Azure / Azure/azure-sdk-tools

[aw] Network Isolation Resolver Agent failed

Open
#15,749 0 comments 0 reactions 0 assignees View on GitHub
agentic-workflows
Dominant language
C#
Stars
135
Forks
260
Avg merge
3d 1h
Merged PRs (30d)
143

Description

### Workflow Failure

**Workflow:** [Network Isolation Resolver Agent](#)
**Branch:** NetworkIsolationResolverAgent
**Run:** https://github.com/Azure/azure-sdk-tools/actions/runs/26470099494

**🔒 Lock File Out of Sync**: The workflow could not start because its compiled lock file no longer matches the source markdown.

This means the workflow's `.md` file was edited but `gh aw compile` was not run afterwards to regenerate the corresponding `.lock.yml` file. The agent is prevented from running against a stale configuration to avoid unexpected behaviour.

**To fix**, recompile the workflow:

```bash
gh aw compile
```

Then commit and push the updated `.lock.yml` file.

More ways to recompile

**Using the gh-aw MCP server** (if configured):

```json
{ "tool": "compile", "arguments": { "validate": true } }
```

**Recompile all workflows at once:**

```bash
gh aw compile --all
```

**Verify the result:**

```bash
gh aw compile --validate
```

How to investigate the mismatch

The workflow run logs contain a verbose debug pass that shows exactly what was hashed. Search the **Check workflow lock file** step logs for lines starting with `[hash-debug]` to see:

- The raw frontmatter text that was used as input
- Any imported files that were included in the hash
- The canonical JSON that was fed to SHA-256
- The resulting hash value

This makes it easy to spot accidental whitespace changes, encoding differences, or import path drift.

This mismatch can also happen on a **fresh install** (even without any manual edits) if `gh aw add @` could not resolve the ref to an exact commit SHA during installation. In that case, rerun the add command with an exact SHA (or retry when API/rate-limit conditions recover), then recompile:

```bash
gh aw add @
gh aw compile
```

How to disable this check

> [!CAUTION]
> Disabling this check means the agent can run against an out-of-date compiled workflow. Only disable it if you have an alternative mechanism to keep lock files in sync.

Set `stale-check: false` in the `on:` section of your workflow frontmatter:

```yaml
on:
issues:
types: [opened]
stale-check: false
```

After editing, recompile the workflow: `gh aw compile`

### Action Required

**Assign this issue to Copilot** using the `agentic-workflows` sub-agent to automatically debug and fix the workflow failure.

Debug with any coding agent

Use this prompt with any coding agent (GitHub Copilot, Claude, Gemini, etc.):

````
Debug the agentic workflow failure using https://raw.githubusercontent.com/github/gh-aw/main/debug.md

The failed workflow run is at https://github.com/Azure/azure-sdk-tools/actions/runs/26470099494
````

Manually invoke the agent

Debug this workflow failure using your favorite Agent CLI and the `agentic-workflows` prompt.

- Start your agent
- Load the `agentic-workflows` prompt from `.github/agents/agentic-workflows.agent.md` or
- Type `debug the agentic workflow network-isolation-resolver-agent failure in https://github.com/Azure/azure-sdk-tools/actions/runs/26470099494`

> [!TIP]
>
> Stop reporting this workflow as a failure
>
> To stop a workflow from creating failure issues, set `report-failure-as-issue: false` in its frontmatter:
> ```yaml
> safe-outputs:
> report-failure-as-issue: false
> ```
>
>

> Generated from [Network Isolation Resolver Agent](https://github.com/Azure/azure-sdk-tools/actions/runs/26470099494/agentic_workflow) · [◷](https://github.com/search?q=repo%3AAzure%2Fazure-sdk-tools+is%3Aissue+%22gh-aw-workflow-id%3A+network-isolation-resolver-agent%22&type=issues)
> - [x] expires on Jun 2, 2026, 7:29 PM UTC

Contributor guide

Open the contributing guide

Research direction

Start with the Network Isolation Resolver Agent workflow and the failed run linked in the issue, then inspect the workflow's source markdown and corresponding lock file. Run `gh aw compile` followed by `gh aw compile --validate`; done means the compiled lock file matches the source and validation succeeds.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
ci-cd
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.