Skip to content

Implement health checks for Azure AI Inference ChatCompletionsClient and EmbeddingsClient - #15969

Merged
Sébastien Ros (sebastienros) merged 10 commits into
microsoft:mainfrom
Formatted:add-azure-openai-inference-health-checks
Sep 2, 2026
Merged

Sébastien Ros (sebastienros) merged 10 commits into
microsoft:mainfrom
Formatted:add-azure-openai-inference-health-checks

Conversation

@Formatted

Copy link
Copy Markdown
Contributor

Description

ChatCompletionsClient and EmbeddingsClient registrations in Aspire.Azure.AI.Inference had GetHealthCheckEnabled hardcoded to false and CreateHealthCheck throwing NotImplementedException, meaning health checks were silently disabled for both client types regardless of configuration.

This PR adds AzureAIInferenceChatCompletionsHealthCheck and AzureAIInferenceEmbeddingsHealthCheck, which use the already-registered SDK clients to call GetModelInfoAsync() (a single read-only HTTP GET to /info), verifying endpoint connectivity. A DisableHealthChecks property is added to ChatCompletionsClientSettings to allow opt-out, consistent with the DisableMetrics/DisableTracing pattern. The conformance test SetHealthCheck override is also enabled.

AzureOpenAIClient health checks remain disabled — the Azure.AI.OpenAI SDK deliberately throws NotSupportedException on GetOpenAIModelClient(), and all other sub-clients require a deployment name and initiate real inference operations. The existing NotImplementedException is replaced with a NotSupportedException and an explanatory comment.

Fixes # (issue) — N/A, addressing existing NotImplementedException / hardcoded false


Checklist

  • Is this feature complete?
    • Yes. Ready to ship.
  • Are you including unit tests for the changes and scenario tests if relevant?
    • Yes — SetHealthCheck conformance tests enabled for ConformanceTests in Aspire.Azure.AI.Inference.Tests
  • Did you add public API?
    • Yes — DisableHealthChecks on ChatCompletionsClientSettings
      • Did you have an API Review for it?
        • Yes
        • No — property follows the established DisableMetrics/DisableTracing pattern on the same type; no new design decisions
      • Did you add <remarks /> and <code /> elements on your triple slash comments?
        • Yes
        • No — property is self-explanatory and consistent with sibling properties on the same class
  • Does the change make any security assumptions or guarantees?
    • No
  • Does the change require an update in our Aspire docs?
    • No

@github-actions

github-actions Bot commented Apr 8, 2026 •

Copy link
Copy Markdown
Contributor

🚀 Dogfood this PR with:

⚠️ WARNING: Do not do this without first carefully reviewing the code of this PR to satisfy yourself it is safe.

curl -fsSL https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.sh | bash -s -- 15969

Or

  • Run remotely in PowerShell:
iex "& { $(irm https://raw.githubusercontent.com/microsoft/aspire/main/eng/scripts/get-aspire-cli-pr.ps1) } 15969"

@Formatted

Copy link
Copy Markdown
Contributor Author

@microsoft-github-policy-service agree

@IEvangelist

David Pine (IEvangelist) commented May 20, 2026 •

Copy link
Copy Markdown
Member

PR testing report

PR: #15969 - Implement health checks for Azure AI Inference ChatCompletionsClient and EmbeddingsClient
Head commit: 5eaa723f86ae8a697252f2ea5568d6b38735df33
Result: Blocked - no PR dogfood CLI artifact could be located

CLI version verification

The PR dogfood installer was invoked, but it could not find a ci.yml workflow run for the PR head SHA. Because no PR CLI artifact could be located, the CLI version could not be verified against the PR head commit and no scenarios were executed.

text Starting download and installation for PR #15969 INSTALL_FAILED: Error: No ci.yml workflow run found for PR SHA: 5eaa723f86ae8a697252f2ea5568d6b38735df33. This could mean no workflow has been triggered for this SHA 5eaa723f86ae8a697252f2ea5568d6b38735df33 . Check at https://github.com/microsoft/aspire/actions/workflows/ci.yml

Changes analyzed

This PR adds health checks and configuration for Azure AI Inference clients:

  • src/Components/Aspire.Azure.AI.Inference/AspireAzureAIInferenceExtensions.cs
  • src/Components/Aspire.Azure.AI.Inference/AzureAIInferenceChatCompletionsHealthCheck.cs
  • src/Components/Aspire.Azure.AI.Inference/AzureAIInferenceEmbeddingsHealthCheck.cs
  • src/Components/Aspire.Azure.AI.Inference/ChatCompletionsClientSettings.cs
  • src/Components/Aspire.Azure.AI.Inference/ConfigurationSchema.json
  • src/Components/Aspire.Azure.AI.Inference/api/Aspire.Azure.AI.Inference.cs
  • src/Components/Aspire.Azure.AI.OpenAI/AspireAzureOpenAIExtensions.cs
  • tests/Aspire.Azure.AI.Inference.Tests/ConformanceTests.cs

Planned scenarios

These scenarios were selected based on the changed files, but were not executed because CLI installation failed first:

  1. Verify the installed PR dogfood Aspire CLI reports the PR head commit.
  2. Create a temp app using the Azure AI Inference integration and verify health checks are registered by default.
  3. Verify DisableHealthChecks disables health-check registration.
  4. Exercise mocked or configured ChatCompletionsClient and EmbeddingsClient health-check paths where practical.

Overall: Not verified. Please rerun after CI produces dogfood artifacts for the PR head commit.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR implements functional health checks for the ChatCompletionsClient and EmbeddingsClient registrations in Aspire.Azure.AI.Inference, replacing the previously hardcoded false for GetHealthCheckEnabled and NotImplementedException in CreateHealthCheck. The health checks call GetModelInfoAsync() — a lightweight read-only GET /info endpoint — to verify connectivity. A DisableHealthChecks opt-out property is added to ChatCompletionsClientSettings, following the existing DisableMetrics/DisableTracing pattern. For the Azure OpenAI component, NotImplementedException is replaced with NotSupportedException and an explanatory comment, since health checks remain unsupported there.

Changes:

  • Added AzureAIInferenceChatCompletionsHealthCheck and AzureAIInferenceEmbeddingsHealthCheck internal classes that use GetModelInfoAsync() for connectivity verification.
  • Added DisableHealthChecks property to ChatCompletionsClientSettings with corresponding config schema and API surface changes.
  • Updated AspireAzureOpenAIExtensions.cs to throw NotSupportedException instead of NotImplementedException with documentation explaining the rationale.

Reviewed changes

Copilot reviewed 8 out of 8 changed files in this pull request and generated no comments.

Show a summary per file
File Description
src/Components/Aspire.Azure.AI.Inference/AzureAIInferenceChatCompletionsHealthCheck.cs New health check class for ChatCompletionsClient using GetModelInfoAsync()
src/Components/Aspire.Azure.AI.Inference/AzureAIInferenceEmbeddingsHealthCheck.cs New health check class for EmbeddingsClient using GetModelInfoAsync()
src/Components/Aspire.Azure.AI.Inference/ChatCompletionsClientSettings.cs Adds DisableHealthChecks property with XML docs
src/Components/Aspire.Azure.AI.Inference/AspireAzureAIInferenceExtensions.cs Wires up health check creation and enabled-check for both client components
src/Components/Aspire.Azure.AI.Inference/ConfigurationSchema.json Adds DisableHealthChecks to the JSON schema
src/Components/Aspire.Azure.AI.Inference/api/Aspire.Azure.AI.Inference.cs Adds public API surface entry for DisableHealthChecks
src/Components/Aspire.Azure.AI.OpenAI/AspireAzureOpenAIExtensions.cs Changes NotImplementedException to NotSupportedException with rationale comments
tests/Aspire.Azure.AI.Inference.Tests/ConformanceTests.cs Enables health check conformance test by providing SetHealthCheck implementation

@radical

Copy link
Copy Markdown
Member

Roni Vegh (@Formatted) could you please merge main here.

@Formatted

Copy link
Copy Markdown
Contributor Author

Ankit Jain (@radical) main merged.

@radical Ankit Jain (radical) added ai area-integrations Issues pertaining to Aspire Integrations packages azure Issues associated specifically with scenarios tied to using Azure labels Jun 25, 2026
Avoid registering the model-info probe for GitHub Models and Azure OpenAI endpoints, where the SDK does not support /info. Restore the generated API baseline and cover endpoint-specific registration behavior.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 73f45c56-c13b-451f-9272-849146f8db34
@sebastienros

Copy link
Copy Markdown
Contributor

Pushed a follow-up fix in fcb4140bfa to address review findings:

  • GetModelInfoAsync calls /info, which the Azure.AI.Inference SDK explicitly does not support for GitHub Models or Azure OpenAI endpoints. Since this PR enables health checks by default, those otherwise-working integrations would have become permanently unhealthy after upgrading. Health-check registration is now skipped for those endpoint families while remaining enabled for supported Foundry model-inference endpoints.
  • Removed the edit to src/Components/Aspire.Azure.AI.Inference/api/Aspire.Azure.AI.Inference.cs because API baseline files are generated and are not updated when new public APIs are introduced during normal PR development.
  • Added focused chat-completions and embeddings coverage for supported Foundry endpoints plus GitHub Models and Azure OpenAI public-cloud/sovereign-cloud endpoint suffixes.

The targeted Aspire.Azure.AI.Inference.Tests project passes on net8.0, net9.0, and net10.0 (222 passed, 18 skipped).

Copilot AI review requested due to automatic review settings August 12, 2026 22:30

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

Suppressed comments (2)

src/Components/Aspire.Azure.AI.Inference/AspireAzureAIInferenceExtensions.cs:472

  • This host-only blacklist misclassifies Azure OpenAI-compatible endpoints on *.services.ai.azure.com as supporting /info. Microsoft Foundry documents https://<resource>.services.ai.azure.com/openai/v1/ as a valid Azure OpenAI base URL, while GetModelInfoAsync explicitly does not support Azure OpenAI endpoints; this therefore enables a health check that will report healthy applications as unhealthy. Gate on the endpoint path/known supported endpoint shapes as well, and add services.ai.azure.com/openai/v1 regression cases for both registrations.
        return !IsHostOrSubdomain(host, "models.github.ai")
            && !IsHostOrSubdomain(host, "models.inference.ai.azure.com")
            && !IsHostOrSubdomain(host, "openai.azure.com")
            && !IsHostOrSubdomain(host, "openai.azure.us")
            && !IsHostOrSubdomain(host, "openai.azure.cn")
            && !IsHostOrSubdomain(host, "openai.azure.de");

src/Components/Aspire.Azure.AI.Inference/AzureAIInferenceEmbeddingsHealthCheck.cs:20

  • The added embeddings tests only verify whether HealthCheckService is registered; none execute this health check. A wrong request path, client call, or status mapping would therefore pass. Add focused tests using a controllable transport to verify that a successful /info response is Healthy and a failed response uses the configured failure status.
            await _client.GetModelInfoAsync(cancellationToken).ConfigureAwait(false);

@sebastienros

Copy link
Copy Markdown
Contributor

PR Testing Report

PR Information

Artifact Version Verification

  • Expected Commit: fcb4140bfa7ef91d417482c9df475a68c977dd10
  • Installed CLI Version: 13.6.0-pr.15969.gfcb4140b
  • Tested Component Package: Aspire.Azure.AI.Inference.13.6.0-pr.15969.gfcb4140b.nupkg
  • Status: ✅ Verified

The installed CLI and component package both contain the PR head's short commit SHA, fcb4140b.

Changes Analyzed

Files Changed

  • src/Components/Aspire.Azure.AI.Inference/AspireAzureAIInferenceExtensions.cs
  • src/Components/Aspire.Azure.AI.Inference/AzureAIInferenceChatCompletionsHealthCheck.cs
  • src/Components/Aspire.Azure.AI.Inference/AzureAIInferenceEmbeddingsHealthCheck.cs
  • src/Components/Aspire.Azure.AI.Inference/ChatCompletionsClientSettings.cs
  • src/Components/Aspire.Azure.AI.Inference/ConfigurationSchema.json
  • src/Components/Aspire.Azure.AI.OpenAI/AspireAzureOpenAIExtensions.cs
  • tests/Aspire.Azure.AI.Inference.Tests/AspireAzureAIInferenceEmbeddingsExtensionTests.cs
  • tests/Aspire.Azure.AI.Inference.Tests/AspireAzureAIInferenceExtensionTests.cs
  • tests/Aspire.Azure.AI.Inference.Tests/ConformanceTests.cs

Change Categories

  • CLI changes
  • Hosting integration changes
  • Dashboard changes
  • Template changes
  • Client/component changes
  • VS Code extension changes
  • Test changes
  • CI infrastructure changes

Test Scenarios Executed

Scenario 1: Supported Foundry model-info probes

Objective: Verify the packaged chat-completions and embeddings integrations register health checks and call the SDK's /info operation for a supported endpoint.

Coverage Type: Happy path

Status: ✅ Passed

Steps:

  1. Created a fresh aspire-empty project from the PR template hive.
  2. Added a minimal .NET 10 probe app consuming Aspire.Azure.AI.Inference from the PR package hive.
  3. Started a local HTTP endpoint that returned valid model-info JSON.
  4. Registered keyed ChatCompletionsClient and EmbeddingsClient instances against that endpoint.
  5. Ran HealthCheckService.CheckHealthAsync().

Evidence:

  • scenario-healthy/create.log
  • scenario-healthy/run.log

Observations:

  • Overall status was Healthy.
  • Both expected registrations were present and healthy.
  • The local server received exactly two /info requests, one per client.

Scenario 2: Unsupported endpoint families

Objective: Verify endpoints documented by the SDK as not supporting /info do not receive the new health-check registration.

Coverage Type: Boundary and compatibility

Status: ✅ Passed

Steps:

  1. Created a fresh aspire-empty project from the PR template hive.
  2. Tested chat and embeddings registrations for:
    • GitHub Models, including a subdomain boundary.
    • models.inference.ai.azure.com.
    • Azure OpenAI public cloud.
    • Azure OpenAI US Government, China, and Germany sovereign-cloud suffixes.
  3. Verified no HealthCheckService was registered for these unsupported endpoint families.
  4. Tested the lookalike host models.github.ai.example.com and verified it was not incorrectly classified as GitHub Models.

Evidence:

  • scenario-unsupported/create.log
  • scenario-unsupported/run.log

Observations:

  • All 14 unsupported chat/embeddings cases suppressed registration.
  • Both suffix-lookalike boundary cases retained registration.

Scenario 3: Explicitly disabled health checks

Objective: Verify DisableHealthChecks = true suppresses registration for both client types even when the endpoint would otherwise support /info.

Coverage Type: Configuration boundary

Status: ✅ Passed

Evidence:

  • scenario-disabled/create.log
  • scenario-disabled/run.log

Observations:

  • Neither chat nor embeddings registered a health check.
  • No network request was attempted.

Scenario 4: Authentication/service failure

Objective: Verify a supported endpoint returning an unsuccessful response produces an unhealthy report rather than throwing out of the health-check pipeline.

Coverage Type: Unhappy path

Status: ✅ Passed

Steps:

  1. Created a fresh aspire-empty project from the PR template hive.
  2. Started a local endpoint that returned HTTP 401 with an error payload.
  3. Registered chat and embeddings clients against that endpoint.
  4. Executed the health-check service.

Evidence:

  • scenario-failure/create.log
  • scenario-failure/run.log

Expected Unhappy-Path Outcome: Both registrations return Unhealthy, retain the SDK exceptions, and do not crash the caller.

Observations:

  • Overall status was Unhealthy.
  • Both registrations were unhealthy and retained exceptions.
  • The local server received exactly two /info requests.

Summary

Scenario Status Notes
Supported Foundry model-info probes ✅ Passed Two healthy checks and two /info requests
Unsupported endpoint families ✅ Passed 14 suppressed registrations; 2 lookalike boundaries preserved
Explicitly disabled health checks ✅ Passed Chat and embeddings registrations suppressed
Authentication/service failure ✅ Passed Two unhealthy results; exceptions retained

Artifacts

  • install.log
  • version.txt
  • scenario-healthy/create.log
  • scenario-healthy/run.log
  • scenario-unsupported/create.log
  • scenario-unsupported/run.log
  • scenario-disabled/create.log
  • scenario-disabled/run.log
  • scenario-failure/create.log
  • scenario-failure/run.log

No screenshots were captured because this PR changes a headless client component and does not modify Dashboard UI.

Overall Result

✅ PR VERIFIED

The packaged PR artifact matches the latest head commit and behaves correctly for supported Foundry endpoints, unsupported GitHub Models and Azure OpenAI endpoint families, explicit health-check opt-out, and failed remote probes.

@github-actions

Copy link
Copy Markdown
Contributor

Retrying the failed CI jobs for this pull request from the CI run attempt. The rerun is being tracked in the rerun attempt.

Copilot AI review requested due to automatic review settings August 24, 2026 16:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated 1 comment.

Record the SDK capability follow-up and the DisableHealthChecks escape hatch for newly introduced Azure OpenAI endpoints.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 73f45c56-c13b-451f-9272-849146f8db34
Copilot AI review requested due to automatic review settings August 24, 2026 16:58

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 9 out of 9 changed files in this pull request and generated no new comments.

Suppressed comments (2)

Previously missed (1) — in code that hasn't changed since the last review.

src/Components/Aspire.Azure.AI.Inference/AzureAIInferenceChatCompletionsHealthCheck.cs:21

  • No test exercises the successful /info path: the registration tests do not instantiate the check, and the conformance test calls a fake endpoint and expects Unhealthy. Therefore an implementation that always returns an unhealthy result would satisfy the current coverage. Add a controlled-client/transport test that returns valid model info and asserts Healthy, alongside the failure case.
            await _client.GetModelInfoAsync(cancellationToken).ConfigureAwait(false);
            return HealthCheckResult.Healthy();

src/Components/Aspire.Azure.AI.Inference/AzureAIInferenceEmbeddingsHealthCheck.cs:20

  • The added embeddings tests only check whether HealthCheckService exists; health-check factories are lazy, and the conformance suite exercises only the chat client. As a result, AzureAIInferenceEmbeddingsHealthCheck is never created or run, so an implementation that throws during creation or always reports unhealthy would still pass. Add a test that executes the registered embeddings check with a controlled transport/client response and verifies the healthy and failure results.
            await _client.GetModelInfoAsync(cancellationToken).ConfigureAwait(false);

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 73f45c56-c13b-451f-9272-849146f8db34
Copilot AI review requested due to automatic review settings August 24, 2026 17:12

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 11 out of 11 changed files in this pull request and generated 1 comment.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 73f45c56-c13b-451f-9272-849146f8db34
Copilot AI review requested due to automatic review settings August 28, 2026 16:00

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 12 out of 12 changed files in this pull request and generated 1 comment.

Foundry Local emits http://127.0.0.1:<port>/ endpoints that serve
OpenAI-compatible routes but not the /info endpoint used by GetModelInfoAsync.
The previous blocklist only excluded Azure OpenAI cloud domains, so Foundry
Local registrations would get a health check that always reported unhealthy.

Extend SupportsModelInfoHealthCheck to also exclude loopback addresses
(127.0.0.1, ::1, localhost) and add regression cases for the Foundry Local
and Ollama-style endpoint shapes in both chat and embeddings tests.
Copilot AI review requested due to automatic review settings August 28, 2026 16:36
auto-merge was automatically disabled August 28, 2026 16:36

Head branch was pushed to by a user without write access

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 12 out of 12 changed files in this pull request and generated no new comments.

Suppressed comments (1)

Previously missed (1) — in code that hasn't changed since the last review.

src/Components/Aspire.Azure.AI.Inference/AzureAIInferenceChatCompletionsHealthCheck.cs:20

  • The new chat-completions health check is never executed by the tests. The conformance and endpoint-support tests only assert registration, while the transport-backed success/failure test covers only EmbeddingsClient. A regression in this class's /info request or exception-to-status handling would therefore pass. Add the equivalent 200/500 transport test for AddAzureChatCompletionsClient, including the /models/info assertion.
            await _client.GetModelInfoAsync(cancellationToken).ConfigureAwait(false);

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot-Session: 73f45c56-c13b-451f-9272-849146f8db34
Copilot AI review requested due to automatic review settings August 31, 2026 18:39
@sebastienros

Copy link
Copy Markdown
Contributor

Addressed the suppressed finding from review #5053130492 in 042d08e209. The chat-completions health check now has the same transport-backed 200/500 execution coverage as embeddings, asserting both the resulting Healthy/Unhealthy status and the /models/info request path.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 12 out of 12 changed files in this pull request and generated no new comments.

@sebastienros
Sébastien Ros (sebastienros) merged commit 5062c0f into microsoft:main Sep 2, 2026
44 checks passed
@github-actions github-actions Bot added this to the 13.6 milestone Sep 2, 2026
@Formatted
Roni Vegh (Formatted) deleted the add-azure-openai-inference-health-checks branch September 2, 2026 19:07
David Pine (IEvangelist) added a commit to microsoft/aspire.dev that referenced this pull request Sep 28, 2026
…ps (#1780)

## Summary

<!-- Describe what this pull request changes and why. -->

Reconcile the 13.6 wiki audit and **all 25 open `docs-from-code`
proposals targeting `release/13.6`** against the actual release source.
Add missing canonical guidance rather than putting all coverage in
What's new. This is a new, isolated feature PR into `release/13.6`; it
does not update the release rollup #1599, merge or close another
proposal, or push directly to a release branch.

**Draft with explicit remaining packaging/validation gates:** the six
REPL walkthroughs are source-verified, but current publicly available
13.6 packages do not contain the late `WithRepl` exports. Generated API
catalogs have deliberately not been fabricated or refreshed from 14.x.
See the open checklist below.

### Evidence baseline

- Documentation base: `717442f6666948bcf77f3d704dc2dadf7c080ec2`.
- Product source of truth:
[`microsoft/aspire@e8fd6fbb954f50ccd2e66479538392f65e13e71d`](https://github.com/microsoft/aspire/tree/e8fd6fbb954f50ccd2e66479538392f65e13e71d),
current `release/13.6` at audit time. Source was read from that Git
object, not the stale source working directory.
- [13.6 wiki](https://github.com/microsoft/aspire/wiki/13.6-Change-log)
snapshot `8e01a371d4f16a1306e48174d4cf1fdeca714348`, whose cutoff is
product PR 20511. Later backports 20541/20546/20548 are included here.
- Proposal base branches alone were **not** used as proof of release
membership. Direct ancestry and known release backports were checked.
Four fallback-targeted proposals are excluded below.
- Wiki link corrections: its REPL link #1752 actually covers Sandboxes;
the REPL proposal is #1740. Its AOT link #1714 covers PFX certificates,
not AOT.

### Complete audit-gap checklist

Checked items mean documentation coverage is implemented, not that cloud
deployment or every product runtime scenario was executed.

- [x] **1. Dotnet API graduation:** correct removal to **13.6**, not
14.0, in What's new, both Dotnet guides, and the diagnostic page;
preserve the prerelease package caveat. This applies to core
`AddDotnetProject`, `DotnetProjectResource`, and related
`WithBuildEnvironment` overloads, not all uses of the diagnostic.
Source: microsoft/aspire#20496.
- [x] **2. Sandboxes:** remove obsolete API suppressions in the article
and deployment guide while preserving Azure service preview/access and
prerelease package limitations. Source: microsoft/aspire#20483.
- [x] **3. Docked REPL documentation:** all six
PostgreSQL/MySQL/MongoDB/SQL Server/Redis/Valkey guides plus the article
now cover opt-in `WithRepl`/`withRepl`, run-only availability, actual
client privileges, credential handling, and explicit exit versus closing
a viewer. Source: microsoft/aspire#20419, backport of
microsoft/aspire#20231. Package-backed checks remain open below.
- [x] **4. Terminal CLI flag:** update current 13.6 article,
`with-terminal`, and all three terminal command references. Preserve
`terminals.v1` and experimental hosting API distinctions. Current
configuration/schema data had no flag entry to remove; historical 13.5
notes remain historical. Source: microsoft/aspire#20548.
- [x] **5. First-party Rust:** rewrite both canonical Rust guides around
`Aspire.Hosting.Rust`; document Cargo versus application arguments,
typed targets, debugging, generated Dockerfiles, workspace context, ABI
constraints, and Toolkit migration. Bacon remains explicitly
Toolkit-only. Add exact first-party package mapping. Source:
microsoft/aspire#18906 and current Rust README.
- [x] **6. Agent setup:** align command reference, skills guide,
AI-agent guide, and article on MCP opt-in, `--mcp`,
chained/non-interactive behavior, seven-skill catalog, Project v2
migration, and Copilot app detection. Also fix stale default-selection
text: all applicable bundle skills are preselected; companion tools
remain opt-in. Sources: microsoft/aspire#19893, microsoft/aspire#20405,
microsoft/aspire#19820.
- [x] **7. Deno AppHost runtime:** document Deno 2+ detection, commands,
permissions, native watch/type checking, doctor, and `DENO_CERT`,
separately from Deno guest hosting. Source: microsoft/aspire#18627,
distinct from microsoft/aspire#18628.
- [x] **8. Native AOT / Fluent UI v5:** concise article, dashboard
exploration, and standalone guidance; automatic packaged-dashboard
selection, no invented performance figures. Source:
microsoft/aspire#19565 and release packaging sources.
- [x] **9. NuGet:** document bundled in-process operations, credential
providers, non-interactive authentication, and realistic
troubleshooting. Correct the proposal's `dotnet nuget locals`
authentication advice: cache commands do not authenticate a feed.
Source: microsoft/aspire#20391.
- [x] **10. Multithreaded builds:** article and coordinated-build guide
explain `-mt`, SDK detection, distinct project/file-based SDK floors,
and fallback. Source: microsoft/aspire#20441.
- [x] **11. Radius:** add a real deployment guide with C#/TypeScript
setup, recipe-backed connections versus local endpoints, per-resource
credential behavior, unauthenticated Redis limitation, secret exposure
boundaries, and actionable runtime diagnostics 070–091. Wire navigation
and exact package mapping. Source: microsoft/aspire#19555 and release
README.
- [x] **12. Connection aliases:** replace contradictory no-encoding
guidance, retain composed logical-key-first lookup and portable-target
behavior, explain collision detection and custom-publisher metadata.
Source: microsoft/aspire#19729.
- [x] **13. Connector Namespace / Toolbox / provisioning:** add
Connector Namespace walkthrough, security/consent/revocation limits and
mapping/sidebar; add Foundry Toolbox walkthrough, connection properties,
roles, index prerequisites, approval enforcement boundaries, immutable
versions, and existing-resource behavior. Extend existing Azure
provisioning guide without a duplicate page. Sources:
microsoft/aspire#19024, microsoft/aspire#17742, microsoft/aspire#20131.
- [x] **14. Remaining high-impact items:** article covers opt-in
manifest-aware DNX and new-template CLI bundling (existing SDK guides
retained), migration skill and Copilot app detection; canonical inline
`CsiVolumeSourceV1`/`VolumeV1.Csi` example, management links, Cosmos
vNext telemetry, and AI Inference `GetModelInfoAsync`/`/info` health
checks with `DisableHealthChecks`. No Azure OpenAI health-check claim.
Sources: microsoft/aspire#19310, microsoft/aspire#19076,
microsoft/aspire#19826, microsoft/aspire#20070, microsoft/aspire#15671,
microsoft/aspire#15969.
- [x] **15. All 25 proposal dispositions:** listed below, including
newer dashboard backports and four exclusions. Existing Sandbox
inference coverage is retained rather than copied from a stale draft.
- [ ] **16. Refresh generated API/catalog/Twoslash data from an official
post-backport 13.6 build.** Existing `26473.12`/`a11eca96` data remains
untouched. The newest public `dotnet9` feed package checked,
`13.6.0-preview.1.26474.10` at
`43496a2a306c81c862c947b11b4f4e5494b6fe08`, still has no Redis
`WithRepl` in its actual package XML. Do not use 14.x, hand-edit
declarations, or attribute source changes to older binaries.
- [ ] **Validate the six REPL examples against that actual post-backport
SDK and running clients.** Their new TypeScript fences are plain
TypeScript, not annotated with unsupported Twoslash data. No existing
diagnostics are allowlisted or suppressed; no generated API exports are
fabricated. Enable Twoslash when the genuine catalog catches up.

### All 25 open proposal dispositions and provenance

Text is selectively adapted from these proposals, not merged wholesale.
#1778 and #1748 are authored by @sebastienros; the other proposals are
authored by the Aspire repo bot. The table credits the associated
product-change authors where supplied by the proposals. Existing PRs
remain open and unchanged.

| Docs PR | Release source / credited product author | Disposition |
| --- | --- | --- |
| #1778 | microsoft/aspire#19729 — @sebastienros | **Adopted:**
canonical connection-string alias correction, including logical-first
resolution and migration. |
| #1771 | microsoft/aspire#20481 — @sebastienros | **Excluded:** flat
polyglot feature keys are not in the audited release tip; no verified
backport. Preserve release key names. |
| #1770 | microsoft/aspire#20525 → microsoft/aspire#20548 — @mitchdenny
| **Corrected/adopted:** command guides plus the still-current 13.6
article, which the proposal incorrectly treats as historical. |
| #1769 | microsoft/aspire#20416 — @JamesNK | **Excluded:** brand hover
change has no verified 13.6 membership/backport. |
| #1768 | microsoft/aspire#20523 → microsoft/aspire#20546 — @JamesNK |
**Adopted:** run pin/unpin preserves selector and current selection. |
| #1766 | microsoft/aspire#20537 → microsoft/aspire#20541 — @mitchdenny
| **Adopted:** terminal dock empty state. |
| #1761 | microsoft/aspire#20490 → microsoft/aspire#20496 — @eerhardt |
**Corrected:** graduation is 13.6, package remains prerelease,
Blazor-specific exception retained. |
| #1760 | microsoft/aspire#20436 — @eerhardt | **Excluded:** CLI
net11/tools-any retarget is not in the audited release; no fallback-base
inference. |
| #1748 | microsoft/aspire#20131 — @sebastienros | **Adopted:** extend
existing provisioning guide with service-specific models/lookups and
projection limits. |
| #1744 | microsoft/aspire#20337 → microsoft/aspire#20441 — @karolz-ms |
**Adopted:** precise SDK-conditional multithreaded build coverage. |
| #1740 | microsoft/aspire#20231 → microsoft/aspire#20419 — @mitchdenny
| **Adapted:** all six guides; TypeScript-first tabs, source-verified
lifecycle/security. Actual post-backport SDK/runtime gate is open above.
|
| #1738 | microsoft/aspire#20158 → microsoft/aspire#20405 — @karolz-ms |
**Partly already covered / completed:** existing seven-skill catalog
retained; add project migration guidance and correct command
catalog/defaults. Do not misclassify the bundled skill as a companion
tool. |
| #1735 | microsoft/aspire#20334 — @karolz-ms | **Excluded:** enhanced
startup errors are not in the audited release; no verified backport. |
| #1731 | microsoft/aspire#19847 → microsoft/aspire#20391 — @eerhardt |
**Corrected/adopted:** in-process NuGet and real authenticated-restore
troubleshooting, not cache-command authentication. |
| #1719 | microsoft/aspire#20299 → microsoft/aspire#20407 — @JamesNK |
**Corrected/adopted:** cookie naming/scoping; identical names can
collide but do not guarantee cross-dashboard cookie decryptability or
shared sign-in. |
| #1664 | microsoft/aspire#20011 — @maddymontaquila | **Adopted:**
concise Azure environment icon release note. |
| #1628 | microsoft/aspire#17742 — @davidfowl | **Adapted/expanded:**
canonical Toolbox examples, consumer contract, role/index prerequisites,
approval/security and concurrency limits. |
| #1623 | microsoft/aspire#19810 — @mitchdenny | **Already covered:**
current Sandbox guide/article already describe compute inference,
explicit selection and external endpoints. Preserve that guidance while
removing obsolete suppressions. |
| #1620 | microsoft/aspire#19243 — @sebastienros | **Adapted:** AKS
credential-before-Helm cleanup and destructive-operation warning; omit
misleading ambient-context workaround. |
| #1614 | microsoft/aspire#19870 — @sebastienros | **Adopted:** typed
callback handle behavior in extension authoring and article. |
| #1574 | microsoft/aspire#19430 — @mitchdenny | **Adapted:** canonical
hostname inheritance, explicit-host precedence, catch-all default
backend. |
| #1570 | microsoft/aspire#19590 — @karolz-ms | **Adopted:** Dev Tunnel
URL regression troubleshooting. |
| #1565 | microsoft/aspire#19429 — @mitchdenny | **Corrected/adopted:**
Helm embedded parameters with real `refExpr` and `addParameter(name, {
value })`, not stringifying a handle or using an invalid actual-SDK
overload. |
| #1564 | microsoft/aspire#19026 — @karolz-ms | **Corrected/adopted:**
C#/TypeScript Dotnet gateway walkthrough. Retain both experimental
diagnostics; remove obsolete run-only restriction after
microsoft/aspire#19997 publishing support. Avoid imported ambiguous API
reference. |
| #1499 | microsoft/aspire#19248 — @IEvangelist | **Adopted:** describe
exact secret-value redaction and embedded-secret limit; release article
already covered the fix. |

### Important source-verified corrections to proposals / earlier audit
assumptions

-
[`BlazorGatewayExtensions.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Hosting.Blazor/BlazorGatewayExtensions.cs):
`AddDotnetProjectBlazorGateway` and the Dotnet `WithBlazorClientApp`
overload still carry `ASPIREDOTNETPROJECT001`; the class carries
`ASPIREBLAZOR001`. They share `WithBlazorClientAppCore`/`WithBlazorApp`
and the publish-companion path. Thus neither blanket diagnostic
retirement nor the proposal's old run-only claim is correct.
-
[`SkillDefinition.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Agents/SkillDefinition.cs)
sets bundled skills' `IsDefault=true`;
[`AgentInitCommand.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Commands/AgentInitCommand.cs)
selects the applicable catalog defaults for both flows. MCP has its own
standalone-only binding.
-
[`TypeScriptAppHostToolchainResolver.cs`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Cli/Projects/TypeScriptAppHostToolchainResolver.cs)
is the source for Deno flags and certificate variable; guest Deno
hosting is separate.
- [`Radius
README`](https://github.com/microsoft/aspire/blob/e8fd6fbb954f50ccd2e66479538392f65e13e71d/src/Aspire.Hosting.Radius/README.md)
supplies the resource-specific credential rules and publish diagnostics,
not assumptions about local endpoints.

## Third-party links and affiliations

<!-- List third-party links and disclose material affiliations. -->

Links point to official Microsoft Learn, VS Code Marketplace debugger
extensions, Rust/Cargo/Bacon documentation, Radius documentation, and
source repositories. No sponsorship, commercial endorsement, or
affiliation claim is introduced. Maintainers should supply any personal
affiliation disclosure required by policy; automation has not inferred
one.

## Validation

<!-- List the checks you ran or explain why validation isn't needed. -->

- **97 passing focused unit checks** across API-reference
authoring/rendering, Twoslash blocks, file-tree formatting, CLI
configuration schema, SEO lengths, and resource catalog.
- **82 passing structured-data checks**, including exact integration
mapping uniqueness and page resolution.
- **11 C# samples compile**, zero warnings/errors, using genuine
`13.6.0-preview.1.26473.12` packages. Scope: Rust, Connector Namespace,
Radius, Toolbox, inline CSI, Helm, Blazor gateway, and provisioning.
`Projects.Api/Worker/Client` use compile-only `IProjectMetadata`
stand-ins; no claim of running those apps or provisioning cloud
resources.
- **10 TypeScript samples pass `tsc`** under `strict`, `NodeNext`, and
`ES2022` against three **unmodified actual SDK files**, not just the
site's declaration bundle. The fixture uses the exact `e8fd6fbb` release
`AtsCapabilityScanner` and genuine `26473.12`
TypeSystem/code-generator/integration binaries, whose informational
source is `a11eca96`. This is an isolated local generation fixture,
**not** a claim that official CLI generation or a new packaged release
was tested. An attempted restore with the older handed-off local CLI
could not discover an AppHost server; the bounded direct generator
fixture was used instead.
- The SDK scan is **not globally warning-free**: it reports a Radius
`withContainerImage` collision on `CSharpAppResource` and an App
Configuration `createRoleAssignment` overload collision. None of the
compiled examples calls those colliding methods; the warnings are
retained in evidence, not suppressed, and no generated declarations were
edited.
- Browser: Connector Namespace, Radius, both Rust pages, Foundry
hosting, and What's new return **HTTP 200**, correct headings, and no
rendered Twoslash errors. New guide/article page-local anchors and the
cross-page Blazor anchor resolve. Connector/Radius mobile layouts have
no horizontal overflow; Connector language-tab interaction works.
Standalone Astro preview emits expected `/api/live` 404s because
StaticHost is not running.
- `git diff --check` passes. No production `pnpm build`, cloud
deployment, REPL runtime session, full product suite, or blanket
validation of every pre-existing example was performed.
- Generated C#/TypeScript API data, declaration bundles, integration
catalogs, image catalogs, and contributor data are unchanged. Only the
authored package-to-guide mapping is updated.

**Before merging:** complete the two packaging/REPL checkboxes above,
inspect CI, and obtain human review. This PR intentionally does not
close or merge the source documentation proposals.

---------

Co-authored-by: David Pine <7679720+IEvangelist@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 3, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

ai area-integrations Issues pertaining to Aspire Integrations packages azure Issues associated specifically with scenarios tied to using Azure

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants