Repository navigation
Conversation
- add camera-onboarding.agent.md with full discovery and config generation phases - add example sparse input and full manifest YAML files - add camera discovery research topic and architecture concept docs - update agents README with camera-onboarding entry 📷 - Generated by Copilot
- enforce env var reference syntax for credentials in input validation - mandate secret-reference-only config output in Phase 5 - classify discovery manifests as confidential with gitignore guidance - add security classification header to generated manifest files - default output to untracked paths with gitignore recommendations 🔒 - Generated by Copilot
kgmwang1
requested review from
Marcel Bindseil (bindsi) and
Chris Montazer (rezatnoMsirhC)
June 26, 2026 14:49
- constrain discovery to explicitly approved scopes and preserve evidence states - authenticate ONVIF devices, inspect profiles, and verify decoded RTSP frames - generate schema-valid credential-free AIO Terraform proposals - add copy and download actions plus aligned agent and component guidance 📷 - Generated by Copilot Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- correct deterministic implementation and artifact paths - update the agent index to describe approved-scope onboarding - remove obsolete manifest examples that conflict with confidential local output 📷 - Generated by Copilot Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- document the implemented discovery, verification, and Terraform proposal architecture - capture rejected alternatives, security boundaries, and operational consequences - replace superseded RPI research and coaching artifacts 📷 - Generated by Copilot Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- restore the full single-node ONVIF example to the pull request baseline - keep camera onboarding output isolated from existing blueprint examples 📷 - Generated by Copilot Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
kgmwang1
marked this pull request as ready for review
October 8, 2026 22:38
📚 Documentation Health ReportGenerated on: 2026-10-08 22:39:44 UTC 📈 Documentation Statistics
🏗️ Three-Tree Architecture Status
🔍 Quality Metrics
This report is automatically generated by the Documentation Automation workflow. |
📚 Documentation Health ReportGenerated on: 2026-10-08 22:42:19 UTC 📈 Documentation Statistics
🏗️ Three-Tree Architecture Status
🔍 Quality Metrics
This report is automatically generated by the Documentation Automation workflow. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Implements a deterministic preflight and selection layer for RTSP/ONVIF camera onboarding. Engineers can discover candidates only within an explicitly approved network scope, authenticate selected ONVIF devices, inspect media profiles, verify a selected RTSP feed by receiving a decoded frame, and generate a reviewable Azure IoT Operations Terraform proposal.
Azure IoT Operations and Azure Device Registry remain the deployment source of truth. The dashboard keeps workflow state in memory, writes confidential local artifacts to a gitignored directory, and never applies Terraform.
Related Issue
Relates to #
Type of Change
Implementation Details
Camera Onboarding Workflow
The camera dashboard now provides an end-to-end onboarding preflight:
namespaced_devices,namespaced_assets, and Akri Media connector enablement values.The generated proposal includes stable names, credential-free RTSP endpoints, Kubernetes secret references, selected profile metadata, and only inspected capabilities. Duplicate logical endpoints are removed deterministically.
Dashboard and Output Experience
.camera-onboarding/directory:camera-discovery-results.jsonpreserves confidential evidence, statuses, and sanitized errors.camera-onboarding.tfvars.examplecontains the reviewable deployment proposal.terraform planorterraform apply.Camera Onboarding Agent (
.github/agents/camera-onboarding.agent.md)The agent now guides engineers through the checked-in deterministic dashboard implementation instead of generating speculative HCL. It requires approved scope, authenticated capability inspection, profile-specific frame verification, secure local output, and human review before deployment.
Terraform Contract Alignment
namespaced_devicesandnamespaced_assetstypes in the full single-node blueprint and111-assetscomponent.Supporting Materials
services/camera-dashboard/src/camera_onboarding.pyservices/camera-dashboard/src/camera_onboarding_ui.pyservices/camera-dashboard/src/onvif_discovery.py.github/agents/camera-onboarding.agent.mdproject-adrs/Draft/camera-onboarding-preflight.mdPrivacy & Security Mitigations
.camera-onboarding/, which is gitignored.Target Applications
Testing Performed
Validation Steps
python -m ruff checkon all changed camera dashboard Python modules — passed.python -m compileall -q src/500-application/510-onvif-connector/services/camera-dashboard/src— passed.markdownlinton changed component and dashboard documentation — passed.git diff --check— passed.camera-onboarding.tfvars.examplewith deterministic duplicate inputs and verified that credentials were removed — passed.terraform fmt -checkon the generated proposal — passed.terraform plan -refresh=falseagainst extracted authoritative blueprint variable contracts using the generated proposal — passed with no changes./24scope — candidate discovery completed, authenticated ONVIF capability inspection passed, and the selected RTSP profile received a decoded frame./healthendpoint after each runtime update — passed.The Docker image build was attempted but the environment's connection to
files.pythonhosted.orgfailed during dependency download with a TLS handshake error. Runtime validation used an isolated local virtual environment populated from the configured package feed.Checklist
Security Review
Additional Notes
The workflow produces a proposal for review only. Terraform and Azure IoT Operations remain the operational deployment path and source of truth.
🤖 Crafted with precision by ✨Copilot following brilliant human instruction,
then carefully refined by our team of discerning human reviewers.