You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Changed
Keyless UI → orchestrator authentication in Classic mode: the UI now calls the orchestrator using its managed identity with Microsoft Entra tokens (ADR-0019). The orchestrator validates the token audience and caller.
The orchestrator API key is now opt-in (useCAppAPIKey=false by default) and is no longer required for chat to work.
Hosted-agent mode is unchanged (it already uses Entra auth).
Component versions
Component
Version
gpt-rag-ui
v3.1.0
gpt-rag-orchestrator
v5.1.0
gpt-rag-ingestion
v3.0.0
infra / AI Landing Zone
v2.7.3
Validation
python -m config.appdefinition --validate passed.
python -m pytest tests -q: 381 passed, 4 skipped.
Component unit tests passed for the orchestrator (v5.1.0) and UI (v3.1.0) releases.