Advanced (Atualizado: 19/07/2026)

Revisão segura de Bicep para pequenas equipes de EC

Claude Code revisa scope, segredos, what-if, acesso público e rollback antes do Bicep.

Revisão segura de Bicep para pequenas equipes de EC

Antes de um fim de semana de promoções, uma equipe pequena de ecommerce não deve publicar um Bicep antigo só porque funcionou no ano passado. main.bicep pode tocar Storage, App Service, Key Vault, chaves de pagamento, acesso público e SKU. Sem revisar scope, segredos e what-if, o erro aparece quando o tráfego sobe.

Key Points

  • Revise scope, parâmetros, segredos, acesso público, custo e rollback.
  • Bicep é legível, mas um arquivo curto pode alterar produção.
  • What-if ajuda a prever mudanças antes do deploy.
  • Claude Code prepara a tabela; pessoas aprovam.
  • Meça itens barrados, secrets em claro, public settings e tempo de revisão.

Workflow: Review Bicep Before Deploy

Comece com main.bicep, parameters, ambiente, resource group, what-if e rollback note. Remova valores secretos antes de usar Claude Code.

SourceReview fieldHuman decision
Scoperesource group, subscriptionproduction impact
ParametersSKU, location, secret-like namescost and payment safety
Resourcesstorage, web app, key vaultpublic access and customer impact
What-ifCreate, Modify, Deletedeploy approval
Rollbackowner, stop notesale-day response

Primary sources checked: Bicep overview, file structure, best practices, what-if, secure parameters, modules, and Azure CLI deploy.

What Claude Code Does And What Humans Decide

Claude Code can list resources, parameters, modules, public settings, secret-like names, and what-if risks. Humans decide production deploy, deletion, SKU, payment keys, customer data, public URL, firewall, cost, and rollback.

3 Use Cases

Use case 1: Read scope before production

  • Input: main.bicep, resource group, subscription, environment, existing resources.
  • Output: create/modify/delete table, scope, resource type, business impact.
  • Human review: production target, SKU, region, public URL, deletion, payment resources.

Use case 2: Find risky parameters

  • Input: parameters, parameter file, Key Vault use, connection string names.
  • Output: secure parameter candidates, plain secret candidates, Key Vault candidates.
  • Human review: payment key, email key, database string, customer data, admin password.

Use case 3: Read what-if output

  • Input: what-if output, deployment date, rollback note, owner.
  • Output: Create/Modify/Delete table, stop condition, approver.
  • Human review: Delete, Replace, SKU, public access, cost, sale impact.

Copy-Paste Prompt

Act as an Azure Bicep safety reviewer for a small ecommerce team.
Turn Bicep files into a human deployment review table.
Check targetScope, secret-like parameters, public access, HTTPS, managed identity, what-if Delete/Replace/SKU changes, and rollback notes.
Never run deployment commands.
Return the five rows to inspect today.

Working Check Code

// verify-bicep-safety-notes.mjs
// No dependencies. Run with: node verify-bicep-safety-notes.mjs
const bicepReview = {
  template: "main.bicep",
  environment: "prod",
  scope: "subscription",
  resources: [
    { type: "Microsoft.Storage/storageAccounts", name: "ecprodstore", publicNetworkAccess: "Enabled", sku: "Standard_LRS" },
    { type: "Microsoft.Web/sites", name: "ec-sale-app", httpsOnly: false, managedIdentity: false },
    { type: "Microsoft.KeyVault/vaults/secrets", name: "payment-api-key", valueFromParameter: "plainTextPaymentKey" }
  ],
  parameters: [
    { name: "location", secure: false, valueExample: "japaneast" },
    { name: "plainTextPaymentKey", secure: false, valueExample: "sk_live_example" }
  ],
  whatIfAttached: false,
  owner: "",
  rollbackNote: ""
};

const problems = [];

if (bicepReview.environment === "prod" && !bicepReview.whatIfAttached) {
  problems.push({ item: "what-if", fix: "attach az deployment what-if output before production deployment" });
}
if (!bicepReview.owner) {
  problems.push({ item: "owner", fix: "assign a human owner for cost, rollback, and approval" });
}
if (!bicepReview.rollbackNote) {
  problems.push({ item: "rollback", fix: "write a rollback or stop-the-line note before sale season" });
}
for (const parameter of bicepReview.parameters) {
  if (/key|secret|password|token/i.test(parameter.name) && !parameter.secure) {
    problems.push({ item: `parameter: ${parameter.name}`, fix: "mark secrets with @secure() or fetch from Key Vault" });
  }
}
for (const resource of bicepReview.resources) {
  if (resource.publicNetworkAccess === "Enabled") {
    problems.push({ item: `public network: ${resource.name}`, fix: "review public access, firewall, private endpoint, or business reason" });
  }
  if (resource.httpsOnly === false) {
    problems.push({ item: `httpsOnly: ${resource.name}`, fix: "enable HTTPS-only before customer traffic" });
  }
  if (resource.type === "Microsoft.Web/sites" && resource.managedIdentity === false) {
    problems.push({ item: `identity: ${resource.name}`, fix: "use managed identity instead of app secrets when possible" });
  }
}

if (problems.length > 0) {
  console.table(problems);
  process.exitCode = 1;
} else {
  console.log("Bicep safety review passed.");
}

Pitfall: Common Failure Cases

Readable Bicep is not automatically safe. Review scope, what-if, secrets, public settings, and rollback. Do not place secrets in plain parameters. Do not run what-if and ignore Delete, Replace, SKU, public access, identity, or diagnostics. Do not deploy before sale season without an owner and rollback note.

FAQ

Q. Does a small EC team need Bicep?

A. Start only where changes repeat: sale pages, image delivery, admin apps, and staging environments.

Q. Can Claude Code read Bicep?

A. Yes, after removing secrets, tokens, customer data, and contract details.

Q. Is what-if enough?

A. No. Humans still approve deletion, replacement, SKU, public access, secrets, and rollback.

Q. What should the team inspect today?

A. targetScope, secret-like parameters, public access, what-if Delete/Modify, and rollback note.

Training And Consultation Signal

Measure what-if items stopped, plain secret candidates, public-setting findings, missing rollback notes, review time, and inquiry rate. If those numbers hurt, Bicep and Azure deployment review are a fit for treinamento ClaudeCodeLab.

What I Verified

I checked Microsoft Learn references for Bicep overview, file structure, best practices, what-if, secure parameters, modules, and Azure CLI deployment. I also checked the CTA, executable JavaScript, internal link, external links, locale coverage, and queue removal.

#claude-code #ecommerce #azure-bicep #iac #seguranca
Grátis

PDF grátis: cheatsheet do Claude Code

Informe seu e-mail e baixe uma página com comandos, hábitos de revisão e workflows seguros.

Cuidamos dos seus dados e não enviamos spam.

Masa

Sobre o autor

Masa

Engenheiro focado em workflows práticos com Claude Code.