bug: Cognitive Services OpenAI User role not assigned to managed identity — 401 on all chat completions
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 58/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- azure
調査の方向性
コンテナー アプリのシステム割り当てマネージド ID と AZURE_OPENAI_AUTH=managed-identity を設定する Bicep 構成を特定します。まず、Azure OpenAI リソースとコンテナー アプリの依存関係をたどります。必要な順序付けで Cognitive Services OpenAI User ロールの割り当てを追加し、その後、RBAC の伝播後にデプロイ済みのアプリがチャット要求を完了できることを確認します。
索引モデルが issue の本文から書いたものです。
説明
Summary
After a successful devclaw up / devclaw deploy, the container starts and the gateway reports ready — but every chat message fails with a 401. The container app's managed identity is never granted the Cognitive Services OpenAI User role on the Azure OpenAI resource.
Error seen in container logs
[agent/embedded] embedded run agent end: isError=true model=gpt-5.4-mini
error=LLM request failed. rawError=401 The principal `<principalId>` lacks
the required data action `Microsoft.CognitiveServices/accounts/OpenAI/
deployments/chat/completions/action` to perform
`POST /openai/v1/chat/completions` operation.
Steps to reproduce
- Complete
devclaw up(even successfully) - Open the WebChat UI — gateway shows Online, model shows
gpt-5.4-mini - Send any message
- Assistant returns
[assistant turn failed before producing content] - Container logs show 401 on every
/openai/v1/chat/completionscall
Root cause
Same pattern as the AcrPull gap. Bicep configures the container app to use AZURE_OPENAI_AUTH=managed-identity but does not create the Cognitive Services OpenAI User role assignment on the Azure OpenAI resource for the container app's principalId. The gateway has no API key to fall back to (by design), so every model call fails.
Expected behaviour
Bicep should create a Cognitive Services OpenAI User role assignment on the Azure OpenAI resource for the container app's system-assigned managed identity, with correct dependsOn so it is in place before the first request.
Manual workaround
PRINCIPAL_ID=$(az containerapp show -n <app> -g <rg> --query 'identity.principalId' -o tsv)
OPENAI_ID=$(az cognitiveservices account list -g <rg> --query '[0].id' -o tsv)
az role assignment create \
--assignee-object-id $PRINCIPAL_ID \
--assignee-principal-type ServicePrincipal \
--role "Cognitive Services OpenAI User" \
--scope $OPENAI_ID
Note: RBAC propagation takes ~90 seconds after assignment. The gateway does not need to be restarted.
Related
Same root cause as #22 (AcrPull not assigned). Both point to Bicep RBAC sequencing gaps that surface when azd up exits before full propagation.
Environment
- Region:
southindia - Restricted corporate subscription with Azure Policy assignments active
- 主要言語
- Shell
- スター
- 25
- フォーク
- 3
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
microsoft/openclaw-dev のほかの issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
microsoft/openclaw-dev#34 ·
-
bug: BOOTSTRAP.md write fails in ephemeral fallback mode (SKIP_STORAGE=true / no Azure Files mount)オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
microsoft/openclaw-dev#24 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 88/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 25/100
microsoft/openclaw-dev#35 ·
-
難易度 4/5 3〜5日 初心者へのやさしさ 55/100
microsoft/openclaw-dev#22 ·
microsoft/openclaw-dev の issue をすべて見る
似ている issue
-
docs(evals): note CLAUDE_CODE_PRINT_BG_WAIT_CEILING_MS for headless eval runs that use workflowsオープンgood first issue needs-triage priority: low
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
melodic-software/claude-code-plugins#7022 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
ready
難易度 2/5 1〜3時間 初心者へのやさしさ 92/100
kubeflow/pipelines#14784 · コメント 1 件 ·
メンテナーはふだん 2 日以内に返信
-
implement-spec: step 9 cleanup collides with branch -D guards and with rewritten integration historyオープンneeds-triage
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
mattpocock/skills#1251 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
NuSkooler/enigma-bbs#907 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 70/100
community-scripts/ProxmoxVE#17841 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信