Skip to content

[Incident] Deployment failure: aoai-model — Copilot CLI 400 (org verification required for reasoning summaries) #61892

Description

@github-actions

Environment

aoai-model — deployment status: failure

Summary

The Smoke Copilot - AOAI (Entra) scheduled smoke workflow failed at the "Execute GitHub Copilot CLI" step. The Copilot CLI harness (copilot-harness) exhausted all 3 retries (4 total attempts) invoking the model backend, and every attempt returned the same upstream 400 error from the Azure OpenAI / OpenAI-compatible endpoint behind the o4-mini-aw model configured for this workflow:

400 Your organization must be verified to generate reasoning summaries. Please go to: (platform.openai.com/redacted) and click on Verify Organization. If you just verified, it can take up to 15 minutes for access to propagate.

This is a provider/account configuration issue on the model backend side (organization verification required to use reasoning-summary output for the o4-mini-aw model), not a regression introduced by a recent code change in this repository. The most recent commit on main prior to the failure (9894316e, "chore: update planned Go, Actions, and docs dependencies", #61774) does not touch inference routing, Copilot harness, or AOAI/Entra configuration.

Evidence

Log excerpt — repeated 400 errors across all 4 attempts
[copilot-harness] inference routing: mode=cli configuredModel="o4-mini-aw" endpoint=managed-by-copilot-cli
[copilot-harness] attempt 1: spawning: copilot --add-dir /tmp/gh-aw/ ... --autopilot --max-autopilot-continues 2 ...
400 Your organization must be verified to generate reasoning summaries. Please go to: (platform.openai.com/redacted) and click on Verify Organization. If you just verified, it can take up to 15 minutes for access to propagate.
Changes    +0 -0
Duration   0s
[copilot-harness] attempt 1 failed: exitCode=1 failureClass=partial_execution ... hasOutput=true tokenCount=0 attemptDurationMs=1102 retriesRemaining=3
[copilot-harness] attempt 1: partial execution — will retry with --continue (attempt 2/4)
... (attempts 2, 3 repeat identical 400 error) ...
[copilot-harness] attempt 4: process closed exitCode=1 ... attemptDurationMs=907 retriesRemaining=0
[copilot-harness] all 3 retries exhausted — giving up (exitCode=1)
[copilot-harness] awf-reflect: models fetch returned 401 for (apiproxy/redacted)
[copilot-harness] awf-reflect: models fetch returned 401 for (apiproxy/redacted)
[copilot-harness] done: exitCode=1 totalDuration=44s
##[error]Agent execution exited with code 1
##[error]Process completed with exit code 1.
Job step summary (relevant steps)

All setup, build, and infra steps (Docker image build, MCP Gateway, Playwright, cache-memory, safe-outputs config) completed successfully. Only Execute GitHub Copilot CLI (step 53) failed; all subsequent cleanup/reporting steps ran and completed normally.

Suggested Remediation

  1. Verify the organization behind the o4-mini-aw model endpoint at (platform.openai.com/redacted) (per the error message). If verification was already submitted, allow up to 15 minutes for propagation and re-run the smoke workflow.
  2. Confirm whether o4-mini-aw is expected to use reasoning summaries for this workflow — if not required, check whether the AOAI/Entra model routing config can disable that output mode as a short-term workaround.
  3. Check the two 401 responses from api-proxy:10000/v1/models and api-proxy:10001/v1/models seen during awf-reflect — confirm these are expected/benign (unused endpoints) and not a secondary auth issue with the Entra/AOAI credentials.
  4. Re-run the failing workflow once the organization verification propagates, to confirm recovery.

Warning

Firewall blocked 1 domain

The following domain was blocked by the firewall during workflow execution:

  • github.com/ghapi

[!TIP]
github.com/ghapi is blocked because GitHub API access uses the built-in GitHub tools by default. Instead of adding github.com/ghapi to network.allowed, use tools.github.mode: gh-proxy for direct pre-authenticated GitHub CLI access without requiring network access to github.com/ghapi:

tools:
  github:
    mode: gh-proxy

See GitHub Tools for more information on gh-proxy mode.

To allow these domains, add them to the network.allowed list in your workflow frontmatter:

network:
  allowed:
    - defaults
    - "github.com/ghapi"

See Network Configuration for more information.

Generated by 🚨 Deployment Incident Monitor · copilot · auto · 41.4 AIC · ⌖ 7.57 AIC · ⊞ 6.1K · ◷

  • expires on Sep 25, 2026, 4:25 PM UTC-08:00

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions