Chapter 3 of 6
Confirm:
- The approved nonproduction scope and change record name the delivery owner.
- The pinned Foundry Agent Service policy assistant endpoint and its network path match the approved configuration. The Foundry platform owner confirms both. (The private-networking and governed-agent controls establish these prerequisites.)
- The existing supported APIM instance has a system-assigned managed identity. The gateway owner confirms its tier and network path.
- The API product, identity, network, safety, operations, and delivery owners can record decisions and resolve readiness gaps.
- The deployment operator has time-bound Contributor on the exact APIM resource group.
- The APIM identity has Foundry Agent Consumer (
eed3b665-ab3a-47b6-8f48-c9382fb1dad6) on the individual governed agent. It has Cognitive Services User (a97b65f3-24c7-4388-baec-2e87135dc908) on the approved Content Safety resource. - The Content Safety backend and Application Insights logger use managed identity. The product owner issued one workload-specific APIM subscription and stored its key in the approved secret store.
Implementation files#
| Type | File | Consumer |
|---|---|---|
| Record | artifacts/gateway-design-record.json | The gateway deployment operator and preflight scripts |
| Deployment | artifacts/gateway/main.bicep | The Session 06 APIM deployment scripts |
| Deployment | artifacts/gateway/apis/policy-assistant-responses.openapi.json | The API Management API import |
| Deployment | artifacts/gateway/policies/policy.xml | The API Management gateway runtime |
| Deployment | artifacts/governance/gateway-control.json | The Session 06 preflight and deployment scripts |
| Record | artifacts/governance/model-routing-decision.md | The API product, platform, safety, and operations owners |
| Deployment | artifacts/environments/sandbox.json | The Session 06 preflight and deployment scripts |
Keep subscription IDs, backend URLs, keys, bearer tokens, prompts, responses, and customer data out of the repository.