Review Keamanan Bicep untuk Tim EC Kecil
Claude Code meninjau scope, secret, what-if, public access, dan rollback sebelum deploy Bicep.
Sebelum akhir pekan promo, tim ecommerce kecil tidak sebaiknya deploy file Bicep lama hanya karena tahun lalu berjalan. main.bicep bisa mengubah Storage, App Service, Key Vault, payment key, public access, dan SKU. Tanpa review scope, secret, dan what-if, masalah muncul saat traffic naik.
Key Points
- Cek scope, parameter, secret, public access, biaya, dan rollback.
- Bicep mudah dibaca, tetapi file pendek tetap bisa mengubah produksi.
- What-if membantu melihat perubahan sebelum deploy.
- Claude Code membuat tabel; manusia menyetujui.
- Ukur temuan what-if, secret polos, public settings, dan waktu review.
Workflow: Review Bicep Before Deploy
Mulai dari main.bicep, parameter, environment, resource group, what-if, dan rollback note. Hapus nilai secret sebelum Claude Code membaca file.
| Source | Review field | Human decision |
|---|---|---|
| Scope | resource group, subscription | production impact |
| Parameters | SKU, location, secret-like names | cost and payment safety |
| Resources | storage, web app, key vault | public access and customer impact |
| What-if | Create, Modify, Delete | deploy approval |
| Rollback | owner, stop note | sale-day response |
Primary sources checked: Bicep overview, file structure, best practices, what-if, secure parameters, modules, and Azure CLI deploy.
What Claude Code Does And What Humans Decide
Claude Code can list resources, parameters, modules, public settings, secret-like names, and what-if risks. Humans decide production deploy, deletion, SKU, payment keys, customer data, public URL, firewall, cost, and rollback.
3 Use Cases
Use case 1: Read scope before production
- Input: main.bicep, resource group, subscription, environment, existing resources.
- Output: create/modify/delete table, scope, resource type, business impact.
- Human review: production target, SKU, region, public URL, deletion, payment resources.
Use case 2: Find risky parameters
- Input: parameters, parameter file, Key Vault use, connection string names.
- Output: secure parameter candidates, plain secret candidates, Key Vault candidates.
- Human review: payment key, email key, database string, customer data, admin password.
Use case 3: Read what-if output
- Input: what-if output, deployment date, rollback note, owner.
- Output: Create/Modify/Delete table, stop condition, approver.
- Human review: Delete, Replace, SKU, public access, cost, sale impact.
Copy-Paste Prompt
Act as an Azure Bicep safety reviewer for a small ecommerce team.
Turn Bicep files into a human deployment review table.
Check targetScope, secret-like parameters, public access, HTTPS, managed identity, what-if Delete/Replace/SKU changes, and rollback notes.
Never run deployment commands.
Return the five rows to inspect today.
Working Check Code
// verify-bicep-safety-notes.mjs
// No dependencies. Run with: node verify-bicep-safety-notes.mjs
const bicepReview = {
template: "main.bicep",
environment: "prod",
scope: "subscription",
resources: [
{ type: "Microsoft.Storage/storageAccounts", name: "ecprodstore", publicNetworkAccess: "Enabled", sku: "Standard_LRS" },
{ type: "Microsoft.Web/sites", name: "ec-sale-app", httpsOnly: false, managedIdentity: false },
{ type: "Microsoft.KeyVault/vaults/secrets", name: "payment-api-key", valueFromParameter: "plainTextPaymentKey" }
],
parameters: [
{ name: "location", secure: false, valueExample: "japaneast" },
{ name: "plainTextPaymentKey", secure: false, valueExample: "sk_live_example" }
],
whatIfAttached: false,
owner: "",
rollbackNote: ""
};
const problems = [];
if (bicepReview.environment === "prod" && !bicepReview.whatIfAttached) {
problems.push({ item: "what-if", fix: "attach az deployment what-if output before production deployment" });
}
if (!bicepReview.owner) {
problems.push({ item: "owner", fix: "assign a human owner for cost, rollback, and approval" });
}
if (!bicepReview.rollbackNote) {
problems.push({ item: "rollback", fix: "write a rollback or stop-the-line note before sale season" });
}
for (const parameter of bicepReview.parameters) {
if (/key|secret|password|token/i.test(parameter.name) && !parameter.secure) {
problems.push({ item: `parameter: ${parameter.name}`, fix: "mark secrets with @secure() or fetch from Key Vault" });
}
}
for (const resource of bicepReview.resources) {
if (resource.publicNetworkAccess === "Enabled") {
problems.push({ item: `public network: ${resource.name}`, fix: "review public access, firewall, private endpoint, or business reason" });
}
if (resource.httpsOnly === false) {
problems.push({ item: `httpsOnly: ${resource.name}`, fix: "enable HTTPS-only before customer traffic" });
}
if (resource.type === "Microsoft.Web/sites" && resource.managedIdentity === false) {
problems.push({ item: `identity: ${resource.name}`, fix: "use managed identity instead of app secrets when possible" });
}
}
if (problems.length > 0) {
console.table(problems);
process.exitCode = 1;
} else {
console.log("Bicep safety review passed.");
}
Pitfall: Common Failure Cases
Readable Bicep is not automatically safe. Review scope, what-if, secrets, public settings, and rollback. Do not place secrets in plain parameters. Do not run what-if and ignore Delete, Replace, SKU, public access, identity, or diagnostics. Do not deploy before sale season without an owner and rollback note.
FAQ
Q. Does a small EC team need Bicep?
A. Start only where changes repeat: sale pages, image delivery, admin apps, and staging environments.
Q. Can Claude Code read Bicep?
A. Yes, after removing secrets, tokens, customer data, and contract details.
Q. Is what-if enough?
A. No. Humans still approve deletion, replacement, SKU, public access, secrets, and rollback.
Q. What should the team inspect today?
A. targetScope, secret-like parameters, public access, what-if Delete/Modify, and rollback note.
Training And Consultation Signal
Measure what-if items stopped, plain secret candidates, public-setting findings, missing rollback notes, review time, and inquiry rate. If those numbers hurt, Bicep and Azure deployment review are a fit for pelatihan ClaudeCodeLab.
What I Verified
I checked Microsoft Learn references for Bicep overview, file structure, best practices, what-if, secure parameters, modules, and Azure CLI deployment. I also checked the CTA, executable JavaScript, internal link, external links, locale coverage, and queue removal.
Artikel terkait
Permission safety ladder Claude Code: perluas akses tanpa kehilangan kontrol
Naik dari read-only ke edit terbatas, command bukti, dan cek deploy dengan kontrol yang jelas.
Checklist Code Review Claude Code untuk Tim
Checklist review kode Claude Code untuk tim: risiko, keamanan, test, PR template, dan CI guard.
Cek Azure Container Apps untuk Situs Rekrutmen
Claude Code mengecek public URL, variabel, form, secret, dan revision sebelum launch.
PDF gratis: cheatsheet Claude Code
Masukkan email dan unduh satu halaman berisi command, kebiasaan review, dan workflow aman.
Kami menjaga datamu dan tidak mengirim spam.
Tentang penulis
Masa
Engineer yang berfokus pada workflow Claude Code praktis dan adopsi tim.