Skip to content

docs(mcp): APIM·Toolbox·IQ 활용과 선택 가이드 - #62

Merged
hellices merged 17 commits into
mainfrom
agents/azure-mcp-setup-and-documentation
Sep 13, 2026
Merged

hellices merged 17 commits into
mainfrom
agents/azure-mcp-setup-and-documentation

Conversation

@hellices

@hellices hellices commented Sep 12, 2026 •

Copy link
Copy Markdown
Owner

고객용 대표 문서

Azure MCP 구성 — APIM·Toolbox·IQ의 활용과 선택 기준을 대표 문서로 정리했습니다.

앞부분은 각 서비스가 무엇이며 왜 사용하는지에 집중합니다. APIM은 여러 팀의 API/MCP에 공통 운영 정책을 적용하고, Toolbox는 client별 도구 연결·인증·변경 관리를 줄이며, IQ는 조직의 업무 데이터와 지식을 연결합니다.

서비스 정의·도입 이유·핵심 기능을 복원하고 APIM과 Toolbox 구성도를 유지했습니다. 인증은 본문에서 짧게 요약하며, 앱 등록·claims·PRM·완료 기준과 인증 구성도는 인증 상세 문서로 이동했습니다. 본문 인증 절은 60줄에서 12줄로 줄였습니다.

이번 구조 변경

  • APIM 기존 MCP proxy와 REST API wrapping을 같은 gateway 장에서 구분했습니다.
  • Work IQ의 MCP/A2A, Fabric IQ의 item별 MCP endpoint, Foundry IQ knowledge-base MCP와 Toolbox connection을 구분했습니다.
  • Toolbox를 단순 검색 기능이 아니라 toolset·connection 인증·version·정책을 관리하는 서비스로 소개합니다.
  • Microsoft Learn에 삽입된 토큰 비교 영상의 구간 링크를 추가했습니다. 영상 설명의 input tokens **4,676 → 467(약 90% 감소)**는 해당 데모의 값이며 일반 보장이나 이 저장소의 실측이 아닙니다.
  • 대표 문서는 HTTP MCP tools 제공·호출과 Entra 인증에 범위를 한정합니다. 제품 전체 conformance를 평가하는 행과 “미확인/미실측” 중심 설명은 제거하고, 지원 구성·명시적 제약·완료 기준을 안내합니다.
  • 실행 당시의 관측과 범위는 사례/sample에 보존합니다. 범위 밖인 resources 지원을 새로 단정하지 않았으며, 대표 문서의 범위 내 기술 설명은 공개 근거를 대조해 verified로 정리했습니다.
  • MCP OAuth로 MCP API token을 받는 흐름과 Entra OBO로 downstream token을 받는 흐름을 연결했습니다.
  • Appendix에서 2026-07-28 protocol의 session·handshake 제거, 요청별 metadata, SSE 유지, OAuth discovery·PKCE·등록 요구사항을 공식 규격과 대조했습니다. SDK/제품 2.x, JSON-RPC 2.0과 구분합니다.
  • 대표 문서는 APIM 중앙 관리와 Toolbox의 IQ/MCP 통합 SVG를 사용하고, 인증 상세 문서는 PRM·Entra 로그인 SVG를 사용합니다.
  • 실제 배포·호출 9개 시나리오와 캡처는 sample walkthrough로 옮겼습니다. GitHub/Azure/AKS/Learn은 예제 backend입니다.
  • Toolbox sample의 일반 목록과 Tool search 시나리오를 연결하고, 마지막 표에서 실제 실행 방법·관측값·캡처 위치를 연결합니다.
  • 인증 상세에서 API 앱과 OAuth client 앱의 등록을 구분하고, 공개 claim 정의에 맞춰 v2 aud·azp·scp와 JWT 정책의 required-claims 위치를 정리했습니다.
  • 설정 완료 기준과 목적별 읽기 경로를 추가했습니다. 상세 wire 규격은 필요할 때 펼쳐 보는 Appendix로 정리하고, 호스팅 참고의 중복 Toolbox 소개·실행 절차를 줄였습니다.
  • APIM SKU의 실제 private network 기능을 공식 비교표로 정리했습니다. 최종 검토에서 client ID/redirect는 client 앱, scope는 API 앱에 맞춘다는 문장도 명확히 했습니다.

MCP HTTP auth 단계별 추가 확인

Entra의 Authorization Code + PKCE 지원, MCP Server/APIM의 PRM 제공·JWT 검증, downstream OBO를 구분했습니다. MSAL interactive flow의 자동 PKCE는 공식 문서로 확인했습니다. 기존 RG·Entra 앱은 읽기 전용으로 재확인했으며 리소스/인증 설정은 변경하지 않았습니다.

추가 확인 결과
401 challenge·PRM APIM·Python에서 challenge와 PRM 200 확인
Token 검증·OBO APIM 정상 token 200, wrong audience 401; Python ARM OBO complete·isError: false
PKCE metadata 해당 tenant OIDC 응답의 선언 누락은 특정 MCP client의 metadata 상호운용성 관측이며, Entra의 PKCE 미지원이나 MSAL 로그인 실패 판정이 아님
Resource URI API 앱에는 api://...만 등록. Canonical URL 대상 CLI token 요청 AADSTS500011
자동 OAuth 전체 흐름 Browser PKCE·refresh 및 Toolbox consumer 인증은 미실행. 제품 미지원으로 표시하지 않음

수동 확인 절차와 비식별 결과를 추가했습니다. 현재 RG에는 Foundry/Toolbox가 없어 그 부분은 문서 근거와 미실측 범위를 표시합니다.

APIM과 Toolbox의 조합은 요구사항에 따른 설계 제안으로 별도 표시했습니다. 새 Foundry/IQ 배포, Toolbox 사용자 OAuth의 실증 또는 자체 토큰 절감 측정을 수행했다고 주장하지 않습니다. 아래 실제 실행 결과와 구분합니다.

Topic package와 실행 방식

최신 main의 #64 게시 구조를 반영해 대표 문서·인증 참고·호스팅 참고·실행 사례와 두 sample을 docs/services/azure-architecture/mcp-configuration/에 모았습니다. 이전 guide/lab/case/research URL은 redirect로 보존합니다. 두 sample에는 sample.yml을 추가했고, .azure·.private의 로컬 배포 상태는 비공개로 보존했습니다.

#65의 목적/주제 태그와 자산 단일 원본 규칙도 반영했습니다. Sample의 중복 이미지 9개는 같은 topic의 사례·참고 문서 원본으로 링크를 바꿨으며, 실행 명령과 이미지 내용은 유지했습니다.

  • azure.yaml과 Bicep 기반 native azd로 provisioning, ACR remote build, Container App service deployment를 수행합니다.
  • 샘플의 테스트·자동 probe·채점 수집기와 별도 Azure 배포 프레임워크는 제거했습니다.
  • 독자가 azd, MCP Inspector, curl, kubectl 명령을 직접 실행합니다. 기존 실행 명령·요청 예제 33개를 이동 전후 비교해 보존했습니다.
  • 실제 실행 기록은 case에 남기고 운영 설계는 guide, 실행 가능한 예제는 samples로 구분합니다.

새 환경에서 실행한 내용

기존 실습 RG, AKS·Container Apps 관리 RG와 Entra 앱 3개를 제거한 뒤 새 azd environment를 배포했습니다.

실행 결과
azd provision --preview 새 환경의 생성 계획 확인
azd up 33분 26초에 provisioning·remote build·service deploy 완료
로컬 GitHub / Azure / AKS / Learn MCP 공식 Inspector client로 도구 조회·호출
APIM REST-to-MCP 직접 REST와 getInventory MCP tool에서 같은 가상 재고 반환
Native Azure MCP OBO 새 RG의 Azure 리소스 조회
Python MCP OBO Protocol 2026-07-28, RG 존재·region·상태 반환
APIM Learn MCP proxy 실제 Learn 도구 조회·검색
인증 오류 무인증·wrong audience 401, 제외된 client 403, 설정 복구 후 정상 조회

공개용 응답 발췌는 docs/services/azure-architecture/mcp-configuration/samples/apim-entra-lab/assets/captures/2026-09-13-responses.json에 있습니다. 원본 실행 로그, token·환경 식별자는 공개하지 않습니다.

검증 및 리뷰 대응

  • 문서 metadata·source·link·public safety 검증 통과
  • strict MkDocs build와 search coverage 확인
  • 최신 main의 글 찾기·자산 규칙을 반영한 뒤 문서 테스트 276개 통과
  • 큰 화면/390px 화면, 밝은/어두운 테마에서 본문 16px·H1 32px, 이미지 로드와 가로 overflow 없음 확인
  • 문서 내용 변경의 독립 코드 리뷰에서 중대한 추가 지적 없음
  • 새 터미널에서 KUBECONFIG가 유실되는 리뷰를 반영했습니다. 절대 경로를 재입력하고 빈 값·상대 경로·없는 파일을 거부하며, 새 셸과 공백 포함 경로 등 5개 조건을 확인했습니다.
  • 임시 caller 제한 실습의 실패 시 복구 리뷰도 반영했습니다. 변경 전 EXIT trap, 원래 오류 코드 유지, 복구 오류 표시, 고유 백업과 새 셸 복구를 적용하고 11개 로컬 shell 조건을 확인했습니다. 실제 Azure 설정은 변경하지 않았습니다.
  • 이전 Bicep provisioning/service module compile과 실제 azd 실행 결과 유지
  • 이동한 두 azd 프로젝트에서 APIM sample의 mcp와 Toolbox의 두 service를 인식하는지 확인
  • 기존 PR 피드백에 따라 httpx2를 직접 의존성으로 명시하고 잘못된 URL의 예외를 ConfigError로 통일
  • 설치된 mcp 2.2.0이 원래 httpx2>=2.5.0을 요구한다는 점을 확인; service import와 정상 URL 2개·오류 URL 8개 확인
  • 재현 가능한 meter 근거가 없는 정확한 일일 가격 대신 실제 배포 조건의 가격 산정 안내
  • 기존 문서 CI는 유지하며, 샘플 애플리케이션 테스트나 의존성을 문서 CI에 연결하지 않습니다.
  • 공개 안전성 검사는 Git에 게시될 파일만 검사하도록 보완했습니다. 로컬 .azure/는 제외하지만 실수로 force-add한 파일은 계속 검사합니다.

검토 사항

  • AKS MCP 0.0.20은 local stdio-only입니다.
  • APIM 관리 API의 문서·Bicep type과 runtime 차이는 문서에 명시했습니다.
  • App Service와 Functions는 리서치 대안입니다.
  • 새 Azure 환경은 후속 실습을 위해 유지 중이며 비용이 발생합니다. 자동 삭제는 없습니다.
  • 사용자 승인에 따라 최신 리뷰와 CI를 확인한 뒤 병합합니다.

Add a reproducible private Azure MCP lab with Entra user delegation, native APIM REST-to-MCP tools, and separately authenticated upstream servers. Preserve sanitized live evidence, architecture SVGs, review corrections, and explicit verification limits.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Critical authentication and proxy findings, plus unresolved moderate correctness and cleanup issues, remain.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

This PR adds an Azure MCP lab covering Entra OBO, APIM REST-to-MCP conversion, Learn proxying, private networking, and validation evidence.

Changes:

  • Adds MCP services, authentication/OBO flows, probes, evidence tooling, and tests.
  • Adds APIM, ACA, AKS, networking, identity, and cleanup infrastructure.
  • Adds guides, research, case documentation, diagrams, captures, and taxonomy entries.

Open findings remain: one documentation status nit, five moderate implementation findings, and two critical authentication/proxy findings.

File summaries
File Reviewed change
samples/azure-api-management/mcp-entra-lab/transport_proxy.py Implements the HTTPS CONNECT proxy; critical listener exposure remains.
samples/azure-api-management/mcp-entra-lab/tests/test_upstream_probe.py Tests upstream probe validation.
samples/azure-api-management/mcp-entra-lab/tests/test_transport_proxy.py Tests proxy relay and allowlisting.
samples/azure-api-management/mcp-entra-lab/tests/test_service_rest.py Tests REST routes, authentication, and OBO.
samples/azure-api-management/mcp-entra-lab/tests/test_service_regressions.py Tests security regressions.
samples/azure-api-management/mcp-entra-lab/tests/test_service_obo.py Tests OBO behavior.
samples/azure-api-management/mcp-entra-lab/tests/test_service_helpers.py Provides service test helpers.
samples/azure-api-management/mcp-entra-lab/tests/test_service_fakes.py Provides service test doubles.
samples/azure-api-management/mcp-entra-lab/tests/test_service_config.py Tests configuration validation.
samples/azure-api-management/mcp-entra-lab/tests/test_service_auth.py Tests token validation.
samples/azure-api-management/mcp-entra-lab/tests/test_service_arm.py Tests ARM access and sanitization.
samples/azure-api-management/mcp-entra-lab/tests/test_probe_utils.py Tests probe utilities.
samples/azure-api-management/mcp-entra-lab/tests/test_probe_cloud.py Tests cloud probes.
samples/azure-api-management/mcp-entra-lab/tests/test_network_probe.py Tests network probe deployment.
samples/azure-api-management/mcp-entra-lab/tests/test_native_gate.py Tests native caller restrictions.
samples/azure-api-management/mcp-entra-lab/tests/test_evidence.py Tests evidence handling.
samples/azure-api-management/mcp-entra-lab/tests/test_entra_setup.py Tests Entra setup.
samples/azure-api-management/mcp-entra-lab/tests/test_cloud_stage.py Tests staged deployment.
samples/azure-api-management/mcp-entra-lab/tests/test_cloud_lab.py Tests lab safeguards.
samples/azure-api-management/mcp-entra-lab/tests/test_cleanup.py Tests cleanup behavior.
samples/azure-api-management/mcp-entra-lab/tests/test_auth_probe.py Tests authentication probes.
samples/azure-api-management/mcp-entra-lab/tests/conftest.py Configures the test suite.
samples/azure-api-management/mcp-entra-lab/service/tools.py Registers MCP tools.
samples/azure-api-management/mcp-entra-lab/service/rest.py Registers REST routes; critical authentication middleware issue remains.
samples/azure-api-management/mcp-entra-lab/service/obo.py Implements OBO exchanges.
samples/azure-api-management/mcp-entra-lab/service/learn.py Connects to Learn MCP; discovery error translation issue remains.
samples/azure-api-management/mcp-entra-lab/service/inventory.py Defines fixture inventory.
samples/azure-api-management/mcp-entra-lab/service/config.py Validates runtime configuration; port validation issue remains.
samples/azure-api-management/mcp-entra-lab/service/auth.py Implements token authentication.
samples/azure-api-management/mcp-entra-lab/service/arm.py Reads and sanitizes ARM results.
samples/azure-api-management/mcp-entra-lab/service/app.py Builds the ASGI application.
samples/azure-api-management/mcp-entra-lab/service/__init__.py Defines the service package.
samples/azure-api-management/mcp-entra-lab/requirements.txt Pins Python dependencies.
samples/azure-api-management/mcp-entra-lab/README.md Documents lab setup and validation.
samples/azure-api-management/mcp-entra-lab/probe_utils.py Provides probe helpers.
samples/azure-api-management/mcp-entra-lab/probe_upstreams.py Probes upstream MCP services.
samples/azure-api-management/mcp-entra-lab/probe_native_gate.py Probes native caller restrictions.
samples/azure-api-management/mcp-entra-lab/package.json Defines Node tooling.
samples/azure-api-management/mcp-entra-lab/package-lock.json Locks Node dependencies.
samples/azure-api-management/mcp-entra-lab/network_probe.py Deploys the private network probe.
samples/azure-api-management/mcp-entra-lab/mcp.example.json Provides client configuration examples.
samples/azure-api-management/mcp-entra-lab/infra/private-dns.bicep Defines private DNS resources.
samples/azure-api-management/mcp-entra-lab/infra/policies/remove-upstream-token.xml Removes upstream bearer tokens.
samples/azure-api-management/mcp-entra-lab/infra/policies/metadata.xml Serves protected-resource metadata.
samples/azure-api-management/mcp-entra-lab/infra/policies/global.xml Defines APIM authentication policy; REST metadata mapping issue remains.
samples/azure-api-management/mcp-entra-lab/infra/native-auth.bicep Configures native authentication.
samples/azure-api-management/mcp-entra-lab/infra/foundation.bicep Defines lab foundation resources; cluster-admin scope issue remains.
samples/azure-api-management/mcp-entra-lab/infra/entry.bicep Defines the deployment entrypoint.
samples/azure-api-management/mcp-entra-lab/infra/apps.bicep Deploys MCP applications.
samples/azure-api-management/mcp-entra-lab/infra/apim.bicep Configures APIM APIs and mappings.
samples/azure-api-management/mcp-entra-lab/evidence/upstreams.json Stores sanitized upstream evidence.
samples/azure-api-management/mcp-entra-lab/evidence/native-client-gate.json Stores native-gate evidence.
samples/azure-api-management/mcp-entra-lab/evidence/auth-local-live.json Stores sanitized authentication evidence.
samples/azure-api-management/mcp-entra-lab/evidence.py Sanitizes and renders evidence.
samples/azure-api-management/mcp-entra-lab/Dockerfile Defines the service image.
samples/azure-api-management/mcp-entra-lab/cloud_stage.py Manages application stages.
samples/azure-api-management/mcp-entra-lab/cloud_lab.py Manages the isolated lab.
samples/azure-api-management/mcp-entra-lab/cleanup.py Implements cleanup; missing service-principal handling issue remains.
samples/azure-api-management/mcp-entra-lab/auth_probe.py Validates tokens and OBO.
samples/azure-api-management/mcp-entra-lab/.dockerignore Restricts the build context.
docs/research/azure-api-management/mcp-authentication-options/images/local-upstreams.svg Illustrates local upstream boundaries.
docs/research/azure-api-management/mcp-authentication-options/images/functions-alternative.svg Illustrates Functions hosting.
docs/research/azure-api-management/mcp-authentication-options/images/container-apps-obo.svg Illustrates ACA OBO.
docs/research/azure-api-management/mcp-authentication-options/images/app-service-alternative.svg Illustrates App Service hosting.
docs/research/azure-api-management/mcp-authentication-options/images/apim-rest-tools.svg Illustrates APIM REST-to-MCP.
docs/research/azure-api-management/mcp-authentication-options/images/apim-existing-mcp.svg Illustrates MCP proxying.
docs-taxonomy.yml Registers documentation taxonomy entries.
Review details

Files not reviewed (1)

  • samples/azure-api-management/mcp-entra-lab/package-lock.json: Generated file

Suppressed comments (5)

docs/guides/azure-api-management/mcp-entra-private-access/index.md:9

  • This page is marked verified even though the linked lab and case still record an unresolved APIM preview endpoint/backend contract conflict (for example, the lab documents the array-versus-keyed-object discrepancy at line 216). The repository documentation contract requires needs-review whenever a material source conflict remains, so this status should not claim complete verification until that conflict is resolved or the guide removes the affected claim.
verification_status: verified

samples/azure-api-management/mcp-entra-lab/cleanup.py:46

  • Cleanup assumes every recorded application already has a service_principal_id, but entra_setup.ensure_app() persists the application record before ensure_sp() runs. If setup is interrupted in that window, or if a prior delete succeeded before its state flag was saved, this direct lookup/GET raises instead of deleting the owned app or resource group, defeating the documented resumable cleanup flow. Handle missing/already-deleted service principals idempotently (for example, discover by appId and treat 404 as already removed) before proceeding with the group deletion.
        if not record.get("cleanup_sp_deleted"):
            principal = directory.request(
                "get", f"/servicePrincipals/{record['service_principal_id']}"
            )
            if principal["appId"] != record["client_id"]:
                raise ValueError("service principal does not match its recorded lab application")

samples/azure-api-management/mcp-entra-lab/infra/foundation.bicep:237

  • This role ID is Azure Kubernetes Service RBAC Cluster Admin, which grants full control of every Kubernetes resource in the new cluster. The later --access-level readonly flag only constrains the AKS MCP process and cannot limit the operator's kubeconfig, so the sample's read-only/security boundary is undermined after deployment. Prefer a narrowly scoped bootstrap/namespace role for the probe, or explicitly document this persistent cluster-admin grant as a lab prerequisite.
    samples/azure-api-management/mcp-entra-lab/infra/policies/global.xml:23
  • This global error branch also applies to the protected lab-rest API, but the ternary maps every API other than learn-mcp to the rest-tools MCP resource. A direct unauthenticated /rest/inventory therefore receives a resource_metadata URL for a different resource, while no REST metadata mapping is defined. Exclude the REST API from this MCP-specific header or provide a distinct REST mapping.
    samples/azure-api-management/mcp-entra-lab/service/config.py:77
  • _require_https_url checks parts.hostname but never evaluates parts.port, so a value such as https://host:not-a-port/mcp passes configuration loading and only fails later when the SDK parses resource_server_url. Validate the port inside this boundary so malformed resource URLs consistently raise ConfigError.
  • Files reviewed: 68/80 changed files
  • Comments generated: 3
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread samples/azure-api-management/mcp-entra-lab/service/rest.py Outdated
Comment thread samples/azure-api-management/mcp-entra-lab/transport_proxy.py Outdated
Comment thread samples/azure-api-management/mcp-entra-lab/service/learn.py Outdated

@my-reviewer-agent my-reviewer-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

이슈 4건을 인라인 코멘트로 남겼습니다.

리뷰 범위: 변경사항 일부만 검토했습니다.

Comment thread docs/labs/azure-api-management/mcp-rest-and-upstream/index.md Outdated
Comment thread samples/azure-api-management/mcp-entra-lab/README.md Outdated
Comment thread samples/azure-api-management/mcp-entra-lab/cloud_lab.py Outdated
Comment thread samples/azure-api-management/mcp-entra-lab/tests/test_service_config.py Outdated
Replace custom deployment and test/probe runners with native azd provisioning, ACR remote builds and explicit MCP client scenarios. Rewrite customer-facing terminology, retain only runtime code, and capture fresh command responses after removing and rebuilding the Azure environment.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@hellices hellices changed the title docs(mcp): Azure MCP·Entra OBO와 APIM REST 실증 가이드 docs(mcp): azd 배포와 Entra OBO 시나리오 가이드 Sep 13, 2026
@hellices
hellices requested a lite review from Copilot September 13, 2026 04:36
Preserve the upstream navigation and local-state rules, retain both publication safety checks, and store curated public responses separately from local evidence.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved runtime, configuration, credential-lifecycle, and validation issues remain.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (6)

docs/guides/azure-api-management/mcp-entra-private-access/index.md:9

  • verification_status: verified is too strong for this page as written: applies_to and the body make version-specific claims about MCP Python SDK 2.2.0 and Inspector 2.5.0, but official_sources lists neither MCP project's canonical source. Add and verify those sources (as the neighboring research page does for the Python SDK), or keep this page at needs-review so the metadata does not claim unsupported verification.
verification_status: verified

docs/labs/azure-api-management/mcp-rest-and-upstream/index.md:32

  • This page is explicitly marked verification_status: needs-review, but last_verified still publishes a date that reads as a completed verification. The source-verification contract distinguishes incomplete review from verified claims; remove this last_verified field (or change the status only after every material claim has been checked) so the metadata does not overstate verification.
last_verified: 2026-09-13

samples/azure-api-management/mcp-entra-lab/README.md:56

  • The README compresses the 401/403 check and cleanup into item 8, while the linked walkthrough and PR description define cleanup as scenario 9. This makes the sample entry point advertise eight scenarios and leaves the walkthrough numbering inconsistent; split the final item into separate 8 and 9 entries.
8. Check 401/403 behavior and remove the environment when finished.

samples/azure-api-management/mcp-entra-lab/scripts/identity.py:183

  • This creates a client secret that expires after two days, but prepare has no rotation path: once secretExpiresAt is reached it raises and redeployment cannot refresh the credential. The walkthrough keeps the environment for later scenarios, so users returning after two days are left to edit private state manually; add an explicit rotation flow or document a supported renewal procedure before relying on this credential.
    samples/azure-api-management/mcp-entra-lab/service/tools.py:72
  • OboError.safe_code is not limited to consent failures: _safe_failure_code also returns values such as invalid_client, server_error, invalid_scope, and AuthorizationFailed. Prefixing every one with ConsentRequired misdiagnoses bad credentials and transient/server failures for tool callers; use a neutral prefix or map only consent-specific codes.
    scripts/docs/validate_public_safety.py:114
  • The no-Git fallback still recursively includes .azure, so running this validator from a source archive or another checkout without .git will inspect private azd state and can fail on a normal local environment. Apply the same .azure exclusion in this branch; the Git-aware branch already skips ignored state while still seeing force-added files.
  • Files reviewed: 46/58 changed files
  • Comments generated: 3
  • Review effort level: Lite

Comment thread samples/azure-api-management/mcp-entra-lab/service/config.py Outdated
Comment thread docs/labs/azure-architecture/mcp-configuration/index.md Outdated
Make the end-to-end walkthrough the primary customer document, with architecture and authentication context, in-place diagrams and actual response captures. Reframe the remaining documents as optional detailed references and point them back to the unified guide.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@hellices hellices changed the title docs(mcp): azd 배포와 Entra OBO 시나리오 가이드 docs(mcp): Azure MCP 통합 가이드와 azd 실습 Sep 13, 2026
Compare direct MCP hosting, managed Toolbox, REST conversion and optional API gateways. Move the main guide to Azure Architecture, add a standalone Toolbox azd example and diagrams, and distinguish source-verified Toolbox guidance from existing live ACA/APIM captures.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@hellices hellices changed the title docs(mcp): Azure MCP 통합 가이드와 azd 실습 docs(mcp): MCP 구성 방법과 Foundry Toolbox·azd 가이드 Sep 13, 2026

@my-reviewer-agent my-reviewer-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

이슈 1건을 인라인 코멘트로 남겼습니다.

리뷰 범위: 변경사항 일부만 검토했습니다.

Comment thread samples/azure-api-management/mcp-entra-lab/service/config.py Outdated
hellices and others added 2 commits September 13, 2026 15:28
관리 gateway, hosted agent runtime, Toolbox 탐색과 backend 호스팅을 구분하고 MCP protocol 변경을 부록으로 정리합니다. 실행 시나리오와 캡처는 samples로 옮기며 기존 리뷰의 URL 예외와 직접 의존성도 보완합니다.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Preserve the published branch history and verify the updated site pipeline with the MCP documentation.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@hellices hellices changed the title docs(mcp): MCP 구성 방법과 Foundry Toolbox·azd 가이드 docs(mcp): Azure MCP 운영 아키텍처와 Entra 인증 가이드 Sep 13, 2026

@my-reviewer-agent my-reviewer-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

검토 범위에서 보고할 이슈가 없습니다.

리뷰 범위: 변경사항 일부만 검토했습니다.

hellices and others added 2 commits September 13, 2026 22:00
서비스와 핵심 기능을 소개하고 APIM과 Toolbox의 protocol·OAuth·OBO 근거를 구분합니다. IQ 통합, 공식 토큰 비교 영상, 단순한 SVG와 실제 실행 기록 링크를 추가합니다.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Integrate main's topic-package publishing layout. Keep the MCP guide, references, validation case and azd samples together, retain old URLs as redirects, and preserve ignored local deployment state. Adapt the existing docs checks to the added topic.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@hellices hellices changed the title docs(mcp): Azure MCP 운영 아키텍처와 Entra 인증 가이드 docs(mcp): APIM·Toolbox·IQ와 MCP 인증·지원 범위 정리 Sep 13, 2026

@my-reviewer-agent my-reviewer-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

이슈 1건을 인라인 코멘트로 남겼습니다.

리뷰 범위: 변경사항 일부만 검토했습니다.

hellices and others added 5 commits September 13, 2026 22:53
사전 token 연결과 자동 OAuth, downstream OBO를 분리합니다. 기존 환경의 discovery·PKCE 선언·resource URI·token 검증·OBO를 재확인하고 공개용 결과와 수동 절차를 연결합니다. 본문 줄글은 표와 짧은 목록으로 정리합니다.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Entra의 Authorization Code와 PKCE 지원을 명확히 하고 MCP Server/APIM의 PRM 제공 및 JWT 검증과 분리합니다. Metadata 관측은 제품 미지원 판정이 아닌 client 상호운용성 노트로 유지합니다.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Integrate the current main branch, use practical purpose/subject tags for MCP documents, and keep one canonical copy of the walkthrough images. Update repository-count expectations for the MCP topic without changing discovery behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
새 터미널에서 실습 kubeconfig 경로를 명시하고 검증해 기본 클러스터로의 잘못된 연결을 방지합니다. 공개 Entra/APIM 계약을 기준으로 API 앱과 client 앱, v2 token claims, PRM 및 JWT 정책 구성을 명확히 합니다.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
HTTP MCP tools와 Entra 인증의 지원 구성, 목적별 읽기 경로와 완료 기준을 안내합니다. 실험 범위 설명은 사례에 유지하고 본문 중복·미확인 중심 비교를 줄이며 명시적인 제품 제약을 정리합니다.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

@my-reviewer-agent my-reviewer-agent Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

이슈 1건을 인라인 코멘트로 남겼습니다.

리뷰 범위: 변경사항 일부만 검토했습니다.

APIM과 Toolbox의 서비스 정의, 활용 상황, 핵심 기능을 본문에 설명합니다. 인증은 통제 지점과 사용자 권한으로 요약하고 상세 구성도와 완료 기준은 인증 참고로 연결해 실증 예제와 중복을 줄입니다.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@hellices hellices changed the title docs(mcp): APIM·Toolbox·IQ와 MCP 인증·지원 범위 정리 docs(mcp): APIM·Toolbox·IQ 활용과 선택 가이드 Sep 13, 2026
hellices and others added 2 commits September 14, 2026 08:09
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
임시 인증 설정 변경 전에 EXIT trap을 등록하고 원래 실패 코드를 유지합니다. 복구 오류를 표시하고 고유 백업과 새 셸의 수동 복구 절차를 제공하며 다른 환경의 백업 적용을 차단합니다.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@hellices
hellices merged commit 0acee8a into main Sep 13, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants