Skip to content

feat(samples): add Agent365 S2S observability demo - #244

Merged
Nikhil Navakiran (nikhilNava) merged 10 commits into
mainfrom
feature/agent365-s2s-sample
Oct 1, 2026
Merged

Nikhil Navakiran (nikhilNava) merged 10 commits into
mainfrom
feature/agent365-s2s-sample

Conversation

@nikhilNava

@nikhilNava Nikhil Navakiran (nikhilNava) commented Sep 15, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • add a self-contained Agent365 S2S sample with two-stage MSAL app-only authentication
  • add expiry-aware, single-flight token caching and secret-safe diagnostics
  • demonstrate all five concrete manual scope types in one deterministic trace: InvokeAgent, ApplyGuardrail, Inference, ExecuteTool, and Output
  • validate the standalone sample with format, lint, and build checks

Validation

  • sample format
  • sample lint
  • sample build

Tests are intentionally omitted because this PR adds only a sample app.

Parity with microsoft/opentelemetry-distro-dotnet#155. ETW logger changes are out of scope.

nikhilc-microsoft and others added 5 commits October 1, 2026 10:37
Add safe exporter success diagnostics, two-stage MSAL authentication, expiry-aware caching, deterministic manual telemetry, sample documentation, and CI validation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 9ccc29b9-bf5d-4725-be3b-c4276b233c4c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9ccc29b9-bf5d-4725-be3b-c4276b233c4c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9ccc29b9-bf5d-4725-be3b-c4276b233c4c
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 9ccc29b9-bf5d-4725-be3b-c4276b233c4c
Keep the PR sample-focused, demonstrate all manual scope types, and remove sample tests and changelog changes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The sample currently fails its added lint check and leaves complex token-cache behavior untested.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Adds a standalone Agent365 S2S observability sample demonstrating authenticated telemetry export and manual scopes.

Changes:

  • Implements two-stage MSAL authentication with token caching and safe diagnostics.
  • Emits a deterministic six-span trace covering all five manual scope types.
  • Adds configuration, documentation, and CI validation.
File Description
.github/​workflows/​pr-validation.yml Validates the sample in CI.
samples/​README.md Links the new sample.
samples/​agent365-s2s/​.gitignore Excludes secrets and build artifacts.
samples/​agent365-s2s/​README.md Documents setup, authentication, and telemetry.
samples/​agent365-s2s/​appsettings.example.json Provides configuration placeholders.
samples/​agent365-s2s/​package.json Defines dependencies and scripts.
samples/​agent365-s2s/​package-lock.json Locks sample dependencies.
samples/​agent365-s2s/​tsconfig.json Configures TypeScript compilation.
samples/​agent365-s2s/​src/​config.ts Loads and validates configuration.
samples/​agent365-s2s/​src/​index.ts Initializes and shuts down telemetry.
samples/​agent365-s2s/​src/​s2sTokenProvider.ts Implements token caching and refresh coalescing.
samples/​agent365-s2s/​src/​safeLogger.ts Prevents logging diagnostic arguments.
samples/​agent365-s2s/​src/​scenario.ts Generates the deterministic trace.
samples/​agent365-s2s/​src/​tokenExchangeClient.ts Performs two-stage MSAL token exchange.
Files not reviewed (1)
  • samples/agent365-s2s/package-lock.json: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread samples/agent365-s2s/src/index.ts Outdated
Comment thread samples/agent365-s2s/src/s2sTokenProvider.ts
Export the logger API consumed by the standalone sample and use its validated routing configuration.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3f6edb2d-96f7-4c61-a5f2-ba0ed8da48a2
Copilot AI balanced review requested due to automatic review settings October 1, 2026 17:26

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The mandatory changelog validation will fail until this feature receives a CHANGELOG.md entry.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (2)
Files not reviewed (1)
  • samples/agent365-s2s/package-lock.json: Generated file

Comment thread src/index.ts
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3f6edb2d-96f7-4c61-a5f2-ba0ed8da48a2
Copilot AI balanced review requested due to automatic review settings October 1, 2026 18:38

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Scope override handling can produce an incorrect token audience, and the required changelog update is absent.

Review effort: Balanced
Findings: 2 High severity

Open (2)
Files not reviewed (1)
  • samples/agent365-s2s/package-lock.json: Generated file
Previously missed (1)

In code that hasn't changed since last review

Medium severity Honor scope overrides when acquiring observability tokens

samples/​agent365-s2s/​src/​index.ts:34

authScopes can be replaced by the ambient A365_OBSERVABILITY_SCOPES_OVERRIDE (A365Configuration.ts:149-173), but this sample's resolver ignores the scopes argument and always acquires OBSERVABILITY_SCOPES. When that override is present, the exporter requests one audience while receiving a token for another. Use the higher-precedence single-scope option here, or make the exchange client honor/validate the supplied scopes.

Comment thread samples/README.md
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3f6edb2d-96f7-4c61-a5f2-ba0ed8da48a2
Copilot AI balanced review requested due to automatic review settings October 1, 2026 18:52

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The required changelog update or exemption label is missing.

Review effort: Balanced
Findings: 2 High severity

Open (2)
Files not reviewed (1)
  • samples/agent365-s2s/package-lock.json: Generated file

Prevent ambient scope overrides from making the exporter request a different audience than the sample token exchange.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3f6edb2d-96f7-4c61-a5f2-ba0ed8da48a2
Copilot AI balanced review requested due to automatic review settings October 1, 2026 19:14
@nikhilNava

Copy link
Copy Markdown
Collaborator Author

Addressed the previously missed scope-override finding in b16a6e3. The sample now uses observabilityScopeOverride for its fixed Agent365 observability audience, so an ambient A365_OBSERVABILITY_SCOPES_OVERRIDE cannot make the exporter request a different audience than the S2S token exchange.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Default durable replay can publish retained spans and undermine the sample’s deterministic behavior.

Review effort: Balanced
Findings: None

Resolved since last review (2)
Files not reviewed (1)
  • samples/agent365-s2s/package-lock.json: Generated file
Previously missed (1)

In code that hasn't changed since last review

Medium severity Disable durable delivery for deterministic self-contained demo

samples/​agent365-s2s/​src/​index.ts:39

Durable delivery defaults to enabled, so a failed run is spooled and replayed by later runs. That can publish retained spans in addition to the documented deterministic six-span trace and leaves state across executions. Disable durable delivery explicitly for this self-contained demo.

Comment thread samples/agent365-s2s/src/index.ts
Resolve and cache the observability token before initializing telemetry so invalid sample credentials reach the existing error handler.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 3f6edb2d-96f7-4c61-a5f2-ba0ed8da48a2
Copilot AI balanced review requested due to automatic review settings October 1, 2026 21:23

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Default durable replay can publish traces from earlier runs and violate the sample’s deterministic behavior.

Review effort: Balanced
Findings: None

Files not reviewed (1)
  • samples/agent365-s2s/package-lock.json: Generated file
Previously missed (1)

In code that hasn't changed since last review

Medium severity Disable durable delivery to preserve deterministic sample behavior

samples/​agent365-s2s/​src/​index.ts:38

The Agent365 exporter enables durable spool-and-replay by default. A failed run can therefore persist this sample's payload and a later run will replay it (and may perform additional token exchanges), so the documented single deterministic trace and “exactly two” confidential-client requests are not guaranteed. Disable durable delivery for this deterministic sample.

@nikhilNava
Nikhil Navakiran (nikhilNava) merged commit c8f50b7 into main Oct 1, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants