Sitelet https://github.com/IntelliTect/EssentialCSharp.Web/tags
Skip to content

Tags: IntelliTect/EssentialCSharp.Web

Tags

deployed/prod/77c809fb855c55201e9374df76a82f8946066e85

Toggle deployed/prod/77c809fb855c55201e9374df76a82f8946066e85's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix: correlate browser and server app insights (#1263)

## Why

Application Insights was splitting browser-initiated flows from the
ASP.NET Core backend, which made it difficult to inspect a single
end-to-end trace for chat and TryDotNet interactions. This change aligns
the browser and server telemetry on the same W3C trace id so Application
Insights can show one correlated request flow.

## What changed

- re-enabled browser dependency tracking in the App Insights JS setup
and configured it for W3C distributed tracing
- allowed correlation headers for the site host and the configured
TryDotNet host so same-origin and TryDotNet requests can stay on the
same trace
- added `traceparent` propagation on the chat stream request and listing
source fetches
- kept the existing TryDotNet `correlationContext` bridge so TryDotNet
session creation can continue to join the browser trace during the
transition

## Notes for reviewers

The main tradeoff here is intentional: this restores browser-side
dependency telemetry that had previously been disabled to reduce noise.
That follows the Microsoft Learn guidance more closely and is what
enables the end-to-end trace view. The TryDotNet support includes a
small project-specific compatibility layer in addition to the standard
App Insights/OpenTelemetry propagation path.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

deployed/prod/ffaa95d91944de1240660626ecf4103dd0d4752f

Toggle deployed/prod/ffaa95d91944de1240660626ecf4103dd0d4752f's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
ci: simplify deploy workflows — Terraform owns Container App config, …

…CI owns image version (#1081)

## Summary

Now that Terraform manages the Container App configuration, the deploy
jobs no longer need to re-configure identity, registry, secrets, or env
vars on every run. This PR strips those steps and adds production
hardening.

## What changed

### Removed (Terraform owns these now)
- `az containerapp identity assign` — UAMI is set in Terraform HCL
- `az containerapp registry set` — ACR pull via managed identity is in
Terraform HCL
- `az containerapp secret set` — all Key Vault secret refs are in
Terraform HCL
- `--replace-env-vars` on `az containerapp update` — env vars are in
Terraform HCL

### Changed
- `deploy-development`: now just loads artifact → pushes to dev ACR →
`az containerapp update --image :sha`
- `deploy-production`: replaced artifact download + push with **`az acr
import`** (server-side copy from dev ACR to prod ACR — faster, no large
artifact download)
- Build job: removed prod registry tags (image only goes to dev ACR at
build time; prod gets it via import)

### Added (production hardening)
- Deploy by **image digest** (`@sha256:...`) instead of mutable tag —
immutable reference
- **Post-deploy image verification** — reads deployed image from
Container App, asserts it matches expected digest; catches silent
rollback if Terraform recreates the resource
- **Smoke test** — `curl --fail /health` on the Container App FQDN
- **Git deploy tag** — `deployed/prod/<sha>` pushed to repo as a durable
audit record

## Prerequisites (confirm before merging)

Verify Terraform HCL for the web Container App has all of:
- [ ] `identity { user_assigned_identity_ids = [...] }` — UAMI attached
- [ ] `registry { ... identity = uami_id }` — ACR pull via managed
identity
- [ ] All 14 secrets as Key Vault refs under `secret {
key_vault_secret_uri }`
- [ ] All env vars under `template.container.env`
- [ ] OIDC identity has `AcrPush` (or `AcrImporter`) on **prod ACR** for
`az acr import`

## RBAC note

The OIDC identity for this repo needs `AcrPush` on the prod ACR in
addition to the dev ACR — `az acr import` writes to prod. Terraform
should own this role assignment.

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>