-
Notifications
You must be signed in to change notification settings - Fork 60
Use S2S-only OBS with isolated app-token providers across samples #339
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
Krishnadheeraj (DheerajPannala)
wants to merge
8
commits into
main
Choose a base branch
from
users/DheerajPannala/obs-s2s-only-20260909
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
8 commits
Select commit
Hold shift + click to select a range
a6f88cf
fix(samples): isolate app-only OBS auth and use S2S endpoints
DheerajPannala e9206cb
fix(samples): support roleless OBS and address auth reviews
DheerajPannala f85bf6c
docs(samples): document oid==sub roleless acceptance; apply quality nits
DheerajPannala 3bac1b1
ci(samples): run business-auth contract guard in the Node.js OpenAI w…
DheerajPannala 0f3aefe
fix(samples): move Node OBS exports to SDK 1.0.0
DheerajPannala 00cec4e
docs(samples): clarify Node OBS app-token limits
DheerajPannala 8ff1e7f
fix(samples): address s2s observability review feedback
DheerajPannala 065753c
fix(samples): keep engines and CI restore sources unchanged; explain …
DheerajPannala File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,52 @@ | ||
| # Copyright (c) Microsoft Corporation. | ||
| # Licensed under the MIT License. | ||
|
|
||
| name: CI - Observability Offline Tests | ||
| permissions: | ||
| contents: read | ||
|
|
||
| on: | ||
| workflow_call: # Called by orchestrator | ||
| workflow_dispatch: # Manual trigger | ||
|
|
||
| jobs: | ||
| python-observability: | ||
| name: Python observability tests | ||
| runs-on: windows-latest | ||
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v4 | ||
|
|
||
| - name: Set up Python | ||
| uses: actions/setup-python@v5 | ||
| with: | ||
| python-version: '3.11' | ||
|
|
||
| - name: Install dependencies | ||
| run: | | ||
| python -m pip install --upgrade pip | ||
| pip install --pre -e "./python/openai/sample-agent[dev]" | ||
| pip install requests | ||
|
|
||
| - name: Run observability tests | ||
| run: python -m pytest tests/observability -q | ||
|
|
||
| dotnet-observability: | ||
| name: .NET ObservabilityAppTokenTests | ||
| runs-on: ubuntu-latest | ||
|
|
||
| steps: | ||
| - name: Checkout repository | ||
| uses: actions/checkout@v4 | ||
|
|
||
| - name: Setup .NET | ||
| uses: actions/setup-dotnet@v4 | ||
| with: | ||
| dotnet-version: '8.0.x' | ||
|
|
||
| - name: Restore test dependencies | ||
| run: dotnet restore tests/e2e/Agent365.E2E.Tests.csproj | ||
|
|
||
| - name: Run ObservabilityAppTokenTests | ||
| run: dotnet test tests/e2e/Agent365.E2E.Tests.csproj --no-restore --filter FullyQualifiedName~ObservabilityAppTokenTests |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,69 @@ | ||
| # Agent 365 observability S2S export | ||
|
|
||
| The samples export Agent 365 observability data through the S2S `/observabilityService/.../otlp/...` route with an app-only token for the agent instance. This changes telemetry transport only: keep business MCP, Graph, OBO, bearer-token development flows, and original turn baggage separate. | ||
|
|
||
| ## Route and token contract | ||
|
|
||
| Live validation on September 28, 2026 showed that a registered agent instance using a roleless app-only token (`idtyp=app`, `roles=[]`, no `scp`) received `200` from `/observabilityService/tenants/{tenant}/otlp/agents/{agent}/traces`. The legacy non-`/otlp` S2S route (`/observabilityService/tenants/{tenant}/agents/{agent}/traces`) rejected the same token with `401` (`AuthenticationSchemeNotSupported`). Every sample must use an SDK/exporter configuration that posts to the `/otlp` route. | ||
|
|
||
| The sample providers accept app-only tokens that meet one of these contracts: | ||
|
|
||
| - `idtyp=app` | ||
| - a valid nonempty `roles` array when `idtyp` is absent | ||
| - absent `idtyp` with a nonempty `oid` equal to `sub` | ||
|
|
||
| Any `scp` claim is rejected, even if it is empty or the token also contains application-looking claims. When present, `roles` must be an array of nonblank strings. | ||
|
|
||
| ## Sample provider scope | ||
|
|
||
| The .NET, Python, and Node.js sample providers are intentionally simple and single-instance: they export for one statically configured tenant and agent instance. Configure the agent instance client ID, not the blueprint ID, service-principal object ID, or agent-user ID. | ||
|
|
||
| These sample providers need their own copy of the blueprint credential. The Python and Node.js samples only include a client-secret development flow and have no managed-identity option; the .NET samples can use a managed-identity assertion for the blueprint credential. All providers currently request tokens from `login.microsoftonline.com`, so sovereign clouds need provider changes before use. | ||
|
|
||
| For production deployments that can serve multiple hired instances or tenants, implement a per-agent/per-tenant cache and reuse the hosting connection credential for that turn's agent identity. Do not rewrite incoming baggage to fit a static configuration. | ||
|
|
||
| ## Configuration | ||
|
|
||
| Enable export explicitly. Keep the checked-in placeholders for local/Playground runs with export disabled. | ||
|
|
||
| ### .NET | ||
|
|
||
| ```json | ||
| { | ||
| "EnableAgent365Exporter": true, | ||
| "Agent365Observability": { | ||
| "TenantId": "<<AGENT_HOME_TENANT_ID>>", | ||
| "AgentId": "<<AGENT_INSTANCE_CLIENT_ID>>", | ||
| "BlueprintClientId": "<<BLUEPRINT_CLIENT_ID>>", | ||
| "UseManagedIdentity": true, | ||
| "ManagedIdentityClientId": "" | ||
| } | ||
| } | ||
| ``` | ||
|
|
||
| For local development with a secret, set `UseManagedIdentity=false` and provide `Agent365Observability:BlueprintClientSecret` through user secrets or `Agent365Observability__BlueprintClientSecret`. | ||
|
|
||
| ### Python and Node.js | ||
|
|
||
| ```dotenv | ||
| ENABLE_A365_OBSERVABILITY_EXPORTER=true | ||
| AGENT365_OBS_TENANT_ID=<<YOUR_TENANT_ID>> | ||
| AGENT365_OBS_AGENT_ID=<<YOUR_AGENT_INSTANCE_CLIENT_ID>> | ||
| AGENT365_OBS_BLUEPRINT_CLIENT_ID=<<YOUR_BLUEPRINT_CLIENT_ID>> | ||
| AGENT365_OBS_BLUEPRINT_CLIENT_SECRET=<<YOUR_BLUEPRINT_CLIENT_SECRET>> | ||
| ``` | ||
|
|
||
| The Python `microsoft-opentelemetry` distro gates its A365 HTTP exporter on `ENABLE_A365_OBSERVABILITY_EXPORTER` or `a365_enable_observability_exporter`; when disabled, A365 span enrichment can remain enabled without sending data to A365. | ||
|
|
||
| ## AI Teammates | ||
|
|
||
| AI Teammate S2S export without the `Agent365.Observability.OtelWrite` application-role step has not been validated. For AI Teammates, complete the OtelWrite application-role assignment that `a365 setup all --aiteammate` prints. | ||
|
|
||
| ## Offline validation | ||
|
|
||
| ```powershell | ||
| python -m pytest tests/observability -q | ||
| dotnet test tests/e2e/Agent365.E2E.Tests.csproj --filter FullyQualifiedName~ObservabilityAppTokenTests | ||
| ``` | ||
|
|
||
| The Python suite mocks token exchange and exporter uploads. The .NET suite mocks HTTP token exchange and validates the sample-local provider copies. |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.