Advanced (Aktualisiert: 19.7.2026)

Bicep Sicherheitsreview fuer kleine EC Teams

Claude Code prueft Scope, Secrets, What-if, Public Access und Rollback vor Azure Bicep.

Bicep Sicherheitsreview fuer kleine EC Teams

Vor einem Sale-Wochenende sollte ein kleines E-Commerce-Team keine alte Bicep-Datei nach Produktion deployen, nur weil sie letztes Jahr funktioniert hat. main.bicep kann Storage, App Service, Key Vault, Payment Keys, Public Access und SKU veraendern. Ohne Review von Scope, Secrets und What-if kommt der Fehler genau bei hohem Traffic.

Key Points

  • Pruefe Scope, Parameter, Secrets, Public Access, Kosten und Rollback.
  • Bicep ist lesbar, aber kurze Dateien koennen Produktion aendern.
  • What-if zeigt erwartete Aenderungen vor dem Deployment.
  • Claude Code erstellt die Tabelle; Menschen genehmigen.
  • Messe gestoppte What-if Punkte, Plain Secrets, Public Settings und Review-Zeit.

Workflow: Review Bicep Before Deploy

Starte mit main.bicep, Parametern, Environment, Resource Group, What-if und Rollback Note. Entferne Secret-Werte vor Claude Code.

SourceReview fieldHuman decision
Scoperesource group, subscriptionproduction impact
ParametersSKU, location, secret-like namescost and payment safety
Resourcesstorage, web app, key vaultpublic access and customer impact
What-ifCreate, Modify, Deletedeploy approval
Rollbackowner, stop notesale-day response

Primary sources checked: Bicep overview, file structure, best practices, what-if, secure parameters, modules, and Azure CLI deploy.

What Claude Code Does And What Humans Decide

Claude Code can list resources, parameters, modules, public settings, secret-like names, and what-if risks. Humans decide production deploy, deletion, SKU, payment keys, customer data, public URL, firewall, cost, and rollback.

3 Use Cases

Use case 1: Read scope before production

  • Input: main.bicep, resource group, subscription, environment, existing resources.
  • Output: create/modify/delete table, scope, resource type, business impact.
  • Human review: production target, SKU, region, public URL, deletion, payment resources.

Use case 2: Find risky parameters

  • Input: parameters, parameter file, Key Vault use, connection string names.
  • Output: secure parameter candidates, plain secret candidates, Key Vault candidates.
  • Human review: payment key, email key, database string, customer data, admin password.

Use case 3: Read what-if output

  • Input: what-if output, deployment date, rollback note, owner.
  • Output: Create/Modify/Delete table, stop condition, approver.
  • Human review: Delete, Replace, SKU, public access, cost, sale impact.

Copy-Paste Prompt

Act as an Azure Bicep safety reviewer for a small ecommerce team.
Turn Bicep files into a human deployment review table.
Check targetScope, secret-like parameters, public access, HTTPS, managed identity, what-if Delete/Replace/SKU changes, and rollback notes.
Never run deployment commands.
Return the five rows to inspect today.

Working Check Code

// verify-bicep-safety-notes.mjs
// No dependencies. Run with: node verify-bicep-safety-notes.mjs
const bicepReview = {
  template: "main.bicep",
  environment: "prod",
  scope: "subscription",
  resources: [
    { type: "Microsoft.Storage/storageAccounts", name: "ecprodstore", publicNetworkAccess: "Enabled", sku: "Standard_LRS" },
    { type: "Microsoft.Web/sites", name: "ec-sale-app", httpsOnly: false, managedIdentity: false },
    { type: "Microsoft.KeyVault/vaults/secrets", name: "payment-api-key", valueFromParameter: "plainTextPaymentKey" }
  ],
  parameters: [
    { name: "location", secure: false, valueExample: "japaneast" },
    { name: "plainTextPaymentKey", secure: false, valueExample: "sk_live_example" }
  ],
  whatIfAttached: false,
  owner: "",
  rollbackNote: ""
};

const problems = [];

if (bicepReview.environment === "prod" && !bicepReview.whatIfAttached) {
  problems.push({ item: "what-if", fix: "attach az deployment what-if output before production deployment" });
}
if (!bicepReview.owner) {
  problems.push({ item: "owner", fix: "assign a human owner for cost, rollback, and approval" });
}
if (!bicepReview.rollbackNote) {
  problems.push({ item: "rollback", fix: "write a rollback or stop-the-line note before sale season" });
}
for (const parameter of bicepReview.parameters) {
  if (/key|secret|password|token/i.test(parameter.name) && !parameter.secure) {
    problems.push({ item: `parameter: ${parameter.name}`, fix: "mark secrets with @secure() or fetch from Key Vault" });
  }
}
for (const resource of bicepReview.resources) {
  if (resource.publicNetworkAccess === "Enabled") {
    problems.push({ item: `public network: ${resource.name}`, fix: "review public access, firewall, private endpoint, or business reason" });
  }
  if (resource.httpsOnly === false) {
    problems.push({ item: `httpsOnly: ${resource.name}`, fix: "enable HTTPS-only before customer traffic" });
  }
  if (resource.type === "Microsoft.Web/sites" && resource.managedIdentity === false) {
    problems.push({ item: `identity: ${resource.name}`, fix: "use managed identity instead of app secrets when possible" });
  }
}

if (problems.length > 0) {
  console.table(problems);
  process.exitCode = 1;
} else {
  console.log("Bicep safety review passed.");
}

Pitfall: Common Failure Cases

Readable Bicep is not automatically safe. Review scope, what-if, secrets, public settings, and rollback. Do not place secrets in plain parameters. Do not run what-if and ignore Delete, Replace, SKU, public access, identity, or diagnostics. Do not deploy before sale season without an owner and rollback note.

FAQ

Q. Does a small EC team need Bicep?

A. Start only where changes repeat: sale pages, image delivery, admin apps, and staging environments.

Q. Can Claude Code read Bicep?

A. Yes, after removing secrets, tokens, customer data, and contract details.

Q. Is what-if enough?

A. No. Humans still approve deletion, replacement, SKU, public access, secrets, and rollback.

Q. What should the team inspect today?

A. targetScope, secret-like parameters, public access, what-if Delete/Modify, and rollback note.

Training And Consultation Signal

Measure what-if items stopped, plain secret candidates, public-setting findings, missing rollback notes, review time, and inquiry rate. If those numbers hurt, Bicep and Azure deployment review are a fit for ClaudeCodeLab Training.

What I Verified

I checked Microsoft Learn references for Bicep overview, file structure, best practices, what-if, secure parameters, modules, and Azure CLI deployment. I also checked the CTA, executable JavaScript, internal link, external links, locale coverage, and queue removal.

#claude-code #ecommerce #azure-bicep #iac #sicherheit
Kostenlos

Kostenloses PDF: Claude-Code-Cheatsheet

E-Mail eintragen und eine Seite mit Befehlen, Review-Gewohnheiten und sicheren Workflows herunterladen.

Wir schützen Ihre Daten und senden keinen Spam.

Masa

Über den Autor

Masa

Engineer für praktische Claude-Code-Workflows und Team-Einführung.