Tags: IntelliTect/EssentialCSharp.Web
Tags
fix: correlate browser and server app insights (#1263) ## Why Application Insights was splitting browser-initiated flows from the ASP.NET Core backend, which made it difficult to inspect a single end-to-end trace for chat and TryDotNet interactions. This change aligns the browser and server telemetry on the same W3C trace id so Application Insights can show one correlated request flow. ## What changed - re-enabled browser dependency tracking in the App Insights JS setup and configured it for W3C distributed tracing - allowed correlation headers for the site host and the configured TryDotNet host so same-origin and TryDotNet requests can stay on the same trace - added `traceparent` propagation on the chat stream request and listing source fetches - kept the existing TryDotNet `correlationContext` bridge so TryDotNet session creation can continue to join the browser trace during the transition ## Notes for reviewers The main tradeoff here is intentional: this restores browser-side dependency telemetry that had previously been disabled to reduce noise. That follows the Microsoft Learn guidance more closely and is what enables the end-to-end trace view. The TryDotNet support includes a small project-specific compatibility layer in addition to the standard App Insights/OpenTelemetry propagation path. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
ci: simplify deploy workflows — Terraform owns Container App config, … …CI owns image version (#1081) ## Summary Now that Terraform manages the Container App configuration, the deploy jobs no longer need to re-configure identity, registry, secrets, or env vars on every run. This PR strips those steps and adds production hardening. ## What changed ### Removed (Terraform owns these now) - `az containerapp identity assign` — UAMI is set in Terraform HCL - `az containerapp registry set` — ACR pull via managed identity is in Terraform HCL - `az containerapp secret set` — all Key Vault secret refs are in Terraform HCL - `--replace-env-vars` on `az containerapp update` — env vars are in Terraform HCL ### Changed - `deploy-development`: now just loads artifact → pushes to dev ACR → `az containerapp update --image :sha` - `deploy-production`: replaced artifact download + push with **`az acr import`** (server-side copy from dev ACR to prod ACR — faster, no large artifact download) - Build job: removed prod registry tags (image only goes to dev ACR at build time; prod gets it via import) ### Added (production hardening) - Deploy by **image digest** (`@sha256:...`) instead of mutable tag — immutable reference - **Post-deploy image verification** — reads deployed image from Container App, asserts it matches expected digest; catches silent rollback if Terraform recreates the resource - **Smoke test** — `curl --fail /health` on the Container App FQDN - **Git deploy tag** — `deployed/prod/<sha>` pushed to repo as a durable audit record ## Prerequisites (confirm before merging) Verify Terraform HCL for the web Container App has all of: - [ ] `identity { user_assigned_identity_ids = [...] }` — UAMI attached - [ ] `registry { ... identity = uami_id }` — ACR pull via managed identity - [ ] All 14 secrets as Key Vault refs under `secret { key_vault_secret_uri }` - [ ] All env vars under `template.container.env` - [ ] OIDC identity has `AcrPush` (or `AcrImporter`) on **prod ACR** for `az acr import` ## RBAC note The OIDC identity for this repo needs `AcrPush` on the prod ACR in addition to the dev ACR — `az acr import` writes to prod. Terraform should own this role assignment. --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>