From 5b7a9b2016d5c6f37f53bdcac3d191fe9ba4b305 Mon Sep 17 00:00:00 2001 From: Victor Barreto Date: Fri, 31 Jul 2026 11:06:17 +0100 Subject: [PATCH 1/6] Fix formatting of code block in prompt management documentation --- docs/02-prompt-management.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/02-prompt-management.md b/docs/02-prompt-management.md index b630223..819e9af 100644 --- a/docs/02-prompt-management.md +++ b/docs/02-prompt-management.md @@ -234,7 +234,7 @@ Next, deploy a second version with enhanced capabilities. To: ```python prompt_file = Path(__file__).parent / 'prompts' / 'v2_instructions.txt' - ``` + ``` 1. Run the agent creation script: From ac62ddfd65854b2dbeb7f618f1b178b1eeaab3c8 Mon Sep 17 00:00:00 2001 From: Victor Barreto Date: Fri, 31 Jul 2026 11:24:23 +0100 Subject: [PATCH 2/6] Update Azure CLI service principal creation command and improve error handling for subscription ID retrieval --- docs/04-automated-evaluation.md | 4 ++-- src/tests/check_traces.py | 7 ++++--- 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/docs/04-automated-evaluation.md b/docs/04-automated-evaluation.md index d5a6efc..0515de2 100644 --- a/docs/04-automated-evaluation.md +++ b/docs/04-automated-evaluation.md @@ -402,10 +402,10 @@ The evaluation script integrates with GitHub Actions to automatically run evalua Create a service principal for GitHub Actions: ```powershell - az ad sp create-for-rbac --name "github-agent-evaluator" + az ad sp create-for-rbac --name "github-agent-evaluator" --create-password false ``` - Save the `appId` and `tenant` values from the output. The workflow below uses OIDC federated credentials, so the generated `password` is not used in this lab. + Save the `appId` and `tenant` values from the output. The workflow below uses OIDC federated credentials, so the generated `password` is not used in this lab. The `--create-password false` flag is included because some Entra ID tenants enforce a baseline security policy (`Block new password credentials in apps`) that rejects password credential creation; skipping it avoids that policy error since OIDC doesn't need a password anyway. Assign the **Foundry User** role so the service principal can call the Foundry project API: diff --git a/src/tests/check_traces.py b/src/tests/check_traces.py index 1d7eb23..6ddaf30 100644 --- a/src/tests/check_traces.py +++ b/src/tests/check_traces.py @@ -11,7 +11,6 @@ from azure.identity import DefaultAzureCredential from azure.monitor.query import LogsQueryClient, LogsQueryStatus from azure.mgmt.applicationinsights import ApplicationInsightsManagementClient -from azure.mgmt.subscription import SubscriptionClient from azure.mgmt.loganalytics import LogAnalyticsManagementClient from azure.ai.projects import AIProjectClient from datetime import timedelta @@ -40,8 +39,10 @@ # Resolve Log Analytics workspace customer ID (required by LogsQueryClient) print("Resolving Log Analytics workspace...") -sub_client = SubscriptionClient(credential) -subscription_id = next(sub_client.subscriptions.list()).subscription_id +subscription_id = os.environ.get("AZURE_SUBSCRIPTION_ID") +if not subscription_id: + print("ERROR: AZURE_SUBSCRIPTION_ID not found in .env file.") + raise SystemExit(1) ai_mgmt = ApplicationInsightsManagementClient(credential, subscription_id) workspace_resource_id = None From fec62aee4b38aca7226c61e776486b8412edf625 Mon Sep 17 00:00:00 2001 From: Victor Barreto Date: Fri, 31 Jul 2026 05:18:02 -0700 Subject: [PATCH 3/6] Commit evaluation results --- evaluation_results.txt | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/evaluation_results.txt b/evaluation_results.txt index 7577fab..3992f8e 100644 --- a/evaluation_results.txt +++ b/evaluation_results.txt @@ -2,8 +2,8 @@ Trail Guide Agent - Evaluation Results ================================================================================ - Eval ID : eval_7c4c645fbe2c4e9e83d2c1b3af300106 - Run ID : evalrun_97c6ed6859324fc0bb01dce5df3ecb75 + Eval ID : eval_e1b291eef6594708946e002438131390 + Run ID : evalrun_fcf8a807fa9d49bbb95b32e9d78f0c5f Total items : 89 Errored items: 0 Scored items : 89 From 910333c0fd1bee1c71ba75d04006ea628327bbf0 Mon Sep 17 00:00:00 2001 From: Victor Barreto Date: Mon, 3 Aug 2026 15:59:45 +0100 Subject: [PATCH 4/6] Revert "Update Azure CLI service principal creation command and improve error handling for subscription ID retrieval" This reverts commit ac62ddfd65854b2dbeb7f618f1b178b1eeaab3c8. --- docs/04-automated-evaluation.md | 4 ++-- src/tests/check_traces.py | 7 +++---- 2 files changed, 5 insertions(+), 6 deletions(-) diff --git a/docs/04-automated-evaluation.md b/docs/04-automated-evaluation.md index 0515de2..d5a6efc 100644 --- a/docs/04-automated-evaluation.md +++ b/docs/04-automated-evaluation.md @@ -402,10 +402,10 @@ The evaluation script integrates with GitHub Actions to automatically run evalua Create a service principal for GitHub Actions: ```powershell - az ad sp create-for-rbac --name "github-agent-evaluator" --create-password false + az ad sp create-for-rbac --name "github-agent-evaluator" ``` - Save the `appId` and `tenant` values from the output. The workflow below uses OIDC federated credentials, so the generated `password` is not used in this lab. The `--create-password false` flag is included because some Entra ID tenants enforce a baseline security policy (`Block new password credentials in apps`) that rejects password credential creation; skipping it avoids that policy error since OIDC doesn't need a password anyway. + Save the `appId` and `tenant` values from the output. The workflow below uses OIDC federated credentials, so the generated `password` is not used in this lab. Assign the **Foundry User** role so the service principal can call the Foundry project API: diff --git a/src/tests/check_traces.py b/src/tests/check_traces.py index 6ddaf30..1d7eb23 100644 --- a/src/tests/check_traces.py +++ b/src/tests/check_traces.py @@ -11,6 +11,7 @@ from azure.identity import DefaultAzureCredential from azure.monitor.query import LogsQueryClient, LogsQueryStatus from azure.mgmt.applicationinsights import ApplicationInsightsManagementClient +from azure.mgmt.subscription import SubscriptionClient from azure.mgmt.loganalytics import LogAnalyticsManagementClient from azure.ai.projects import AIProjectClient from datetime import timedelta @@ -39,10 +40,8 @@ # Resolve Log Analytics workspace customer ID (required by LogsQueryClient) print("Resolving Log Analytics workspace...") -subscription_id = os.environ.get("AZURE_SUBSCRIPTION_ID") -if not subscription_id: - print("ERROR: AZURE_SUBSCRIPTION_ID not found in .env file.") - raise SystemExit(1) +sub_client = SubscriptionClient(credential) +subscription_id = next(sub_client.subscriptions.list()).subscription_id ai_mgmt = ApplicationInsightsManagementClient(credential, subscription_id) workspace_resource_id = None From 8b61b0820ec54f48cbb014aad26f1ae191648619 Mon Sep 17 00:00:00 2001 From: Victor Barreto Date: Mon, 3 Aug 2026 16:02:58 +0100 Subject: [PATCH 5/6] Remove evaluation results file --- evaluation_results.txt | 15 --------------- 1 file changed, 15 deletions(-) delete mode 100644 evaluation_results.txt diff --git a/evaluation_results.txt b/evaluation_results.txt deleted file mode 100644 index 3992f8e..0000000 --- a/evaluation_results.txt +++ /dev/null @@ -1,15 +0,0 @@ -================================================================================ - Trail Guide Agent - Evaluation Results -================================================================================ - - Eval ID : eval_e1b291eef6594708946e002438131390 - Run ID : evalrun_fcf8a807fa9d49bbb95b32e9d78f0c5f - Total items : 89 - Errored items: 0 - Scored items : 89 - -Average Scores (1-5 scale, threshold: 3) - No scores returned — open Azure AI Foundry portal > Evaluations for details. - -Pass Rates (score >= 3) - No scores returned. \ No newline at end of file From 6e923efe536a7f54d746338e3db8a2c11bd03a9d Mon Sep 17 00:00:00 2001 From: Victor Barreto Date: Fri, 4 Sep 2026 15:32:15 +0100 Subject: [PATCH 6/6] Update authentication instructions to recommend device code login for VS Code terminal issues --- docs/00-prerequisites.md | 7 +++++++ docs/01-infrastructure-setup.md | 6 +++--- docs/02-prompt-management.md | 4 ++-- docs/03-design-optimize-prompts.md | 4 ++-- docs/04-automated-evaluation.md | 4 ++-- docs/05-monitoring-tracing.md | 4 ++-- 6 files changed, 18 insertions(+), 11 deletions(-) diff --git a/docs/00-prerequisites.md b/docs/00-prerequisites.md index 9449ccc..48574a9 100644 --- a/docs/00-prerequisites.md +++ b/docs/00-prerequisites.md @@ -147,6 +147,13 @@ azd auth login Both commands will open a browser window for authentication. Sign in with your Azure credentials. +> ⚠️ **Important** +> In some environments, the VS Code integrated terminal may crash or close during the interactive login flow. +> If this happens, use device code authentication instead: +> ```bash +> az login --use-device-code +> ``` + ## Troubleshooting ### Common issues diff --git a/docs/01-infrastructure-setup.md b/docs/01-infrastructure-setup.md index 765e3bc..9bd3ebb 100644 --- a/docs/01-infrastructure-setup.md +++ b/docs/01-infrastructure-setup.md @@ -63,11 +63,11 @@ You'll use the Azure Developer CLI to deploy all required Azure resources using Sign in with your Azure credentials when prompted. This authentication is needed for the Python SDK and other Azure operations in subsequent labs. - > ⚠️ **Important ** + > ⚠️ **Important** > In some environments, the VS Code integrated terminal may crash or close during the interactive login flow. - > If this happens, authenticate using explicit credentials instead: + > If this happens, use device code authentication instead: > ```powershell - > az login --username --password + > az login --use-device-code > ``` 1. Provision resources: diff --git a/docs/02-prompt-management.md b/docs/02-prompt-management.md index 819e9af..790fd96 100644 --- a/docs/02-prompt-management.md +++ b/docs/02-prompt-management.md @@ -76,9 +76,9 @@ Now you'll use the Azure Developer CLI to deploy all required Azure resources. > ⚠️ **Important** > In some environments, the VS Code integrated terminal may crash or close during the interactive login flow. - > If this happens, authenticate using explicit credentials instead: + > If this happens, use device code authentication instead: > ```powershell - > az login --username --password + > az login --use-device-code > ``` 1. Provision resources: diff --git a/docs/03-design-optimize-prompts.md b/docs/03-design-optimize-prompts.md index eb27ce8..6ce5627 100644 --- a/docs/03-design-optimize-prompts.md +++ b/docs/03-design-optimize-prompts.md @@ -76,9 +76,9 @@ Now you'll use the Azure Developer CLI to deploy all required Azure resources. > ⚠️ **Important** > In some environments, the VS Code integrated terminal may crash or close during the interactive login flow. - > If this happens, authenticate using explicit credentials instead: + > If this happens, use device code authentication instead: > ```powershell - > az login --username --password + > az login --use-device-code > ``` 1. Provision resources: diff --git a/docs/04-automated-evaluation.md b/docs/04-automated-evaluation.md index d5a6efc..956cd14 100644 --- a/docs/04-automated-evaluation.md +++ b/docs/04-automated-evaluation.md @@ -82,9 +82,9 @@ Now you'll use the Azure Developer CLI to deploy all required Azure resources. > ⚠️ **Important** > In some environments, the VS Code integrated terminal may crash or close during the interactive login flow. - > If this happens, authenticate using explicit credentials instead: + > If this happens, use device code authentication instead: > ```powershell - > az login --username --password + > az login --use-device-code > ``` 1. Provision resources: diff --git a/docs/05-monitoring-tracing.md b/docs/05-monitoring-tracing.md index 3a5cbc6..d791847 100644 --- a/docs/05-monitoring-tracing.md +++ b/docs/05-monitoring-tracing.md @@ -81,9 +81,9 @@ Now you'll use the Azure Developer CLI to deploy all required Azure resources. > ⚠️ **Important** > In some environments, the VS Code integrated terminal may crash or close during the interactive login flow. - > If this happens, authenticate using explicit credentials instead: + > If this happens, use device code authentication instead: > ```powershell - > az login --username --password + > az login --use-device-code > ``` 1. Provision resources: