You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This commit was created on GitHub.com and signed with GitHub’s verified signature.
Changed
DEPLOY_ACR_TASK_AGENT_POOL now defaults to true. With NETWORK_ISOLATION=true the foundation provisions the in-VNet ACR Task agent pool, so remote image builds work without opening the registry to the public network. Without network isolation no pool is created (#741).
Fixed
azd deploy now fails early, before deploying any application, when NETWORK_ISOLATION=true and no ACR Task agent pool exists, with guidance to provision the pool or use BUILD_MODE=local from a VNet-connected host (#741).
Keyless UI-to-orchestrator auth now works with the default system-assigned frontend identity: post-provision publishes ORCHESTRATOR_AUTH_AUDIENCE as the Azure Resource Manager audience when no user-assigned identity or explicit audience exists (ADR-0019).
Components pinned to the patch releases with the same network-isolation guard.
Component versions
Component
Version
gpt-rag-ui
v3.1.1
gpt-rag-orchestrator
v5.1.1
gpt-rag-ingestion
v3.0.1
infra / AI Landing Zone
v2.7.3
Validation
Bicep build and lifecycle-hook checks (PowerShell and shell) for the agent pool default and the fail-early guard.
Keyless chat validated on a fresh Basic deployment (NETWORK_ISOLATION=false) in a validation environment.
A full network-isolated deployment with the agent pool was not executed for this release.
Note: the ACR agent pool is billed per hour while running; scale it to zero with az acr agentpool update --count 0 when idle.