#2
Copilot wants to merge 7 commits intomainfrom
copilot/add-ps-rule-exclusion-for-legacy-files

Conversation

Copy link
Copy Markdown

Copilot AI commented Mar 30, 2026

PSRule was scanning legacy Bicep files under infra/old/ during AZD Template Validation, causing CI failures due to unresolvable compilation errors (BCP091, BCP062, BCP029, BCP134) from moved/deleted file references and invalid declarations.

Changes

  • .ps-rule/ps-rule.yaml (new file): Creates PSRule configuration excluding infra/old/** from input path scanning
input:
  pathIgnore:
    - 'infra/old/**'
Original prompt

The AZD Template Validation workflow is failing (see failing job) due to Bicep compilation errors in legacy files under infra/old/.

Errors

PSRule is picking up old/legacy Bicep files under infra/old/00-older/ and infra/old/08-2025/ that have multiple compilation errors:

  • BCP091: Missing file references (files moved or deleted)
  • BCP062: Invalid referenced declarations (aiFoundryAiHub, containerAppEnvironment, entraIdApplication)
  • BCP029: Invalid resource types
  • BCP134: Scope subscription is not valid for the module
  • BCP035/BCP104: Missing required properties / module has errors

Solution

Create a new file .ps-rule/ps-rule.yaml (the .ps-rule/ directory does not currently exist in the repo) with the following content to exclude the legacy infra/old/ directory from PSRule validation:

# PSRule configuration
# See https://aka.ms/ps-rule/options for more information.

input:
  pathIgnore:
    - 'infra/old/**'

This will tell PSRule to skip all files under infra/old/ during Bicep compilation and rule evaluation, eliminating the legacy Bicep errors.

The following is the prior conversation context from the user's chat exploration (may be truncated):

User: Please find a solution for this failing job. Use the logs, job definition, and any referenced files where the failure occurred. Keep your response focused on the solution and include code suggestions when appropriate.

Assistant:

I'll start by fetching the job logs and the workflow definition to understand the failure.

Assistant: Let me examine the workflow file and the relevant Bicep files to understand the full picture.

Assistant:

Failing Job Analysis: AZD Template Validation

The job has three distinct failures. Here's a breakdown and solution for each:


1. Bicep Compilation Errors in infra/old/ Directory

The PSRule validation is picking up old/legacy Bicep files under infra/old/00-older/ and infra/old/08-2025/ that have multiple issues:

  • BCP091: Missing file references (files moved or deleted)
  • BCP062: Invalid referenced declarations (aiFoundryAiHub, containerAppEnvironment, entraIdApplication)
  • BCP029: Invalid resource types
  • BCP134: Scope subscription is not valid for the module
  • BCP035/BCP104: Missing required properties / module has errors

Solution: Exclude the infra/old/ directory from validation. You can do this by adding a .ps-rule/ps-rule.yaml configuration file (or updating it if it exists) to exclude those paths:

# .ps-rule/ps-rule.yaml
input:
  pathIgnore:
    - 'infra/old/**'

Alternatively, if these old Bicep files are no longer needed, delete the infra/old/ directory entirely.


2. PSRule Failure: Azure.AppService.ManagedIdentity (AZR-000082)

The resource app-macaeebfc4 (a Microsoft.Web/sites resource) is failing because it does not have a managed identity configured.

Solution: In your main Bicep template where the App Service is defined, add the identity property to enable a system-assigned managed identity:

resource appService 'Microsoft.Web/sites@2022-09-01' = {
  name: appServiceName
  location: location
  identity: {
    type: 'SystemAssigned'
  }
  properties: {
    // ... existing properties
  }
}

If you're already using a user-assigned managed identity, make sure it's being passed correctly in the test Bicep file. If this rule should be suppressed for the test environment, you can add a suppression in .ps-rule/ps-rule.yaml:

suppression:
  Azure.AppService.ManagedIdentity:
    - app-macaeebfc4

3. Shell Script Syntax Error in Post-Validation Step

The log shows:

conditional binary operator expected
Process completed with exit code 2

This occurs in a step that runs if [ -f "./infra/main.bicep" ]; then. The error suggests a quoting or syntax issue in how the shell command is being constructed. This is likely coming from the microsoft/template-validation-action@v0.4.3 itself, and may be triggered by an environment variable containing special characters or being empty.

This is a secondary failure (runs after the primary PSRule failure), so fixing issues #1 and #2 above should be the priority.


Recommended Fix (Priority Order)

  1. Exclude or remove infra/old/ — This eliminates all the legacy Bicep compilation errors.
  2. Add managed identity to the App Service in your Bicep template — This fixes the only PSRule rule failure (AZR-000082), which is the primary blocker causing the job to exit with code 1.

After these two changes, the validation should pass with 88/88 rules succeeding.

User: give full filewith for pathIgnore:
- 'infra/old/**'

Assistant:

Let me check if a .ps-rule/ps-rule.yaml file already exists in the repository.

Assistant: The `.p...

This pull request was created from Copilot chat.

Pavan-Microsoft and others added 6 commits March 30, 2026 16:09
Updated the workflow to deploy Azure resources instead of validating templates. Added steps for Azure login and provisioning.
Updated the Azure workflow for deployment, replacing template validation with deployment steps and adding Azure login and provisioning commands.
…tion

chore: Update Azure workflow for deployment and add template validation
Copilot AI changed the title [WIP] Add PSRule exclusion for legacy Bicep files chore: exclude legacy infra/old/ from PSRule validation Mar 30, 2026
Copilot AI requested a review from Pavan-Microsoft March 30, 2026 11:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants