Skip to content

v4.1.1

Choose a tag to compare

@placerda placerda released this 06 Oct 13:57
· 42 commits to main since this release
bfd8ba4

Changed

  • DEPLOY_ACR_TASK_AGENT_POOL now defaults to true. With NETWORK_ISOLATION=true the foundation provisions the in-VNet ACR Task agent pool, so remote image builds work without opening the registry to the public network. Without network isolation no pool is created (#741).

Fixed

  • azd deploy now fails early, before deploying any application, when NETWORK_ISOLATION=true and no ACR Task agent pool exists, with guidance to provision the pool or use BUILD_MODE=local from a VNet-connected host (#741).
  • Keyless UI-to-orchestrator auth now works with the default system-assigned frontend identity: post-provision publishes ORCHESTRATOR_AUTH_AUDIENCE as the Azure Resource Manager audience when no user-assigned identity or explicit audience exists (ADR-0019).
  • Components pinned to the patch releases with the same network-isolation guard.

Component versions

Component Version
gpt-rag-ui v3.1.1
gpt-rag-orchestrator v5.1.1
gpt-rag-ingestion v3.0.1
infra / AI Landing Zone v2.7.3

Validation

  • Bicep build and lifecycle-hook checks (PowerShell and shell) for the agent pool default and the fail-early guard.
  • Keyless chat validated on a fresh Basic deployment (NETWORK_ISOLATION=false) in a validation environment.
  • A full network-isolated deployment with the agent pool was not executed for this release.
  • Note: the ACR agent pool is billed per hour while running; scale it to zero with az acr agentpool update --count 0 when idle.