Skip to content

Add deploy-agent-aks-agentid + teardown-agent-aks-agentid skills (Entra SDK auth-sidecar on AKS) - #28

Draft
vj926 wants to merge 4 commits into
microsoft:mainfrom
vj926:vij/aks
Draft

Add deploy-agent-aks-agentid + teardown-agent-aks-agentid skills (Entra SDK auth-sidecar on AKS)#28
vj926 wants to merge 4 commits into
microsoft:mainfrom
vj926:vij/aks

Conversation

@vj926

@vj926 vj926 commented May 22, 2026

Copy link
Copy Markdown
Collaborator

Summary

Adds an Azure Kubernetes Service variant of the dev (Ollama) sidecar sample, alongside the existing Container Apps tutorial. Same architectural pattern, AKS-native primitives.

What's in this PR

  • deploy/azure/kubernetes-service/dev/README.md — Microsoft Learn-style walkthrough (~700 lines).

    • Phase 1 Entra app setup → Phase 2 Azure infra (AKS + ACR + OIDC issuer + Workload Identity addon) → Phase 3 Federated Identity Credential on the Blueprint app → Phase 4 Build → Phase 5 Deploy → Phase 6 Post-deploy Entra config → Phase 7 Verify.
    • Sections on cost, teardown, rotation, troubleshooting.
    • Appendix A: kind smoke test (no Azure required). Appendix B: docker-compose → k8s migration notes.
  • .claude/skills/deploy-agent-aks-dev/ — automated fast-path skill mirroring the layout of deploy-agent-aca-dev:

    • scripts/ — per-phase shell + PowerShell scripts, deploy-aks-dev.sh orchestrator, smoke-test-kind.sh.
    • manifests/ — six envsubst-rendered YAMLs (namespace, ServiceAccount, weather-api, Ollama, llm-agent, LoadBalancer).
    • references/ — SKU sizing, Workload Identity primer, cross-tenant federation, post-deploy manual steps, troubleshooting, non-Azure k8s portability notes.
  • .claude/skills/teardown-agent-aks-dev/ — matching teardown skill.

Architecture highlights

  • Secretless. Agent pod uses Azure Workload Identity (federated identity credential on the Blueprint app). No client secret in-cluster.
  • Federation subject: system:serviceaccount:agentid:agent-sa, audience api://AzureADTokenExchange, issuer = the AKS cluster's OIDC URL.
  • Cross-tenant supported. The Entra tenant (Blueprint + Agent apps) and the Azure subscription tenant (AKS + ACR) may differ. FIC trust is OIDC-URL-based and tenant-agnostic. Documented in §7.2 and references/cross-tenant-federation.md.
  • Default mode is autonomous (app-only). User-OBO via MSAL is documented as an optional add-on (§11.4 — accessed via kubectl port-forward to keep the browser in a secure-context for PKCE).

Validation

End-to-end validated on AKS Standard_D4s_v5 with Ollama llama3.2:3b. Tool-calling reliability table (references/sku-sizing.md) and four > [!WARNING] blocks in the tutorial document the silent-failure modes for under-sized models.

Conventions followed

  • Tutorial structure, frontmatter (ms.topic: tutorial), admonition style, and section ordering mirror deploy/azure/container-apps/dev/README.md.
  • Skill folder layout matches deploy-agent-aca-dev / teardown-agent-aca-dev.
  • No changes to shared sidecar/ source code.

Notes for reviewers

  • Sibling skill cross-links (deploy-agent-aca-dev, entra-agent-id-setup) point to skills already in this repo.
  • Two small unrelated runtime tweaks for the shared sidecar (Open-Meteo timeout/retry) are intentionally not in this PR — happy to file separately if useful.

Adds an AKS variant of the dev (Ollama) sidecar deployment alongside the
existing Azure Container Apps tutorial. Mirrors the upstream layout:

- deploy/azure/kubernetes-service/dev/README.md - Microsoft Learn-style
  walkthrough (Phase 1 Entra -> Phase 7 Verify, cost, teardown,
  troubleshooting, kind smoke-test appendix).
- .claude/skills/deploy-agent-aks-dev/ - automated fast-path skill
  (orchestrator, per-phase scripts, envsubst-rendered manifests,
  references covering SKU sizing, workload identity, cross-tenant
  federation, post-deploy manual steps, troubleshooting).
- .claude/skills/teardown-agent-aks-dev/ - matching teardown skill.

Key architectural points:
- Secretless: agent pod uses Azure Workload Identity (federated identity
  credential on the Blueprint app) to acquire tokens; no client secret in
  the cluster.
- Service account 'agent-sa' in namespace 'agentid' is the federation
  subject (system:serviceaccount:agentid:agent-sa).
- Cross-tenant supported: Entra tenant (Blueprint + Agent apps) and
  Azure subscription tenant (AKS + ACR) may differ; FIC trust is
  OIDC-URL-based.
- Default path is autonomous app-only auth; user-OBO is documented as an
  optional add-on via port-forward in section 11.4.

Validated end-to-end on an AKS Standard_D4s_v5 cluster with Ollama
llama3.2:3b. Tool-calling reliability table and SKU warnings document
the silent-failure modes for under-sized models.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
vj926 added a commit to vj926/AgentID-using-EntraSDK_AKS that referenced this pull request May 22, 2026
- Move manifests from sidecar/aks/manifests/ into
  .claude/skills/deploy-agent-aks-dev/manifests/ (matches upstream
  pattern: deployment artifacts live inside the skill).
- Add deploy/azure/kubernetes-service/dev/README.md - publication-grade
  walkthrough mirroring deploy/azure/container-apps/dev structure.
- Delete sidecar/aks/ entirely. Sidecar app source is shared and lives
  at sidecar/{dev,weather-api}/ upstream; per-deployment artifacts
  belong in the skill. The Open-Meteo timeout/retry patches that lived
  in sidecar/aks/{llm-agent,weather-api}-patched/ are preserved in git
  history and can be revived as a separate small PR.
- Update scripts (smoke-test-kind.sh, 04-apply-manifests.sh) and
  references (SKILL.md, non-azure-k8s.md, troubleshooting.md) to use
  the new manifests location.
- Drop patched-configmap logic from 04-apply-manifests.sh since the
  patched/ dirs are no longer shipped.

Upstream draft PR: microsoft/entra-agentid-samples#28

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…sent grant short-circuit

- references/obo-preflight-checklist.md (new): 12 pre-flight items the
  agentic CLI walks before enabling OBO — Microsoft.Graph module,
  admin role, the four GUIDs, SP existence, redirect URI match, secure
  context, AllPrincipals vs Principal consent decision, assignment
  gating, clean browser session. Plus 4 post-run verification rows.

- references/troubleshooting.md: rows for failure modes seen in real
  debugging — AADSTS500011 (Blueprint identifierUris empty / SP
  missing), silent PATCH rollback on platform-managed Blueprint,
  Connect-MgGraph not recognized (module missing),
  consentType=Principal trap masking a missing AllPrincipals grant,
  MSAL browser cache replay, assignment-required gating.

- scripts/grant-agent-obo-consent.ps1: fix early-return bug. The
  pre-existing-grant short-circuit matched any User.Read grant
  regardless of consentType, so a Principal-typed grant could mask
  a missing AllPrincipals grant and the script falsely reported
  success. It now only short-circuits on an AllPrincipals grant and
  warns when only a Principal grant exists.

- SKILL.md: link the new checklist from References.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
…entid

Aligns naming with the convention used elsewhere in the repo
(<verb>-agent-<host>-<flavor>) and disambiguates from the AUID variant
landing in PR microsoft#33 (deploy-agent-aks-auid). The 'dev' flavor slot is
replaced with the explicit identity flavor 'agentid'.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
vj926 added a commit to vj926/entra-agentid-samples that referenced this pull request Jun 10, 2026
Aligns with the repo's <verb>-agent-<host>-<flavor> naming used by
deploy-agent-aca-dev, deploy-agent-aca-aws, and (in PR microsoft#28)
deploy-agent-aks-agentid. The AUID variant occupies the 'auid' flavor
slot, mirroring how 'aws' differentiates the Bedrock variant of ACA.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@vj926 vj926 changed the title deploy: add Azure Kubernetes Service tutorial for sidecar dev sample Add deploy-agent-aks-agentid + teardown-agent-aks-agentid skills (Entra SDK auth-sidecar on AKS) Jun 10, 2026
@microsoft-github-policy-service

Copy link
Copy Markdown

vj926 please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.

@microsoft-github-policy-service agree [company="{your company}"]

Options:

  • (default - no company specified) I have sole ownership of intellectual property rights to my Submissions and I am not making Submissions in the course of work for my employer.
@microsoft-github-policy-service agree
  • (when company given) I am making Submissions in the course of work for my employer (or my employer has intellectual property rights in my Submissions by contract or applicable law). I have permission from my employer to make Submissions and enter into this Agreement on behalf of my employer. By signing below, the defined term “You” includes me and my employer.
@microsoft-github-policy-service agree company="Microsoft"
Contributor License Agreement

Contribution License Agreement

This Contribution License Agreement (“Agreement”) is agreed to by the party signing below (“You”),
and conveys certain license rights to Microsoft Corporation and its affiliates (“Microsoft”) for Your
contributions to Microsoft open source projects. This Agreement is effective as of the latest signature
date below.

  1. Definitions.
    “Code” means the computer software code, whether in human-readable or machine-executable form,
    that is delivered by You to Microsoft under this Agreement.
    “Project” means any of the projects owned or managed by Microsoft and offered under a license
    approved by the Open Source Initiative (www.opensource.org).
    “Submit” is the act of uploading, submitting, transmitting, or distributing code or other content to any
    Project, including but not limited to communication on electronic mailing lists, source code control
    systems, and issue tracking systems that are managed by, or on behalf of, the Project for the purpose of
    discussing and improving that Project, but excluding communication that is conspicuously marked or
    otherwise designated in writing by You as “Not a Submission.”
    “Submission” means the Code and any other copyrightable material Submitted by You, including any
    associated comments and documentation.
  2. Your Submission. You must agree to the terms of this Agreement before making a Submission to any
    Project. This Agreement covers any and all Submissions that You, now or in the future (except as
    described in Section 4 below), Submit to any Project.
  3. Originality of Work. You represent that each of Your Submissions is entirely Your original work.
    Should You wish to Submit materials that are not Your original work, You may Submit them separately
    to the Project if You (a) retain all copyright and license information that was in the materials as You
    received them, (b) in the description accompanying Your Submission, include the phrase “Submission
    containing materials of a third party:” followed by the names of the third party and any licenses or other
    restrictions of which You are aware, and (c) follow any other instructions in the Project’s written
    guidelines concerning Submissions.
  4. Your Employer. References to “employer” in this Agreement include Your employer or anyone else
    for whom You are acting in making Your Submission, e.g. as a contractor, vendor, or agent. If Your
    Submission is made in the course of Your work for an employer or Your employer has intellectual
    property rights in Your Submission by contract or applicable law, You must secure permission from Your
    employer to make the Submission before signing this Agreement. In that case, the term “You” in this
    Agreement will refer to You and the employer collectively. If You change employers in the future and
    desire to Submit additional Submissions for the new employer, then You agree to sign a new Agreement
    and secure permission from the new employer before Submitting those Submissions.
  5. Licenses.
  • Copyright License. You grant Microsoft, and those who receive the Submission directly or
    indirectly from Microsoft, a perpetual, worldwide, non-exclusive, royalty-free, irrevocable license in the
    Submission to reproduce, prepare derivative works of, publicly display, publicly perform, and distribute
    the Submission and such derivative works, and to sublicense any or all of the foregoing rights to third
    parties.
  • Patent License. You grant Microsoft, and those who receive the Submission directly or
    indirectly from Microsoft, a perpetual, worldwide, non-exclusive, royalty-free, irrevocable license under
    Your patent claims that are necessarily infringed by the Submission or the combination of the
    Submission with the Project to which it was Submitted to make, have made, use, offer to sell, sell and
    import or otherwise dispose of the Submission alone or with the Project.
  • Other Rights Reserved. Each party reserves all rights not expressly granted in this Agreement.
    No additional licenses or rights whatsoever (including, without limitation, any implied licenses) are
    granted by implication, exhaustion, estoppel or otherwise.
  1. Representations and Warranties. You represent that You are legally entitled to grant the above
    licenses. You represent that each of Your Submissions is entirely Your original work (except as You may
    have disclosed under Section 3). You represent that You have secured permission from Your employer to
    make the Submission in cases where Your Submission is made in the course of Your work for Your
    employer or Your employer has intellectual property rights in Your Submission by contract or applicable
    law. If You are signing this Agreement on behalf of Your employer, You represent and warrant that You
    have the necessary authority to bind the listed employer to the obligations contained in this Agreement.
    You are not expected to provide support for Your Submission, unless You choose to do so. UNLESS
    REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING, AND EXCEPT FOR THE WARRANTIES
    EXPRESSLY STATED IN SECTIONS 3, 4, AND 6, THE SUBMISSION PROVIDED UNDER THIS AGREEMENT IS
    PROVIDED WITHOUT WARRANTY OF ANY KIND, INCLUDING, BUT NOT LIMITED TO, ANY WARRANTY OF
    NONINFRINGEMENT, MERCHANTABILITY, OR FITNESS FOR A PARTICULAR PURPOSE.
  2. Notice to Microsoft. You agree to notify Microsoft in writing of any facts or circumstances of which
    You later become aware that would make Your representations in this Agreement inaccurate in any
    respect.
  3. Information about Submissions. You agree that contributions to Projects and information about
    contributions may be maintained indefinitely and disclosed publicly, including Your name and other
    information that You submit with Your Submission.
  4. Governing Law/Jurisdiction. This Agreement is governed by the laws of the State of Washington, and
    the parties consent to exclusive jurisdiction and venue in the federal courts sitting in King County,
    Washington, unless no federal subject matter jurisdiction exists, in which case the parties consent to
    exclusive jurisdiction and venue in the Superior Court of King County, Washington. The parties waive all
    defenses of lack of personal jurisdiction and forum non-conveniens.
  5. Entire Agreement/Assignment. This Agreement is the entire agreement between the parties, and
    supersedes any and all prior agreements, understandings or communications, written or oral, between
    the parties relating to the subject matter hereof. This Agreement may be assigned by Microsoft.

Addresses review feedback on PR microsoft#28:
- Replace mixed bash/PowerShell with PowerShell-only
- Rewrite teardown to remove all Entra objects created by setup
- Clean up SPA redirect URIs and k8s namespace during teardown

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant