Skip to content

Commit b3253c2

Browse files
Merge pull request #14 from corticalstack/chore/scrub-tenant-identifiers
chore(08,12): scrub tenant identifiers and refresh deep-research outputs
2 parents ba6f772 + 0b8112e commit b3253c2

9 files changed

Lines changed: 1209 additions & 43 deletions

File tree

08-agents/08-03-hosted-agents/08-03-01-deploy-hosted-agent.ipynb

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -335,7 +335,7 @@
335335
"name": "stdout",
336336
"output_type": "stream",
337337
"text": [
338-
"Principal ID: 5db0aa5d-f281-47a3-9720-04727dec61e8\n",
338+
"Principal ID: 00000000-0000-0000-0000-000000000000\n",
339339
"Deploying ACR infrastructure (~1-2 min)...\n",
340340
"\u001b[?1h\u001b=\u001b[93mA new Bicep release is available: v0.43.8. Upgrade now by running \"az bicep upgrade\".\u001b[0m\n",
341341
"\u001b[?1h\u001b=\u001b[93m<repo-root>/08-agents/08-03-hosted-agents/main.bicep(41,9) : Warning BCP334: The provided value can have a length as small as 3 and may be too short to assign to a target with a configured minimum length of 5. [https://aka.ms/bicep/core-diagnostics#BCP334]\n",
@@ -511,7 +511,7 @@
511511
"\u001b[93mWaiting for an agent...\u001b[0m\n",
512512
"2026/05/10 13:05:26 Downloading source code...\n",
513513
"2026/05/10 13:05:27 Finished downloading source code\n",
514-
"2026/05/10 13:05:27 Using acb_vol_def3c675-dcb8-438a-b726-37b613e7a5aa as the home volume\n",
514+
"2026/05/10 13:05:27 Using acb_vol_00000000-0000-0000-0000-000000000000 as the home volume\n",
515515
"2026/05/10 13:05:27 Setting up Docker configuration...\n",
516516
"2026/05/10 13:05:28 Successfully set up Docker configuration\n",
517517
"2026/05/10 13:05:28 Logging in to registry: acralphac2676f.azurecr.io\n",

08-agents/08-05-contoso-pmo-mcp/08-05-01-contoso-pmo-agent-setup.ipynb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -299,7 +299,7 @@
299299
" ERROR: Cannot change the site func-contoso-pmo-mcp-d55074 to the App Service Plan ASP-rgfoundrycontosopmomcp-e6cf due to hosting constraints.\n",
300300
" … waiting 30 s for managed identity to initialize...\n",
301301
"Assigning storage roles to managed identity...\n",
302-
" ✓ managed identity principal: 187581c6-b580-42c9-a030-01de0e898f4d\n",
302+
" ✓ managed identity principal: 00000000-0000-0000-0000-000000000000\n",
303303
" ✓ Storage Blob Data Owner\n",
304304
" ✓ Storage Queue Data Contributor\n",
305305
" ✓ Storage Table Data Contributor\n",

08-agents/08-05b-contoso-private-banking-mcp/08-05b-01-private-banking-agent-setup.ipynb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -259,7 +259,7 @@
259259
" ERROR: Cannot change the site func-private-banking-mcp-97aab2 to the App Service Plan ASP-rgfoundryprivatebankingmcp-c0e3 due to hosting constraints.\n",
260260
" … waiting 30 s for managed identity to initialize...\n",
261261
"Assigning storage roles to managed identity...\n",
262-
" ✓ managed identity principal: 67bc2a77-6ab1-4d78-b03a-16ccc0529bdd\n",
262+
" ✓ managed identity principal: 00000000-0000-0000-0000-000000000000\n",
263263
" ✓ Storage Blob Data Owner\n",
264264
" ✓ Storage Queue Data Contributor\n",
265265
" ✓ Storage Table Data Contributor\n",

08-agents/08-06-agent-offline-evaluation/08-06-05-results-and-portal.ipynb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -407,7 +407,7 @@
407407
"output_type": "stream",
408408
"text": [
409409
"View evaluation results in Foundry portal:\n",
410-
"https://ai.azure.com/resource/build/evaluation/3e864d4f-d92d-4182-a49f-f1118878762c?wsid=/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-foundry-core-c2676f/providers/Microsoft.CognitiveServices/accounts/aif-core-c2676f/projects/project-admin-c2676f&tid=b845d325-6786-435a-bc28-b326d9fcbe16\n"
410+
"https://ai.azure.com/resource/build/evaluation/00000000-0000-0000-0000-000000000000?wsid=/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-foundry-core-c2676f/providers/Microsoft.CognitiveServices/accounts/aif-core-c2676f/projects/project-admin-c2676f&tid=00000000-0000-0000-0000-000000000000\n"
411411
]
412412
},
413413
{

08-agents/08-07-agent-live-observability/08-07-01-deploy-observability-infra.ipynb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -119,7 +119,7 @@
119119
"name": "stdout",
120120
"output_type": "stream",
121121
"text": [
122-
"Principal ID: 5db0aa5d-f281-47a3-9720-04727dec61e8\n"
122+
"Principal ID: 00000000-0000-0000-0000-000000000000\n"
123123
]
124124
}
125125
],

12-foundry-iq-deep-research/12-01-deploy-o3-backend.ipynb

Lines changed: 144 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -41,10 +41,19 @@
4141
},
4242
{
4343
"cell_type": "code",
44-
"execution_count": null,
44+
"execution_count": 1,
4545
"id": "12010001-0000-0000-0000-000000000003",
4646
"metadata": {},
47-
"outputs": [],
47+
"outputs": [
48+
{
49+
"name": "stdout",
50+
"output_type": "stream",
51+
"text": [
52+
"Gateway URL : https://apim-foundry-c2676f.azure-api.net/openai\n",
53+
"Chat model : gpt-4.1-mini\n"
54+
]
55+
}
56+
],
4857
"source": [
4958
"import json\n",
5059
"import os\n",
@@ -81,11 +90,52 @@
8190
},
8291
{
8392
"cell_type": "code",
84-
"execution_count": null,
93+
"execution_count": 2,
8594
"id": "12010001-0000-0000-0000-000000000005",
8695
"metadata": {},
87-
"outputs": [],
88-
"source": "# Derive APIM name and suffix from GATEWAY_URL\n# e.g. https://apim-foundry-{suffix}.azure-api.net/openai -> apim-foundry-{suffix}\nAPIM_NAME = GATEWAY_URL.split('//')[1].split('.')[0]\nSUFFIX = APIM_NAME.split('-')[-1] # e.g. {suffix}\nCORE_RG = f'rg-foundry-core-{SUFFIX}'\n\n# Subscription ID + ARM base URI used by Steps 3 and 5 to call APIM management\n# endpoints directly via `az rest`. This avoids requiring the `az apim` CLI\n# extension, which is not bundled with the base Azure CLI.\nSUB_ID = subprocess.run(\n 'az account show --query id -o tsv', shell=True, capture_output=True, text=True\n).stdout.strip()\nAPIM_BASE_URI = (\n f'https://management.azure.com/subscriptions/{SUB_ID}'\n f'/resourceGroups/{CORE_RG}/providers/Microsoft.ApiManagement/service/{APIM_NAME}'\n)\n\n# Get deployer principal ID from cached JWT\ntoken = subprocess.run(\n 'az account get-access-token --query accessToken -o tsv',\n shell=True, capture_output=True, text=True\n).stdout.strip()\npadding = '=' * (4 - len(token.split('.')[1]) % 4)\nPRINCIPAL_ID = json.loads(base64.b64decode(token.split('.')[1] + padding))['oid']\n\nprint(f'APIM service : {APIM_NAME}')\nprint(f'Core RG : {CORE_RG}')\nprint(f'Subscription : {SUB_ID}')\nprint(f'Principal ID : {PRINCIPAL_ID}')"
96+
"outputs": [
97+
{
98+
"name": "stdout",
99+
"output_type": "stream",
100+
"text": [
101+
"APIM service : apim-foundry-c2676f\n",
102+
"Core RG : rg-foundry-core-c2676f\n",
103+
"Subscription : 00000000-0000-0000-0000-000000000000\n",
104+
"Principal ID : 00000000-0000-0000-0000-000000000000\n"
105+
]
106+
}
107+
],
108+
"source": [
109+
"# Derive APIM name and suffix from GATEWAY_URL\n",
110+
"# e.g. https://apim-foundry-{suffix}.azure-api.net/openai -> apim-foundry-{suffix}\n",
111+
"APIM_NAME = GATEWAY_URL.split('//')[1].split('.')[0]\n",
112+
"SUFFIX = APIM_NAME.split('-')[-1] # e.g. {suffix}\n",
113+
"CORE_RG = f'rg-foundry-core-{SUFFIX}'\n",
114+
"\n",
115+
"# Subscription ID + ARM base URI used by Steps 3 and 5 to call APIM management\n",
116+
"# endpoints directly via `az rest`. This avoids requiring the `az apim` CLI\n",
117+
"# extension, which is not bundled with the base Azure CLI.\n",
118+
"SUB_ID = subprocess.run(\n",
119+
" 'az account show --query id -o tsv', shell=True, capture_output=True, text=True\n",
120+
").stdout.strip()\n",
121+
"APIM_BASE_URI = (\n",
122+
" f'https://management.azure.com/subscriptions/{SUB_ID}'\n",
123+
" f'/resourceGroups/{CORE_RG}/providers/Microsoft.ApiManagement/service/{APIM_NAME}'\n",
124+
")\n",
125+
"\n",
126+
"# Get deployer principal ID from cached JWT\n",
127+
"token = subprocess.run(\n",
128+
" 'az account get-access-token --query accessToken -o tsv',\n",
129+
" shell=True, capture_output=True, text=True\n",
130+
").stdout.strip()\n",
131+
"padding = '=' * (4 - len(token.split('.')[1]) % 4)\n",
132+
"PRINCIPAL_ID = json.loads(base64.b64decode(token.split('.')[1] + padding))['oid']\n",
133+
"\n",
134+
"print(f'APIM service : {APIM_NAME}')\n",
135+
"print(f'Core RG : {CORE_RG}')\n",
136+
"print(f'Subscription : {SUB_ID}')\n",
137+
"print(f'Principal ID : {PRINCIPAL_ID}')"
138+
]
89139
},
90140
{
91141
"cell_type": "markdown",
@@ -97,11 +147,34 @@
97147
},
98148
{
99149
"cell_type": "code",
100-
"execution_count": null,
150+
"execution_count": 3,
101151
"id": "12010001-0000-0000-0000-000000000007",
102152
"metadata": {},
103-
"outputs": [],
104-
"source": "check = subprocess.run(\n f'az rest --method GET'\n f' --uri \"{APIM_BASE_URI}/backends/openai-research?api-version=2024-06-01-preview\"'\n f' -o none',\n shell=True, capture_output=True, text=True\n)\nBACKEND_EXISTS = check.returncode == 0\n\nif BACKEND_EXISTS:\n print('✅ openai-research APIM backend already exists - skipping Bicep deployment.')\n print(' Proceeding to read existing resources.')\nelse:\n print('ℹ️ openai-research backend not found - will deploy main.bicep.')"
153+
"outputs": [
154+
{
155+
"name": "stdout",
156+
"output_type": "stream",
157+
"text": [
158+
"✅ openai-research APIM backend already exists - skipping Bicep deployment.\n",
159+
" Proceeding to read existing resources.\n"
160+
]
161+
}
162+
],
163+
"source": [
164+
"check = subprocess.run(\n",
165+
" f'az rest --method GET'\n",
166+
" f' --uri \"{APIM_BASE_URI}/backends/openai-research?api-version=2024-06-01-preview\"'\n",
167+
" f' -o none',\n",
168+
" shell=True, capture_output=True, text=True\n",
169+
")\n",
170+
"BACKEND_EXISTS = check.returncode == 0\n",
171+
"\n",
172+
"if BACKEND_EXISTS:\n",
173+
" print('✅ openai-research APIM backend already exists - skipping Bicep deployment.')\n",
174+
" print(' Proceeding to read existing resources.')\n",
175+
"else:\n",
176+
" print('ℹ️ openai-research backend not found - will deploy main.bicep.')"
177+
]
105178
},
106179
{
107180
"cell_type": "markdown",
@@ -115,10 +188,18 @@
115188
},
116189
{
117190
"cell_type": "code",
118-
"execution_count": null,
191+
"execution_count": 4,
119192
"id": "12010001-0000-0000-0000-000000000009",
120193
"metadata": {},
121-
"outputs": [],
194+
"outputs": [
195+
{
196+
"name": "stdout",
197+
"output_type": "stream",
198+
"text": [
199+
"ℹ️ Skipped (backend already exists)\n"
200+
]
201+
}
202+
],
122203
"source": [
123204
"if not BACKEND_EXISTS:\n",
124205
" result = subprocess.run(\n",
@@ -152,11 +233,48 @@
152233
},
153234
{
154235
"cell_type": "code",
155-
"execution_count": null,
236+
"execution_count": 5,
156237
"id": "12010001-0000-0000-0000-000000000011",
157238
"metadata": {},
158-
"outputs": [],
159-
"source": "# Try the dedicated deep research subscription first; fall back to the alpha\n# subscription if it doesn't exist yet. Uses `az rest` against ARM directly,\n# matching the pattern in 10-01 and 11-01, so the `az apim` extension is not needed.\ndef _list_apim_subscription_key(sub_name: str) -> str | None:\n r = subprocess.run(\n f'az rest --method POST'\n f' --uri \"{APIM_BASE_URI}/subscriptions/{sub_name}/listSecrets?api-version=2024-06-01-preview\"'\n f' --query primaryKey -o tsv',\n shell=True, capture_output=True, text=True\n )\n return r.stdout.strip() if r.returncode == 0 and r.stdout.strip() else None\n\nDR_GATEWAY_KEY = _list_apim_subscription_key('foundry-gateway-dr')\nif DR_GATEWAY_KEY:\n print('✅ Using foundry-gateway-dr subscription key')\nelse:\n DR_GATEWAY_KEY = _list_apim_subscription_key('foundry-gateway-alpha')\n if DR_GATEWAY_KEY:\n print('ℹ️ Using foundry-gateway-alpha subscription key (fallback)')\n else:\n raise RuntimeError('Could not retrieve APIM subscription key. Check az login and core RG.')\n\nDR_MODEL = 'o3-deep-research'\n\nprint(f'DR model : {DR_MODEL}')\nprint(f'DR key : {DR_GATEWAY_KEY[:4]}... (hidden)')"
239+
"outputs": [
240+
{
241+
"name": "stdout",
242+
"output_type": "stream",
243+
"text": [
244+
"ℹ️ Using foundry-gateway-alpha subscription key (fallback)\n",
245+
"DR model : o3-deep-research\n",
246+
"DR key : 8382... (hidden)\n"
247+
]
248+
}
249+
],
250+
"source": [
251+
"# Try the dedicated deep research subscription first; fall back to the alpha\n",
252+
"# subscription if it doesn't exist yet. Uses `az rest` against ARM directly,\n",
253+
"# matching the pattern in 10-01 and 11-01, so the `az apim` extension is not needed.\n",
254+
"def _list_apim_subscription_key(sub_name: str) -> str | None:\n",
255+
" r = subprocess.run(\n",
256+
" f'az rest --method POST'\n",
257+
" f' --uri \"{APIM_BASE_URI}/subscriptions/{sub_name}/listSecrets?api-version=2024-06-01-preview\"'\n",
258+
" f' --query primaryKey -o tsv',\n",
259+
" shell=True, capture_output=True, text=True\n",
260+
" )\n",
261+
" return r.stdout.strip() if r.returncode == 0 and r.stdout.strip() else None\n",
262+
"\n",
263+
"DR_GATEWAY_KEY = _list_apim_subscription_key('foundry-gateway-dr')\n",
264+
"if DR_GATEWAY_KEY:\n",
265+
" print('✅ Using foundry-gateway-dr subscription key')\n",
266+
"else:\n",
267+
" DR_GATEWAY_KEY = _list_apim_subscription_key('foundry-gateway-alpha')\n",
268+
" if DR_GATEWAY_KEY:\n",
269+
" print('ℹ️ Using foundry-gateway-alpha subscription key (fallback)')\n",
270+
" else:\n",
271+
" raise RuntimeError('Could not retrieve APIM subscription key. Check az login and core RG.')\n",
272+
"\n",
273+
"DR_MODEL = 'o3-deep-research'\n",
274+
"\n",
275+
"print(f'DR model : {DR_MODEL}')\n",
276+
"print(f'DR key : {DR_GATEWAY_KEY[:4]}... (hidden)')"
277+
]
160278
},
161279
{
162280
"cell_type": "markdown",
@@ -168,10 +286,20 @@
168286
},
169287
{
170288
"cell_type": "code",
171-
"execution_count": null,
289+
"execution_count": 6,
172290
"id": "12010001-0000-0000-0000-000000000013",
173291
"metadata": {},
174-
"outputs": [],
292+
"outputs": [
293+
{
294+
"name": "stdout",
295+
"output_type": "stream",
296+
"text": [
297+
"✅ .env updated:\n",
298+
" DR_MODEL=o3-deep-research\n",
299+
" DR_GATEWAY_KEY=8382...\n"
300+
]
301+
}
302+
],
175303
"source": [
176304
"lines = env_file.read_text().splitlines() if env_file.exists() else []\n",
177305
"\n",
@@ -225,4 +353,4 @@
225353
},
226354
"nbformat": 4,
227355
"nbformat_minor": 5
228-
}
356+
}

0 commit comments

Comments
 (0)