Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

bug: Cognitive Services OpenAI User role not assigned to managed identity — 401 on all chat completions

オープン
#23 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
3/5
見積もり時間
1〜2日
初心者へのやさしさ
58/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
静か
技術スタック
azure

調査の方向性

コンテナー アプリのシステム割り当てマネージド ID と AZURE_OPENAI_AUTH=managed-identity を設定する Bicep 構成を特定します。まず、Azure OpenAI リソースとコンテナー アプリの依存関係をたどります。必要な順序付けで Cognitive Services OpenAI User ロールの割り当てを追加し、その後、RBAC の伝播後にデプロイ済みのアプリがチャット要求を完了できることを確認します。

索引モデルが issue の本文から書いたものです。

説明

Summary

After a successful devclaw up / devclaw deploy, the container starts and the gateway reports ready — but every chat message fails with a 401. The container app's managed identity is never granted the Cognitive Services OpenAI User role on the Azure OpenAI resource.

Error seen in container logs

[agent/embedded] embedded run agent end: isError=true model=gpt-5.4-mini
error=LLM request failed. rawError=401 The principal `<principalId>` lacks
the required data action `Microsoft.CognitiveServices/accounts/OpenAI/
deployments/chat/completions/action` to perform
`POST /openai/v1/chat/completions` operation.

Steps to reproduce

  1. Complete devclaw up (even successfully)
  2. Open the WebChat UI — gateway shows Online, model shows gpt-5.4-mini
  3. Send any message
  4. Assistant returns [assistant turn failed before producing content]
  5. Container logs show 401 on every /openai/v1/chat/completions call

Root cause

Same pattern as the AcrPull gap. Bicep configures the container app to use AZURE_OPENAI_AUTH=managed-identity but does not create the Cognitive Services OpenAI User role assignment on the Azure OpenAI resource for the container app's principalId. The gateway has no API key to fall back to (by design), so every model call fails.

Expected behaviour

Bicep should create a Cognitive Services OpenAI User role assignment on the Azure OpenAI resource for the container app's system-assigned managed identity, with correct dependsOn so it is in place before the first request.

Manual workaround

PRINCIPAL_ID=$(az containerapp show -n <app> -g <rg> --query 'identity.principalId' -o tsv)
OPENAI_ID=$(az cognitiveservices account list -g <rg> --query '[0].id' -o tsv)
az role assignment create \
  --assignee-object-id $PRINCIPAL_ID \
  --assignee-principal-type ServicePrincipal \
  --role "Cognitive Services OpenAI User" \
  --scope $OPENAI_ID

Note: RBAC propagation takes ~90 seconds after assignment. The gateway does not need to be restarted.

Related

Same root cause as #22 (AcrPull not assigned). Both point to Bicep RBAC sequencing gaps that surface when azd up exits before full propagation.

Environment

  • Region: southindia
  • Restricted corporate subscription with Azure Policy assignments active
主要言語
Shell
スター
25
フォーク
3
PR マージ指標
30日以内にマージされた PR はありません

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

microsoft/openclaw-dev のほかの issue

microsoft/openclaw-dev の issue をすべて見る

似ている issue

Shell/Bash の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。