You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
az bicep build --file infra/main.bicep --outfile <temporary file> succeeded; the compiler emitted existing warnings.
Full umbrella pytest -q: 572 passed, 4 skipped, and 12 test_private_network_hooks subtest failures at the ACR Task pool guard. Those tests do not exercise the changed release pins.
Azure end-to-end acceptance has not run; it will be performed separately after publication.
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Fixed
First azd up on a fresh clone no longer fails with "missing required inputs": infra/main.parameters.json is committed as a seed and preprovision recomposes it on every provision (#748).
preprovision hooks now automatically mark infra/main.parameters.json as skip-worktree, so regenerated parameters no longer appear in git status (#749).
Component versions
Component
Version
gpt-rag-ui
v3.1.1
gpt-rag-orchestrator
v5.1.1
gpt-rag-ingestion
v3.0.1
infra / AI Landing Zone
v2.7.3
Validation
infra/main.parameters.json seed and skip-worktree behavior verified on a fresh clone with the PowerShell and shell preprovision hooks.
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Fixed
Fresh deployments failed in preprovision because app-definition.jsonsource.commit values did not match the component commits pinned in manifest.json. The app definition now pins the same commits as the manifest.
Component versions
Component
Version
gpt-rag-ui
v3.1.1
gpt-rag-orchestrator
v5.1.1
gpt-rag-ingestion
v3.0.1
infra / AI Landing Zone
v2.7.3
Validation
Fresh deployment with NETWORK_ISOLATION=true in westus3 using azd up: images built on the ACR agent pool while the registry kept public network access disabled; frontend, orchestrator, and data ingestion container apps running the pinned images.
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Changed
DEPLOY_ACR_TASK_AGENT_POOL now defaults to true. With NETWORK_ISOLATION=true the foundation provisions the in-VNet ACR Task agent pool, so remote image builds work without opening the registry to the public network. Without network isolation no pool is created (#741).
Fixed
azd deploy now fails early, before deploying any application, when NETWORK_ISOLATION=true and no ACR Task agent pool exists, with guidance to provision the pool or use BUILD_MODE=local from a VNet-connected host (#741).
Keyless UI-to-orchestrator auth now works with the default system-assigned frontend identity: post-provision publishes ORCHESTRATOR_AUTH_AUDIENCE as the Azure Resource Manager audience when no user-assigned identity or explicit audience exists (ADR-0019).
Components pinned to the patch releases with the same network-isolation guard.
Component versions
Component
Version
gpt-rag-ui
v3.1.1
gpt-rag-orchestrator
v5.1.1
gpt-rag-ingestion
v3.0.1
infra / AI Landing Zone
v2.7.3
Validation
Bicep build and lifecycle-hook checks (PowerShell and shell) for the agent pool default and the fail-early guard.
Keyless chat validated on a fresh Basic deployment (NETWORK_ISOLATION=false) in a validation environment.
A full network-isolated deployment with the agent pool was not executed for this release.
Note: the ACR agent pool is billed per hour while running; scale it to zero with az acr agentpool update --count 0 when idle.
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Changed
Keyless UI → orchestrator authentication in Classic mode: the UI now calls the orchestrator using its managed identity with Microsoft Entra tokens (ADR-0019). The orchestrator validates the token audience and caller.
The orchestrator API key is now opt-in (useCAppAPIKey=false by default) and is no longer required for chat to work.
Hosted-agent mode is unchanged (it already uses Entra auth).
Component versions
Component
Version
gpt-rag-ui
v3.1.0
gpt-rag-orchestrator
v5.1.0
gpt-rag-ingestion
v3.0.0
infra / AI Landing Zone
v2.7.3
Validation
python -m config.appdefinition --validate passed.
python -m pytest tests -q: 381 passed, 4 skipped.
Component unit tests passed for the orchestrator (v5.1.0) and UI (v3.1.0) releases.
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPT-RAG is now Agent Landing Zone. This is the first GA release under the new name. It is intended for new deployments only: existing GPT-RAG environments must be redeployed. In-place upgrade is not supported.
Changed
Rebranded GPT-RAG to Agent Landing Zone (repository Azure/agent-landing-zone), with application components renamed to agent-app-ui, agent-app-orchestrator, and agent-app-ingestion.
Separated foundation (infrastructure) and application deployment: operators can deploy only the landing zone, or the landing zone plus the application, using the default or hosted-agent orchestration option.
App Configuration label agent-lz is now primary; components still read the legacy gpt-rag label during the transition.
infra/ is now repository-owned source incorporated from the AI Landing Zone v2.7.3 release.
User documentation moved to the central AI Landing Zones documentation site.
Includes all v3.8.4–v3.8.11 hotfixes.
Component versions
Component
Version
agent-app-ui
v3.0.0
agent-app-orchestrator
v5.0.0
agent-app-ingestion
v3.0.0
infra / AI Landing Zone
v2.7.3
Validation
Release contract and unit test suite (pytest) passed on the release branch.
Preview v4.0.0-preview.1 was validated with a fresh Basic deployment in a validation environment (NETWORK_ISOLATION=false).
This commit was created on GitHub.com and signed with GitHub’s verified signature.
GPT-RAG is now Agent Landing Zone. This is the first preview of v4.0.0 under the new name.
New deployments only. Existing GPT-RAG v3.x environments cannot be upgraded in place. To adopt v4, redeploy.
Changed
Rebranded GPT-RAG as Agent Landing Zone. The umbrella repository is now Azure/agent-landing-zone, and the components are agent-app-ui, agent-app-orchestrator and agent-app-ingestion. The old GitHub URLs redirect.
Added an infrastructure-only deployment mode that provisions the landing zone without any application.
Added custom application selection through app-definition.json, which defaults to the UI + orchestrator + ingestion trio, with or without a hosted agent.
Renamed resources, configuration labels (agent-lz, with the legacy gpt-rag label still read during the transition), images and naming.
Component versions
Component
Version
agent-app-ui
v3.0.0-preview.2
agent-app-orchestrator
v5.0.0-preview.2
agent-app-ingestion
v3.0.0-preview.2
infra / AI Landing Zone
v2.7.3
Validation
An end-to-end smoke test passed on a fresh Basic deployment in uksouth, with NETWORK_ISOLATION=false.
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Documentation release. No runtime code changes from v3.8.10.
Every component that loads the gpt-rag App Configuration label (UI, orchestrator, hosted-agent identity) needs Key Vault Secrets User to resolve Key Vault references such as authClientSecret. Without it the orchestrator returns HTTP 500 (#716).