git-integration-operations-cli
Runs the Fabric Git integration lifecycle through fab api or az rest, including connecting a workspace to Azure DevOps or GitHub, committing, updating from Git, reading sync status, resolving conflicts, disconnecting a connected workspace, and automating sync with a service principal.
Install / Use
npx skills add microsoft/skills-for-fabric --skill git-integration-operations-cliInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
AutomationSupported Platforms
Our assessment of git-integration-operations-cli
git-integration-operations-cli scores 93/100 on our quality scale, 733rd of 2,881 Automation skills we index (top 26%).
Its SKILL.md is 35 KB long, well organised into 46 sections with 13 code examples: a thorough specification that gives an agent plenty to work with.
With 1,181 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 15 days ago, so git-integration-operations-cli is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
git-integration-operations-cli compared with similar skills
All 4 of these similar skills score higher than git-integration-operations-cli; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| git-integration-operations-cli (this skill)by microsoft | 93 | 1.2k | 15d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 89.0k | 17d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.3k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 85.3k | 2d ago | MCP Server |
| crawl4aiby unclecode | 100 | 84.7k | 8d ago | MCP Server |
Frequently asked questions
- How do I install git-integration-operations-cli?
- Run
npx skills add microsoft/skills-for-fabric --skill git-integration-operations-cli. The install tabs above show the steps for each supported agent. - Which AI agents does git-integration-operations-cli work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is git-integration-operations-cli safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is git-integration-operations-cli still maintained?
- The repository was last updated 15 days ago, so git-integration-operations-cli is actively maintained.
Skill content
View source on GitHubname: git-integration-operations-cli description: "Runs the Fabric Git integration lifecycle through fab api or az rest, including connecting a workspace to Azure DevOps or GitHub, committing, updating from Git, reading sync status, resolving conflicts, disconnecting a connected workspace, and automating sync with a service principal. For stage promotion use deployment-pipelines-authoring-cli. Branch switching, fab deploy, fabric-cicd and cross-workspace rebinding are out of scope." metadata: maturity: experimental owner: yaron
Telemetry — MANDATORY. Every
api.fabric.microsoft.comcall must carryx-ms-fabric-skill: git-integration-operations-cli(az rest:--headers "x-ms-fabric-skill=git-integration-operations-cli"), including every LRO poll,fabric_lroand retry. Snippets omit it — add it anyway.
CRITICAL NOTES
- To find a workspace ID from its name: list all workspaces, then filter by
displayNamewith JMESPath. To find an item ID: list items of that type in the workspace, then filter bydisplayName.- All Git operations are control plane calls against
https://api.fabric.microsoft.com. Runfab auth loginonce andfab apisets the base URL and Fabric token audience automatically. With theaz restfallback you must pass the matching--resourceyourself, or you get a 401.commitToGit,updateFromGit, and evengit/statuscan return HTTP 202 (long-running operation), not just a synchronous body. On202, poll the operation: withfab, readx-ms-operation-idfrom--show_headersand pollfab api operations/{id}untilstatusisSucceeded; with theaz restfallback, poll theLocation/x-ms-operation-idheader (see COMMON-CORE long-running operation polling). THEN readgit/statusto confirmworkspaceHead == remoteCommitHash. Prefer the operation poll to confirm completion; if you pollgit/statusinstead, treat an in-progress (202) or not-yet-synced response as "still running" and do not act on itschangesuntil the heads match. (Learn: rest/api/fabric/core/git and fabric/cicd/git-integration/git-automation.)updateFromGitrequires the workspace's currentworkspaceHead; a stale value returns400 WorkspaceHeadMismatch. Always readgit/statusfirst.- Prerequisites for every Git operation: the workspace must be assigned to a capacity (an unassigned workspace fails with
WorkspaceHasNoCapacityAssigned), and the caller (user or service principal) must hold the right workspace role: connect and disconnect require Admin; commit and update require at least Contributor with write permission on all items; branch switching requires Admin (or Contributor when the workspace opt-in setting Allow users with at least Contributor role to change Git branch is on). Only one Git operation may run against a workspace at a time.- Tenant admin switches gate Git integration and are a common cause of an unexplained failure. The GitHub sync switch is off by default (enable it before any GitHub connect); Azure DevOps sync is on by default. Cross-region workspace-to-Azure-repo needs the cross-geo export switch (GitHub does not enforce it). See references/git-integration-concepts.md § Tenant admin prerequisites.
Git Integration Operations — CLI Skill
Automate the Fabric Git integration lifecycle (connect, commit, update, status, disconnect) from CLI environments. Whether cross-workspace item references rebind after promotion is a separate concern, determined by the item definition format (logical vs object IDs) rather than the Git lifecycle itself.
Prerequisite Knowledge
Read these shared references first (paths assume this skill lives under
skills/git-integration-operations-cli/ in skills-for-fabric; adjust when drafting
outside the repo):
- COMMON-CLI.md § Finding Workspaces and Items in Fabric — Mandatory for resolving workspace/item IDs by name.
- COMMON-CORE.md § Authentication & Token Acquisition — wrong audience = 401; read before any auth issue.
- COMMON-CLI.md § Authentication Recipes —
az loginflows and token acquisition for CLI. - COMMON-CLI.md § Fabric Control-Plane API via az rest — the
az restfallback path (always pass--resource); includes LRO polling helpers. - COMMON-CORE.md § Core Control-Plane REST APIs — pagination, long-running-operation polling, rate limiting.
Table of Contents
| Task | Reference | |---|---| | Pre-flight checks before connecting | SKILL.md § Pre-Flight (before you connect) | | Connect a workspace to Git | SKILL.md § Connect a Workspace to Git | | Create a git connection (service principal) | SKILL.md § Create the Git provider connection (service principal) | | Commit workspace items to Git | SKILL.md § Commit to Git | | Update a workspace from Git | SKILL.md § Update from Git | | Check sync status | SKILL.md § Check Sync Status | | Resolve update conflicts | SKILL.md § Resolve Conflicts | | Disconnect from Git | SKILL.md § Disconnect from Git | | Link a branch workspace to its base (workspace relations) | SKILL.md § Link a Branch Workspace to its Base (Workspace Relations) | | Git integration concepts (sync model, status, permissions) | references/git-integration-concepts.md § Concepts | | Tenant admin prerequisites (switches) | references/git-integration-concepts.md § Tenant admin prerequisites | | Supported Git providers | references/git-integration-concepts.md § Supported Git providers | | Supported item types | references/git-integration-concepts.md § Supported item types | | Avoiding formatting-only diffs (trailing newline / line endings) | references/git-integration-concepts.md § Avoiding formatting-only diffs | | Service principal / CI-CD pipeline templates | references/automation-templates.md | | Gotchas, Rules, Troubleshooting | SKILL.md § Gotchas, Rules, Troubleshooting |
Must/Prefer/Avoid
MUST DO
- Read
git/statusand pass the currentworkspaceHeadinto everycommitToGitandupdateFromGitcall. - Poll
git/statusafter each async operation untilworkspaceHead == remoteCommitHashand thechangesarray is empty. A202/Succeededstatus is not proof of a correct sync — validate the state. - Deploy an item together with the items it references in the same commit, so logical IDs can resolve inside the target workspace.
MUST NEVER
- Never run two Git operations concurrently on the same workspace — a second
commitToGit/updateFromGitwhile one is stillRunningcorrupts head tracking. Serialize: poll the first toSucceededbefore starting the next. - Never treat a workspace as both a source of truth and a CI/CD push target on the same branch. Pick one writer per branch: either humans commit from the workspace, or automation pushes to Git — not both at once.
PREFER
fab api(afterfab auth login) as the primary driver: it sets the base URL and Fabric token audience automatically, avoiding the 401 wrong-audience trap. Useaz restwith--resource "https://api.fabric.microsoft.com"as the fallback whenfabis unavailable or you need fine-grained header control.PreferRemoteconflict resolution for a clean "pull latest from Git" into a downstream/target workspace.
AVOID
- Reusing a stale
workspaceHead(causes400 WorkspaceHeadMismatch). - Passing request bodies via stdin to
fab api(use-i <file.json>or-i '<inline JSON>').
CLI: fab primary, az rest fallback
Every operation below is shown with fab api. Run fab auth login once (it
supports service principals for automation); fab then handles the base URL and
token audience for you. The identical call on the az rest fallback is a
mechanical translation:
Authenticate fab for the identity you are running as:
fab auth login # interactive user (SSO)
fab auth login -u <client-id> -p <client-secret> --tenant <tenant-id> # service principal (CI/CD)
fab auth login --identity # managed identity (Azure compute)
A service principal or managed identity must be workspace Admin to connect or
disconnect (at least Contributor with write on all items is enough for
commit/update) and (for the ConfiguredConnection path) hold the git provider
credentials. See
references/automation-templates.md for full
pipeline scripts.
fab api <endpoint>becomesaz rest --method GET --url "https://api.fabric.microsoft.com/v1/<endpoint>" --resource "https://api.fabric.microsoft.com".fab api -X post <endpoint> -i body.jsonadds--method POST --headers "Content-Type=application/json" --body @body.json.
fab api reads a request body via -i from either a file path or an inline JSON
string (e.g. -i '{"displayName":"..."}') — never from stdin. It prints
{"status_code": <code>, "text": <parsed body>} (add --show_headers for a
top-level headers object), so read response fields with jq -r '.text.<field>'
and the LRO id with jq -r '.headers["x-ms-operation-id"]'. See
Example 2 for a full az rest pair.
Pre-Flight (before you connect)
Run these Git-relevant checks in order before git/connect. Each failure has a
specific fix — resolving them up front avoids the most common connect-time errors.
| Check | Command | Pass = proceed / Fail = fix |
|---|---|---|
| Auth + Fabric token | fab auth login then fab api workspaces | 401 → re-login (fab sets the correct audience automatically) |
| Caller is workspace Admin | fab api "workspaces/${WORKSPACE_ID}/roleAssignments" | Connect/disconnect require the Admin role |
| Workspace has capacity | fab api "workspaces/${WORKSPACE_ID}" → check capacityId | WorkspaceHasNoCapacityAssigned → assign a capacity (Git requires one) |
| Git credential for the SP path | fab api connections (reuse if one already fits) | SP connect needs a ConfiguredConnection. If none exists, the skill creates it from your ADO org/project/repo + SP tenant/client/secret — see Create the Git provider connection (needs the tenant toggle "service principals can create connections"). The interactive-user SSO path uses Automatic and needs no connection. |
| Target directoryName exists on the branch | GitHub: curl -fsS -H "Authorization: Bearer $PAT" "https://api.github.com/repos/$OWNER/$REPO/contents/$DIR?ref=$BRANCH" — ADO: Items API on the repo | The API (unlike the portal) does not create a missing folder — connecting to a directoryName that doesn't exist fails with 404 GitProviderResourceNotFound. If the folder is new,
Truncated for display — read the full file on GitHub.
Related Skills
Agent-Reach
89.0kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.3kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
85.3k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
crawl4ai
84.7kOpen-source web crawler and scraper for LLMs and AI agents: any website into clean, LLM-ready Markdown. Run it yourself, or use Crawl4AI Cloud with one key.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
