Repository navigation
docs: launch readiness — known limitations + Az OpenAI prereq + trust tiers + vendored-fork workflow - #216
Merged
Pal Lakatos-Toth (pallakatos) merged 3 commits intoMay 5, 2026
Conversation
…iers, vendored-fork workflow Pre-launch documentation pass covering four soft spots flagged in the weakness audit. No code changes; pure docs. README.md - New "Known limitations" section between "Project status" and "Contributing & support". Calls out: anonymous-tier mesh default pending api://agentmesh provisioning, multi-runtime images not yet published to a public registry, Semantic Kernel + MAF .NET CRD-wired but adapter-incomplete, attestation router-and-audit only, no managed service equivalent. - Add a one-line callout under "Try it in five minutes" linking to the new Az OpenAI prereq snippet so first-time users without a deployment can self-serve. docs/getting-started.md - New "Don't have an Azure OpenAI deployment yet?" subsection under "Prerequisites" with three az commands (account create, deployment create, read endpoint+key) plus link to the official quickstart and pointer to azureclaw up for the Foundry-managed alternative. docs/security.md - New "Trust tiers and the api://agentmesh prerequisite" subsection under Layer 8. Tier table (Anonymous 0 vs Verified 600), explanation of why fail-open is the default, three resolution paths (lower threshold / provision app reg / set AGT_SKIP_ENTRA=1), the three log lines an operator may see at sandbox start, and the framing that none of them are errors. CONTRIBUTING.md - New "Working with the vendored AgentMesh forks" section between the credentials secret convention and Pull Requests. Two ground rules (upstream PR first, no quiet rebases past the audit gate), the dist/ overlay flow for the SDK, the Rust 1.94+ toolchain note for relay/ registry, and the copyright-header exclusion. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
The rest of the codebase (router, controller, CLI) integrates with Azure AI Foundry — not standalone Azure OpenAI accounts. The prereq snippet I added in the previous commit used --kind OpenAI, which is inconsistent with how azureclaw up provisions things and with the 18 Foundry API groups the router actually proxies. - docs/getting-started.md: rename subsection to "Don't have an Azure AI Foundry deployment yet?", switch --kind to AIServices, explain why (Content Safety, Memory Store, agents, the rest of the AI Services surface), point to the Foundry quickstart instead of the Azure OpenAI quickstart. - docs/getting-started.md prereq table: clarify "Azure AI Foundry (or Azure OpenAI)" to match — local mode still accepts a bare AOAI endpoint, but Foundry is the recommended shape. - README.md: update the cross-link anchor to match the renamed heading (#dont-have-an-azure-ai-foundry-deployment-yet). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Once PR #218 lands, the trust-tier staleness statement 'the controller and CLI do not perform it for you' becomes wrong. Update the three spots that talked about manual provisioning to point at the new CLI helper instead, while keeping docs/permissions.md as the canonical home for the underlying 'az ad app create' invocation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Pal Lakatos-Toth (pallakatos)
deleted the
launch-readiness-docs-and-trust-tiers
branch
May 5, 2026 09:53
Pal Lakatos-Toth (pallakatos)
added a commit
that referenced
this pull request
May 12, 2026
… tiers + vendored-fork workflow (#216) * docs: launch readiness — known limitations, Az OpenAI prereq, trust tiers, vendored-fork workflow Pre-launch documentation pass covering four soft spots flagged in the weakness audit. No code changes; pure docs. README.md - New "Known limitations" section between "Project status" and "Contributing & support". Calls out: anonymous-tier mesh default pending api://agentmesh provisioning, multi-runtime images not yet published to a public registry, Semantic Kernel + MAF .NET CRD-wired but adapter-incomplete, attestation router-and-audit only, no managed service equivalent. - Add a one-line callout under "Try it in five minutes" linking to the new Az OpenAI prereq snippet so first-time users without a deployment can self-serve. docs/getting-started.md - New "Don't have an Azure OpenAI deployment yet?" subsection under "Prerequisites" with three az commands (account create, deployment create, read endpoint+key) plus link to the official quickstart and pointer to azureclaw up for the Foundry-managed alternative. docs/security.md - New "Trust tiers and the api://agentmesh prerequisite" subsection under Layer 8. Tier table (Anonymous 0 vs Verified 600), explanation of why fail-open is the default, three resolution paths (lower threshold / provision app reg / set AGT_SKIP_ENTRA=1), the three log lines an operator may see at sandbox start, and the framing that none of them are errors. CONTRIBUTING.md - New "Working with the vendored AgentMesh forks" section between the credentials secret convention and Pull Requests. Two ground rules (upstream PR first, no quiet rebases past the audit gate), the dist/ overlay flow for the SDK, the Rust 1.94+ toolchain note for relay/ registry, and the copyright-header exclusion. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: prereq snippet uses Foundry (AIServices), not legacy OpenAI The rest of the codebase (router, controller, CLI) integrates with Azure AI Foundry — not standalone Azure OpenAI accounts. The prereq snippet I added in the previous commit used --kind OpenAI, which is inconsistent with how azureclaw up provisions things and with the 18 Foundry API groups the router actually proxies. - docs/getting-started.md: rename subsection to "Don't have an Azure AI Foundry deployment yet?", switch --kind to AIServices, explain why (Content Safety, Memory Store, agents, the rest of the AI Services surface), point to the Foundry quickstart instead of the Azure OpenAI quickstart. - docs/getting-started.md prereq table: clarify "Azure AI Foundry (or Azure OpenAI)" to match — local mode still accepts a bare AOAI endpoint, but Foundry is the recommended shape. - README.md: update the cross-link anchor to match the renamed heading (#dont-have-an-azure-ai-foundry-deployment-yet). Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * docs: reference azureclaw mesh setup-trust as the canonical resolution Once PR #218 lands, the trust-tier staleness statement 'the controller and CLI do not perform it for you' becomes wrong. Update the three spots that talked about manual provisioning to point at the new CLI helper instead, while keeping docs/permissions.md as the canonical home for the underlying 'az ad app create' invocation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Pal Lakatos-Toth <pallakatos@github.com> Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Pre-launch documentation pass covering four soft spots flagged in the weakness audit. No code changes.
Why
We agreed in the audit table that of the five pre-launch weaknesses, four can be addressed entirely with documentation in the private repo today, without exposing any image registry or naming decision publicly:
api://agentmeshEntra app reg not provisioned in any tenant — sub-agents silently fall back to anonymous tierdocs/security.md+ entry in README's new "Known limitations"devmodeazsnippet indocs/getting-started.md+ cross-link from READMECONTRIBUTING.mdIssue #1 (private ACR public-401) is naming-blocked, deferred. Issue #2 (multi-runtime images never pushed to ACR) is now scoped as a one-shot operator action —
azureclaw push --buildagainst the dev ACR — and is called out in the new Known Limitations entry so users hit a clear message rather thanImagePullBackOff.What changed
README.md— new## Known limitationssection (5 bullets), one-line cross-link to the Az OpenAI prereq snippet under "Try it in five minutes".docs/getting-started.md— new### Don't have an Azure OpenAI deployment yet?subsection with threeazcommands.docs/security.md— new#### Trust tiers and the api://agentmesh prerequisitesubsection under Layer 8 (mesh): tier table, three resolution paths, the three log lines an operator may see at boot.CONTRIBUTING.md— new## Working with the vendored AgentMesh forkssection: upstream-PR ground rule, audit-gate behaviour, SDKdist/overlay flow, Rust 1.94+ note.Verification
git diff --stat→ 4 files, +85 / -0://collapsed inapi://agentmesh→apiagentmesh).Out of scope
api://agentmeshEntra app registration (per-tenant operator action).