Azure-Samples / Azure-Samples/rag-data-openai-python-promptflow

Endpoint deployment error due to principal roles given to unfound resources in the RG

Open
#40 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
Python
Stars
290
Forks
152
PR merge metrics
No merged PRs in 30d

Description

Error when deploying as an endpoint to AI Studio.

Cause: Setting roles for AOAI and AI Search throws the error: Resources not found. The code gives roles based on the connection name, not the resource name.

**Resolution steps:**

1) Add to the provision.yaml:
AZURE_OPENAI_RESOURCE_NAME: "${aoai.aoai_resource_name}" # necessary for the endpoint deployment
AZURE_SEARCH_RESOURCE_NAME: "${search.search_resource_name}" # necessary for the endpoint deployment

This will update the env variables with the name of AOAI and AI Search Resources

2) Modify deploy.py to give roles based on the resource names (not the connection names as originally):

- for AOAI:

scope=f'''/subscriptions/{os.environ["AZURE_SUBSCRIPTION_ID"]}/resourceGroups/{os.environ["AZURE_RESOURCE_GROUP"]}/providers/Microsoft.CognitiveServices/accounts/{os.environ["AZURE_OPENAI_RESOURCE_NAME"]}''',
role_name="Cognitive Services OpenAI User",
principal_id=endpoint.identity.principal_id
)

- for AI Search: scope=f'''/subscriptions/{os.environ["AZURE_SUBSCRIPTION_ID"]}/resourceGroups/{os.environ["AZURE_RESOURCE_GROUP"]}/providers/Microsoft.Search/searchServices/{os.environ["AZURE_SEARCH_RESOURCE_NAME"]}''',
role_name="Search Index Data Contributor",
principal_id=endpoint.identity.principal_id
)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with provision.yaml to inspect the AOAI and AI Search resource-name environment variables, then review deploy.py where endpoint roles are assigned. Deploy the endpoint and verify that role scopes use the actual resource names and no resources-not-found error occurs.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, python
Domain
authorization, cloud
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.