Advanced (Diperbarui: 19/7/2026)

Review Keamanan Bicep untuk Tim EC Kecil

Claude Code meninjau scope, secret, what-if, public access, dan rollback sebelum deploy Bicep.

Review Keamanan Bicep untuk Tim EC Kecil

Sebelum akhir pekan promo, tim ecommerce kecil tidak sebaiknya deploy file Bicep lama hanya karena tahun lalu berjalan. main.bicep bisa mengubah Storage, App Service, Key Vault, payment key, public access, dan SKU. Tanpa review scope, secret, dan what-if, masalah muncul saat traffic naik.

Key Points

  • Cek scope, parameter, secret, public access, biaya, dan rollback.
  • Bicep mudah dibaca, tetapi file pendek tetap bisa mengubah produksi.
  • What-if membantu melihat perubahan sebelum deploy.
  • Claude Code membuat tabel; manusia menyetujui.
  • Ukur temuan what-if, secret polos, public settings, dan waktu review.

Workflow: Review Bicep Before Deploy

Mulai dari main.bicep, parameter, environment, resource group, what-if, dan rollback note. Hapus nilai secret sebelum Claude Code membaca file.

SourceReview fieldHuman decision
Scoperesource group, subscriptionproduction impact
ParametersSKU, location, secret-like namescost and payment safety
Resourcesstorage, web app, key vaultpublic access and customer impact
What-ifCreate, Modify, Deletedeploy approval
Rollbackowner, stop notesale-day response

Primary sources checked: Bicep overview, file structure, best practices, what-if, secure parameters, modules, and Azure CLI deploy.

What Claude Code Does And What Humans Decide

Claude Code can list resources, parameters, modules, public settings, secret-like names, and what-if risks. Humans decide production deploy, deletion, SKU, payment keys, customer data, public URL, firewall, cost, and rollback.

3 Use Cases

Use case 1: Read scope before production

  • Input: main.bicep, resource group, subscription, environment, existing resources.
  • Output: create/modify/delete table, scope, resource type, business impact.
  • Human review: production target, SKU, region, public URL, deletion, payment resources.

Use case 2: Find risky parameters

  • Input: parameters, parameter file, Key Vault use, connection string names.
  • Output: secure parameter candidates, plain secret candidates, Key Vault candidates.
  • Human review: payment key, email key, database string, customer data, admin password.

Use case 3: Read what-if output

  • Input: what-if output, deployment date, rollback note, owner.
  • Output: Create/Modify/Delete table, stop condition, approver.
  • Human review: Delete, Replace, SKU, public access, cost, sale impact.

Copy-Paste Prompt

Act as an Azure Bicep safety reviewer for a small ecommerce team.
Turn Bicep files into a human deployment review table.
Check targetScope, secret-like parameters, public access, HTTPS, managed identity, what-if Delete/Replace/SKU changes, and rollback notes.
Never run deployment commands.
Return the five rows to inspect today.

Working Check Code

// verify-bicep-safety-notes.mjs
// No dependencies. Run with: node verify-bicep-safety-notes.mjs
const bicepReview = {
  template: "main.bicep",
  environment: "prod",
  scope: "subscription",
  resources: [
    { type: "Microsoft.Storage/storageAccounts", name: "ecprodstore", publicNetworkAccess: "Enabled", sku: "Standard_LRS" },
    { type: "Microsoft.Web/sites", name: "ec-sale-app", httpsOnly: false, managedIdentity: false },
    { type: "Microsoft.KeyVault/vaults/secrets", name: "payment-api-key", valueFromParameter: "plainTextPaymentKey" }
  ],
  parameters: [
    { name: "location", secure: false, valueExample: "japaneast" },
    { name: "plainTextPaymentKey", secure: false, valueExample: "sk_live_example" }
  ],
  whatIfAttached: false,
  owner: "",
  rollbackNote: ""
};

const problems = [];

if (bicepReview.environment === "prod" && !bicepReview.whatIfAttached) {
  problems.push({ item: "what-if", fix: "attach az deployment what-if output before production deployment" });
}
if (!bicepReview.owner) {
  problems.push({ item: "owner", fix: "assign a human owner for cost, rollback, and approval" });
}
if (!bicepReview.rollbackNote) {
  problems.push({ item: "rollback", fix: "write a rollback or stop-the-line note before sale season" });
}
for (const parameter of bicepReview.parameters) {
  if (/key|secret|password|token/i.test(parameter.name) && !parameter.secure) {
    problems.push({ item: `parameter: ${parameter.name}`, fix: "mark secrets with @secure() or fetch from Key Vault" });
  }
}
for (const resource of bicepReview.resources) {
  if (resource.publicNetworkAccess === "Enabled") {
    problems.push({ item: `public network: ${resource.name}`, fix: "review public access, firewall, private endpoint, or business reason" });
  }
  if (resource.httpsOnly === false) {
    problems.push({ item: `httpsOnly: ${resource.name}`, fix: "enable HTTPS-only before customer traffic" });
  }
  if (resource.type === "Microsoft.Web/sites" && resource.managedIdentity === false) {
    problems.push({ item: `identity: ${resource.name}`, fix: "use managed identity instead of app secrets when possible" });
  }
}

if (problems.length > 0) {
  console.table(problems);
  process.exitCode = 1;
} else {
  console.log("Bicep safety review passed.");
}

Pitfall: Common Failure Cases

Readable Bicep is not automatically safe. Review scope, what-if, secrets, public settings, and rollback. Do not place secrets in plain parameters. Do not run what-if and ignore Delete, Replace, SKU, public access, identity, or diagnostics. Do not deploy before sale season without an owner and rollback note.

FAQ

Q. Does a small EC team need Bicep?

A. Start only where changes repeat: sale pages, image delivery, admin apps, and staging environments.

Q. Can Claude Code read Bicep?

A. Yes, after removing secrets, tokens, customer data, and contract details.

Q. Is what-if enough?

A. No. Humans still approve deletion, replacement, SKU, public access, secrets, and rollback.

Q. What should the team inspect today?

A. targetScope, secret-like parameters, public access, what-if Delete/Modify, and rollback note.

Training And Consultation Signal

Measure what-if items stopped, plain secret candidates, public-setting findings, missing rollback notes, review time, and inquiry rate. If those numbers hurt, Bicep and Azure deployment review are a fit for pelatihan ClaudeCodeLab.

What I Verified

I checked Microsoft Learn references for Bicep overview, file structure, best practices, what-if, secure parameters, modules, and Azure CLI deployment. I also checked the CTA, executable JavaScript, internal link, external links, locale coverage, and queue removal.

#claude-code #ecommerce #azure-bicep #iac #security
Gratis

PDF gratis: cheatsheet Claude Code

Masukkan email dan unduh satu halaman berisi command, kebiasaan review, dan workflow aman.

Kami menjaga datamu dan tidak mengirim spam.

Masa

Tentang penulis

Masa

Engineer yang berfokus pada workflow Claude Code praktis dan adopsi tim.