Skip to content

ci(azure): Deploy to Azure Container Apps has failed on every main run for 3 weeks — no Azure change since 2026-07-19 is deployed #1794

Description

@cristim

The Azure deploy has not succeeded on main in the last 100 workflow runs, going back to at least 2026-07-19. Found while checking whether #1223 was stale.

Deploy to Azure Container Apps, branch=main, last 100 runs:
  failure:   68
  cancelled: 32
  success:    0
  oldest run in window: 2026-07-19

It fails at Terraform Apply, not at build or test:

Error: authorization.RoleAssignmentsClient#Create: Failure responding ...
Error: loading Role Definition List: could not find role 'CUDly Reservation Purchaser (custom) - ***'

Blocked resources: azurerm_role_assignment.cost_management_reader and azurerm_role_assignment.subscription_reader.

Why this went unnoticed for three weeks

CI - Build & Test is green on main and has been across every recent merge (a37e14790, d6e60f637, 726389b48). Every PR gate we look at is green. The deploy workflow is a separate run that nothing surfaces, so "CI is green" has been true and irrelevant at the same time.

This is the same shape as the multi-module gap in #1751: a check that looked comprehensive was scoped to something narrower than anyone assumed. There, ./... covered one module of six. Here, "CI green" covers build and test but not deploy.

What it means for what we have been merging

If this workflow is what ships the running Azure service, then no Azure change merged since 2026-07-19 is live. That window includes several providers/azure money-path fixes merged in the last day:

Verify that inference before acting on it. I have established the workflow fails; I have not established what it deploys, whether another path ships the Azure service, or whether the failing role assignments are the last step or an early one that aborts before anything useful happens. A partial apply that fails at the end has different consequences from one that fails before deploying the app image.

The immediate cause

A custom role definition named CUDly Reservation Purchaser (custom) - <subscription> does not exist in the target subscription, so Terraform cannot resolve it to assign it.

Establish which of these it is before fixing:

  1. The role was never created in this subscription (bootstrap step missed or a new subscription).
  2. The role was created and has since been deleted or renamed.
  3. The Terraform name template drifted from what the bootstrap creates (a suffix, a casing change, an interpolation that renders differently).
  4. The deploy identity lacks permission to read role definitions, so the role exists but the lookup returns nothing. This one looks like a missing role but is a permissions failure, and the error text does not distinguish it.

Option 4 is worth ruling out explicitly: Microsoft.Authorization/roleDefinitions/read is a separate grant from the ability to create assignments, and a caller without it sees an empty list rather than a permission error.

Verification for whatever lands

  • A deploy run on main reaching success, not merely getting past this error to a different one.
  • The two blocked role assignments present in the subscription afterwards.
  • Confirm the deployed image actually corresponds to current main, since three weeks of failed applies may have left state that a single success does not fully reconcile.

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions