ensure-pipelines-host
Ensures the tenant has a usable Power Platform Pipelines host environment before any pipeline operation runs. Detects host state via the same resolution order as the Power Apps UI (org-db setting → BAP env metadata → default-custom-host setting); if any existing host (Platform or Custom) is found, u…
Install / Use
npx skills add microsoft/power-platform-skills --skill ensure-pipelines-hostInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
AutomationSupported Platforms
Our assessment of ensure-pipelines-host
ensure-pipelines-host scores 85/100 on our quality scale, 1958th of 2,892 Automation skills we index.
Its SKILL.md is 88 KB long, well organised into 41 sections with 8 code examples: long enough that it reads more like full documentation than a focused instruction file, which agents can find harder to follow.
It has 919 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 12 days ago, so ensure-pipelines-host is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
ensure-pipelines-host compared with similar skills
All 4 of these similar skills score higher than ensure-pipelines-host; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| ensure-pipelines-host (this skill)by microsoft | 85 | 919 | 12d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 92.4k | 21d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.5k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.9k | today | MCP Server |
| crawl4aiby unclecode | 100 | 84.8k | 1d ago | MCP Server |
Frequently asked questions
- How do I install ensure-pipelines-host?
- Run
npx skills add microsoft/power-platform-skills --skill ensure-pipelines-host. The install tabs above show the steps for each supported agent. - Which AI agents does ensure-pipelines-host work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is ensure-pipelines-host safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is ensure-pipelines-host still maintained?
- The repository was last updated 12 days ago, so ensure-pipelines-host is actively maintained.
Skill content
View source on GitHubname: ensure-pipelines-host
description: >-
Ensures the tenant has a usable Power Platform Pipelines host environment
before any pipeline operation runs. Detects host state via the same
resolution order as the Power Apps UI (org-db setting → BAP env metadata →
default-custom-host setting); if any existing host (Platform or Custom) is
found, uses it. If no host is bound to the source env, provisions a new
Platform Host (recommended, idempotent) or a Custom Host via the
BAP env-create API with the D365_ProjectHost template, or guides the user
through PPAC install / New custom host (manual fallbacks). Polls
lifecycle operations, verifies the host responds to Pipelines API calls,
writes a host-check artifact other ALM skills consume. Use when asked to:
"set up pipelines host", "ensure pipelines host", "no pipelines host",
"install pipelines", "create pipelines host", "provision platform host",
"provision custom host". Also invoked transparently by
/power-pages:setup-pipeline when its host discovery step finds nothing.
user-invocable: true
argument-hint: "Optional: 'detect-only' to skip provisioning paths and report state; 'auto-platform' to run the Platform-Host fast-path (idempotent, ~3–5 min) without the path-decision prompt (still gated by tenant pre-call confirmation); 'auto-custom' to run the Custom-Host fast-path without the path-decision prompt (still gated by tenant + admin-role + pre-call-echo prompts)"
allowed-tools: Read, Write, Edit, Bash, Glob, Grep, TaskCreate, TaskUpdate, TaskList, AskUserQuestion, mcp__plugin_power-pages_microsoft-learn__microsoft_docs_search, mcp__plugin_power-pages_microsoft-learn__microsoft_docs_fetch
model: opus
<!-- alm-lint-ignore: SKILL-must-read-manifest — this skill manages the Pipelines host environment (deploymentenvironments / deploymentpipelines tables on the host), not the source-env solution. The site's .solution-manifest.json is irrelevant to host lifecycle: a host can be provisioned before any solution exists, and a single host is shared across many solutions. ALM-aware-by-default does not apply. -->Plugin check: Run
node "${PLUGIN_ROOT}/scripts/check-version.js"— if it outputs a message, show it to the user before proceeding.
ensure-pipelines-host
Scope: When no host is bound to the source env, this skill detects any existing host (Custom or PE) for reuse, or — in
NoHoststate — offers three provisioning paths: a new Platform Host (recommended; idempotent, ~3–5 min); a new Custom Host (admin-only, ~5–10 min); or PPAC manual provisioning (fallback). Implementation details — endpoint names, template names, BAP audience — live in Phase 4.0 / 4.A / 4.C below; user-facing prose stays focused on outcomes.
Power Platform Pipelines need a host environment — a Dataverse environment with the Power Platform Pipelines managed solution installed, where pipelines, stages, run history, and artifacts live. The existing setup-pipeline and deploy-pipeline skills assume a host is already configured. This skill closes that gap.
What we know (sources of truth)
This plan is grounded in three primary sources, in priority order:
useGetOrCreatePlatformEnvironment.v4.ts(Microsoft-internal client source —power-platform-ux/packages/powerapps-appdeployment-ux/src/hooks/v4/). Defines the exact HTTP contract for Platform Environment provisioning: endpoint, body, headers, polling.ProjectHostProvider.tsx(same repo,src/components/ProjectHostProvider/). Defines the exact resolution order the Power Apps UI uses to determine which environment is the project host for a source environment. We mirror that order so this skill agrees with the UI.- eng.ms
createcustompipelineshost(Microsoft-internal). Documents the Custom Host fast-path: aD365_ProjectHostorg template that ships the Pipelines app pre-installed, callable through the standard environment-creation API.
Public Microsoft Learn (learn.microsoft.com/power-platform/alm/{platform-host-pipelines, custom-host-pipelines, set-a-default-pipelines-host}) is the user-facing description of the same flows; we cite it for behaviors users will recognize. HARs in PipelinesDeployScenario.har and Pipelines.har confirm the read-side calls.
Three host shapes the tenant can be in
| Shape | How it got there | Where it lives | Org template |
|---|---|---|---|
| Platform Host (PE) | Auto-provisioned by getOrCreate BAP call (or as a side-effect of first navigation to the Pipelines page in make.powerapps.com). Hidden from the env picker. One per tenant. | Microsoft-managed Dataverse env in tenant's home geo | D365_1stPartyAdminApps |
| Custom Host | Created by an admin via PPAC Deployments → New custom host, or via the standard env-create API with the D365_ProjectHost template, or by installing the Power Platform Pipelines app on an existing Dataverse env. | A regular Dataverse env in the tenant | D365_ProjectHost (or app-installed-onto-existing-env) |
| No host bound to source env | Tenant has not used Pipelines from this env. | — | — |
The current discover-pipelines-host.js only checks the tenant-level DefaultCustomPipelinesHostEnvForTenant setting. That's one signal of many. This skill implements the full resolution order.
Resolution order (mirrors ProjectHostProvider.tsx)
This is the load-bearing decision tree. It is what the Power Apps UI does. We replicate it so the skill agrees with the UI.
┌─────────────────────────────────────────────────────────────────────┐
│ 1. GetOrgDbOrgSetting('ProjectHostEnvironmentId') on source env │
└──────────────────────────┬──────────────────────────────────────────┘
│
┌──────────────┴───────────────┐
│ value present │ value empty
▼ ▼
┌───────────────────────┐ ┌────────────────────────────┐
│ 2. Resolve env via │ │ 5a. Tenant-wide search: │
│ BAP GET │ │ list envs + per-env │
│ /environments/{id} │ │ /deploymentpipelines │
└───────┬───────────────┘ │ probe. │
│ │ │
environmentSku? │ - 1 Custom Host found → │
│ │ AvailableUnboundCustom │
┌────┴────────────┐ │ (3.C-pre) │
│ Platform │ │ - >1 Custom Hosts → │
│ │ │ MultipleUnboundCustom │
│ │ │ (3.C-pre') │
│ │ │ - PE only → │
│ │ │ PlatformHostExists- │
│ │ │ Unbound (3.C-pre'') │
│ │ │ - none → NoHost (3.C) │
│ │ │ │
│ │ │ 5b. Decision tree paths │
│ │ │ for create-new (3.C): │
│ │ │ - Platform getOrCreate │
│ │ │ (fast-path, no admin) │
│ │ │ - Custom D365_ProjectHost│
│ │ │ (fast-path, admin) │
│ │ │ - Manual app install │
│ │ │ - Manual PPAC create │
│ │ └────────────────────────────┘
▼ │
┌──────────────┐ │
│ 3. Check │ │ environmentSku ≠ Platform (Custom Host)
│ Default- │ ▼
│ Custom- │ ┌──────────────────────────────┐
│ Pipelines- │ │ 4. Use the Custom Host │
│ HostEnv- │ │ directly. Skip default- │
│ ForTenant │ │ custom check. │
└──────┬───────┘ └──────────────────────────────┘
│
┌───┴────────────────────────┐
│ admin set a custom default │
│ │
▼ ▼
┌─────────────────┐ ┌─────────────────────────┐
│ default == │ │ default != │
│ org setting? │ │ org setting │
│ │ │ │
│ → use default │ │ → CannotRedirect ERROR │
│ custom │ │ (user locked to PE │
└─────────────────┘ │ but admin overrode │
│ at tenant scope) │
└─────────────────────────┘
if no admin default → use PE
Source: ProjectHostProvider.tsx lines 100–213 (orgSetting fetch → defaultCustomPipelinesHost fetch → finalProjectHostEnvironmentId resolution).
What this skill does NOT do
These are deliberate non-goals (each based on a hard constraint or a destructive blast-radius — see Design Constraints below):
- Does not silently provision anything. Any action that creates an env or binds the source env to a host requires explicit user confirmation, with the tenant name + tenant ID echoed back. PE is tenant-singleton and admin-non-deletable, so the Phase 4.0 pre-call confirmation gate is the principal mitigation against wrong-tenant provisioning. The
getOrCreateendpoint is idempotent — calling it on a tenant that already has a PE returns the existing one rather than creating a duplicate. - Does not call
Force Linkto rebind an environment to a different host. Force Link is destructive (makers lose access to existing pipelines in the previous host) and is hidden behind a separate confirmation gate, only reachable when the user explicitly says "rebind". - Does not change the tenant-level
DefaultCustomPipelinesHostEnvForTenantsetting. That setting is irreversible-adjacent (existing pipelines in the previous default become inaccessible — seelearn.microsoft.com/power-platform/alm/set-a-default-pipelines-host). Out of scope. - Does not delete environments.
- Does not write
ProjectHostEnvironmentIddirectly. Binding is established through the documented Pipelines flow (creating adeploymentenvironmentrecord in the host); writing the org setting directly bypasses validation.
Auth strategy: PAC-first with BAP fallback (--source auto)
Read-side detection (Phase 2 resolution order, env list, env-by-id) defaults to --source auto:
- If a BAP token is provided, try BAP env-list / env-GET first (richer data including
lastModifiedTime,permissions,tenantId). - On HTTP 401 or 403, fall back to
pac admin list --jsonviapac-bap-shim.js. PAC has its own first-party client-ID grants on BAP that Az CLI doesn't always inherit (verified 2026-04-28:D365DemoTSCE53051106demo tenant rejects Az tokens for BAP even with correct audience claims). - If no BAP token is provided at all, go straight to PAC.
The PAC shim returns BAP-shaped data; downstream code (sku filter, ranking, classification) is unchanged. Fields not provided by PAC (tenantId, lastModifiedTime, permissions, isManaged) come back as null — none are critical for host detection. PAC also doesn't surface Platform Hosts (PE) since pac admin list doesn't include Platform-sku envs; PE detection requires --source bap with a working BAP token.
Write-side actions (env-create POST in provision-custom-host.js, lifecycle op polling) still require BAP. Az CLI tokens with the right audience usually work for these even when env-list calls fail, because the BAP RP enforces different policy on actions than reads. If provision-custom-host.js returns 401, the user must register a service principal in the target tenant (or use the PPAC UI fallback path 4.C).
Design Constraints
- JIT provisioning is required when a PE is selected — existing or freshly provisioned. From
ProjectHostProvider.tsx(line 232–240 comment): *"In the Platform Environment case, the user may not already be provisioned there
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
92.4kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.5kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
85.9k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.8kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
