-
Notifications
You must be signed in to change notification settings - Fork 11
feat(samples): add Agent365 S2S observability demo #244
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Nikhil Navakiran (nikhilNava)
merged 10 commits into
main
from
feature/agent365-s2s-sample
Oct 1, 2026
Merged
Changes from all commits
Commits
Show all changes
10 commits
Select commit
Hold shift + click to select a range
ca2d9cc
feat(samples): add Agent365 S2S observability demo
nikhilc-microsoft a126d29
fix(samples): harden S2S refresh handling
nikhilc-microsoft 76ed13e
fix(a365): align correlation fallback
nikhilc-microsoft 528db2c
fix(samples): keep SDKStats dimensions unchanged
nikhilc-microsoft abb290b
fix(samples): complete Agent365 S2S span coverage
nikhilc-microsoft 4e77611
fix(samples): restore clean S2S build
nikhilc-microsoft 2559319
refactor(samples): use environment configuration
nikhilc-microsoft df5c13a
fix(samples): export deterministic Agent365 trace
nikhilc-microsoft b16a6e3
fix(samples): pin Agent365 token audience
nikhilc-microsoft 85b2d97
fix(samples): validate S2S credentials before tracing
nikhilc-microsoft File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,4 @@ | ||
| .env | ||
| dist/ | ||
| node_modules/ | ||
| .test-tmp/ |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,107 @@ | ||
| # Agent365 service-to-service observability sample | ||
|
|
||
| This standalone Node.js 22 sample publishes a deterministic agent trace to the | ||
| Agent365 service-to-service observability endpoint. It uses app-only | ||
| authentication; no interactive user sign-in or pre-generated bearer token is | ||
| required. | ||
|
|
||
| ## Prerequisites | ||
|
|
||
| - Node.js 22 or later. | ||
| - An Agent365 blueprint application with a client secret. | ||
| - An Agent365 agent application in the same Microsoft Entra tenant. | ||
| - The Agent365 agent application must have the | ||
| `Agent365.Observability.OtelWrite` application permission with tenant admin | ||
| consent. | ||
| - The blueprint and agent application must be configured for the Agent365 | ||
| federated managed identity (FMI) token-exchange flow. | ||
|
|
||
| Never commit `.env`. The included `.gitignore` excludes it. | ||
|
|
||
| ## Configure and run | ||
|
|
||
| Build the root distro first so the sample's local `file:../..` dependency can | ||
| resolve its generated package exports: | ||
|
|
||
| ```powershell | ||
| Set-Location ..\.. | ||
| npm ci | ||
| npm run build | ||
| Set-Location samples\agent365-s2s | ||
| ``` | ||
|
|
||
| Then configure and run the sample: | ||
|
|
||
| ```powershell | ||
| Copy-Item sample.env .env | ||
| npm ci | ||
| npm run build | ||
| npm start | ||
| ``` | ||
|
|
||
| Set every required value in `.env`: | ||
|
|
||
| | Variable | Description | | ||
| | ------------------------------ | ------------------------------------------------------------------------------------- | | ||
| | `A365_AUTHORITY` | HTTPS Microsoft Entra authority root, for example `https://login.microsoftonline.com` | | ||
| | `A365_BLUEPRINT_CLIENT_ID` | Blueprint application client ID | | ||
| | `A365_BLUEPRINT_CLIENT_SECRET` | Blueprint application client secret | | ||
| | `A365_TENANT_ID` | Microsoft Entra tenant ID | | ||
| | `A365_AGENT_ID` | Agent365 agent application client ID and FMI path | | ||
| | `A365_CLUSTER_CATEGORY` | Must be `prod` | | ||
|
|
||
| The sample rejects missing values, malformed GUIDs, non-HTTPS | ||
| authorities, and authorities containing tenant paths, queries, or fragments. | ||
| Configuration errors name only the invalid setting and never echo its value. | ||
|
|
||
| ## Authentication flow | ||
|
|
||
| The sample performs exactly two confidential-client requests: | ||
|
|
||
| 1. The blueprint application requests | ||
| `api://AzureADTokenExchange/.default`, using the configured `agentId` as | ||
| `fmiPath`. | ||
| 2. The returned blueprint token becomes the `clientAssertion` for the agent | ||
| application, which requests | ||
| `api://9b975845-388f-4429-889e-eab1ef63949c/.default`. | ||
|
|
||
| The final observability token is cached per normalized tenant/agent identity | ||
| and reused only while it expires more than 60 seconds in the future. | ||
| Concurrent refreshes share one request, and failed refreshes can be retried. | ||
|
|
||
| ## Expected telemetry | ||
|
|
||
| Each run creates exactly six spans in one trace and demonstrates all five | ||
| concrete manual scope types: | ||
|
|
||
| 1. `invoke_agent` for the complete synthetic request. | ||
| 2. `apply_guardrail` allowing the synthetic input. | ||
| 3. `Chat` inference selecting `lookup_weather`. | ||
| 4. `execute_tool` with deterministic synthetic arguments and result. | ||
| 5. `Chat` inference producing the final answer. | ||
| 6. `output_messages` recording the response sent to the caller. | ||
|
|
||
| All five child spans are direct children of `invoke_agent`. The run starts at | ||
| the current time and uses fixed relative offsets and durations. Published | ||
| agent, caller, user, conversation, message, guardrail, and tool values are | ||
| explicitly synthetic; only the configured tenant and agent IDs identify the | ||
| destination. | ||
|
|
||
| The distro is configured with `enableObservabilityExporter: true`, | ||
| `useS2SEndpoint: true`, the exact observability scope, and `prod` routing. The | ||
| sample shuts down the SDK after the scenario so queued telemetry is flushed | ||
| without a fixed sleep. | ||
|
|
||
| ## Safe diagnostics | ||
|
|
||
| The logger prints only preformatted messages and discards additional error | ||
| arguments. Tokens, client secrets, raw MSAL responses, exception messages, | ||
| nested errors, and stacks are never rendered. Authentication failures contain | ||
| only the failed stage and a sanitized MSAL error code. | ||
|
|
||
| The sample also reuses the repository's root Prettier and ESLint configuration: | ||
|
|
||
| ```powershell | ||
| npm run format | ||
| npm run lint | ||
| ``` |
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.