apiops init: generate a Copilot prompt file to audit artifacts against APIM best practices
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
- Issue type
- Feature
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- azure, typescript
- Domain
- backend-api-design, cli
Research direction
Start with src/templates/copilot/identity-setup-prompt.ts and src/services/init-service.ts to follow the existing prompt-generation pattern. Then inspect src/commands/init-command.ts for the next-steps output and generatedFiles.configs handling. Done means apiops init generates the new prompt alongside the identity prompt, with the focused artifact audit starting with hardcoded secrets in policy.xml and offering remediation.
Written by the indexing model from the issue text.
Description
Problem or use case
After apiops extract, users have no guided way to check their extracted APIM artifacts against APIM best practices. The audit should look for anti-patterns (e.g. named values holding secrets that aren''t marked secret) that otherwise go unnoticed. We want a low-friction, Copilot-assisted audit that also offers to fix the issues it finds.
Proposed solution
Have apiops init generate an additional Copilot prompt file — e.g. .github/prompts/apiops-check-best-practices.prompt.md — following the same generation pattern as the existing identity-setup prompt (src/templates/copilot/identity-setup-prompt.ts, written in src/services/init-service.ts). When opened with GitHub Copilot, the prompt guides the user through auditing the artifacts in the repo against a focused set of APIM best practices.
Scope — only things apiops-cli tracks
Keep the checks centered on apiops-managed artifacts (policies, named values, backends, diagnostics/loggers, subscriptions, products). Explicitly out of scope: infra/SKU/networking/scale guidance from the WAF doc that doesn''t map to apiops artifacts.
Checks (initial set)
- Hardcoded secrets in
policy.xml(headline check) — detect literal secrets in policy XML (set-headerauth/keys,set-query-parametercode/sig,authentication-basicpassword,validate-jwtkeys, connection-string fragments).- Offer to fix: create a (secret) named value for the secret and rewrite the policy to reference it via
{{named-value}}, per https://learn.microsoft.com/en-us/azure/api-management/api-management-howto-properties
- Offer to fix: create a (secret) named value for the secret and rewrite the policy to reference it via
- Named values holding secrets that aren''t marked
secret: trueor aren''t Key Vault–backed → flag and offer to mark/migrate. - Backend URLs / keys inlined in policies instead of using named values/backends → suggest parameterizing.
(Start with check #1; #2–#3 can follow.)
Reference
APIM best-practice guidance: https://learn.microsoft.com/en-us/azure/well-architected/service-guides/azure-api-management — used as a source, but the prompt should distill only the artifact-level items above rather than the full large-deployment guidance.
Affected command
apiops init (generates the prompt file); the prompt itself assists with apiops extract output.
Implementation notes
- New template under
src/templates/copilot/(e.g.best-practices-prompt.ts) + embedded markdown, mirroringidentity-setup-prompt.ts. - Write the file in
init-service.tsalongside the identity prompt (conflict-check + add togeneratedFiles.configs), and mention it in theinit-command.tsnext-steps output. - Relates to #198 (the CLI-side redact-and-warn for the same class of issue; this prompt is the interactive remediation counterpart).
- Dominant language
- TypeScript
- Stars
- 29
- Forks
- 10
- Avg merge
- 1d 14h
- Merged PRs (30d)
- 22
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from Azure/apiops-cli
-
type:question
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
Azure/apiops-cli#277 ·
-
type:documentation
Difficulty 1/5 Under an hour Newbie friendliness 94/100
Azure/apiops-cli#250 ·
-
Documentation P2
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
Azure/apiops-cli#24 · 1 comment ·
-
type:bug
Difficulty 4/5 3-5 days Newbie friendliness 55/100
Azure/apiops-cli#291 ·
-
type:bug
Difficulty 3/5 1-2 days Newbie friendliness 58/100
Azure/apiops-cli#276 ·
All issues in Azure/apiops-cli
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Eynzof/Hermes-CN-Desktop#610 ·
-
bug clawsweeper:linked-pr-open clawsweeper:needs-live-repro clawsweeper:no-new-fix-pr impact:message-loss issue-rating: 🐚 platinum hermit P2 regression
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
-
enhancement
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
calcite-components needs triage refactor
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Esri/calcite-design-system#15203 ·
-
Difficulty 1/5 Under an hour Newbie friendliness 78/100
fullcalendar/fullcalendar#8106 ·