Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
29 commits
Select commit Hold shift + click to select a range
e230be1
feat(hubs): add Azure Resource Manager ingestion
MSBrett Aug 24, 2026
3f94f79
Merge remote-tracking branch 'origin/dev' into features/finops-hubs-a…
MSBrett Aug 24, 2026
c5f116e
feat(dashboard): add AI and emerging workloads view
MSBrett Aug 24, 2026
8ddd21d
feat(hubs): collect availability zone and SKU restriction supply data
MSBrett Aug 24, 2026
e5ed70f
feat(dashboard): add the FinOps hub capacity dashboard canvas
MSBrett Aug 24, 2026
c05fc7c
chore: ignore local knowledge-graph tool output
MSBrett Aug 24, 2026
50d51be
Merge branch 'features/psychic-fiesta' into features/finops-hubs-arm-app
MSBrett Aug 24, 2026
bdfeeac
feat(dashboard): add navigable Compute capacity details
MSBrett Aug 24, 2026
e74b6ee
fix(hubs): secure ARM paging and preserve scope identity
MSBrett Aug 24, 2026
3746816
feat(hubs): expand quota ingestion
MSBrett Aug 26, 2026
d50b2b2
fix(hubs): complete ARM failure handling
MSBrett Aug 26, 2026
ae6d96d
fix(hubs): harden ARM query orchestration
MSBrett Aug 29, 2026
fba96ff
Revert "fix(hubs): harden ARM query orchestration"
MSBrett Aug 29, 2026
ffb9615
fix(hubs): restore ingestion and quota contracts
MSBrett Aug 29, 2026
1e9c36a
chore: ignore local knowledge-graph tool artifacts
MSBrett Aug 30, 2026
de65482
feat(finops-hub): harden ingestion and expand dashboard
MSBrett Aug 30, 2026
6205598
Merge remote-tracking branch 'origin/dev' into features/finops-hubs-a…
MSBrett Aug 30, 2026
246ae4b
fix(dashboard): remove fabricated MACC query
MSBrett Aug 31, 2026
dbb13f9
chore(hubs): update dashboard extension, quota catalog queries, and g…
MSBrett Aug 31, 2026
aa21567
fix(hubs): remediate PR review findings for ARM ingestion
MSBrett Sep 1, 2026
a7d697c
feat(dashboard): add Azure AI capacity matrix view
MSBrett Sep 1, 2026
d4f57fe
feat(workbooks): add FinOps hub workbook
MSBrett Sep 3, 2026
32882c6
feat(workbooks): add FinOps hub supply views
MSBrett Sep 3, 2026
d5ae204
revert(workbooks): remove rejected FinOps hub workbook
MSBrett Sep 3, 2026
db653d0
Revert "revert(workbooks): remove rejected FinOps hub workbook"
MSBrett Sep 3, 2026
a0c365e
feat(dashboard): add AI workload dashboards
MSBrett Sep 4, 2026
9692adc
fix(hubs): collapse ARM query engine to 2 pipeline layers, cap shared…
MSBrett Sep 6, 2026
08b7986
perf(hubs): remove shared CopyQuery concurrency ceiling in ARM ingestion
MSBrett Sep 7, 2026
287c6f3
fix(hubs): paginate ARM subscription list in ExecuteTenant
MSBrett Sep 7, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
42 changes: 42 additions & 0 deletions .github/extensions/ftk-local-dashboard/PRODUCT.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
# Product

## Register

product

## Users

FinOps practitioners, cloud engineers, and consultants who need to analyze Azure cost data locally without deploying Azure resources. They run this dashboard as a GitHub Copilot canvas while they explore the data model, validate large datasets, or analyze data in disconnected or on-premises environments. They are data-fluent, comfortable with KQL and Azure concepts, and expect density and precision over decoration. They want numbers fast.

## Product Purpose

A FinOps hub dashboard that connects to a local Kusto emulator or a remote Azure Data Explorer cluster. It provides cost, allocation, rate optimization, usage, anomaly, AI token, AI Foundry platform, agent operations, and supply views. The AI Foundry view reproduces the canonical Azure Managed Grafana platform dashboard across every accessible Cognitive Services account. It uses Azure Monitor platform metrics, supports account and deployment drill-down, and replaces fixed prices with FinOps Hub rates. The Supply workspace keeps quota, billed demand, inventory, physical supply, and pricing commitments separate. Success means that a practitioner can load hub data, select a view, and answer a FinOps question in one session.

The separate Foundry agents view shows Microsoft Foundry agent activity from application dependencies and traces. It shares the Foundry account and time controls. Every panel derives from one cached query of the workspaces that are connected to accessible Microsoft Foundry projects. Selecting a Foundry account scopes the result by Foundry project.

Both Microsoft Foundry operations views show estimated cost beside the token usage that produced it. The Foundry infrastructure view supports deployment and time-bucket estimates from platform metrics. The Foundry agents view supports uncached input, cached input, output, model, agent, and individual-run estimates from traces. Agent run cost isn't a `Costs()` join. Exact `Costs()` matches for separately billed agent resources appear as a distinct authoritative billed-cost field. Partial price coverage and telemetry gaps stay visible.

## Brand Personality

Precise. Grounded. Efficient. The interface should feel like a well-calibrated instrument, not a product pitch. Numbers are the focus, and the chrome disappears.

The canvas is a desktop-only workspace with a minimum width of 1280 pixels. Do not add mobile layouts or narrow-screen reflow.

## Anti-references

- Consumer personal finance dashboards (Mint, Copilot Money) β€” too soft, too colorful
- SaaS marketing dashboards (hero metric templates, gradient text, glassmorphism cards)
- Over-designed BI tools with heavy chrome, deep sidebars, and modal-heavy workflows
- Any interface that prioritizes looking impressive over being immediately useful

## Design Principles

1. **Numbers first**: KPIs and data are the primary visual elements. Supporting chrome, such as headers, tabs, and labels, recedes.
2. **GitHub-native**: Use GitHub design tokens (`--background-color-default`, `--text-color-default`, and others) so the panel feels like an extension of Copilot.
3. **Dense by design**: FinOps data is multidimensional. Don't sacrifice information density for whitespace.
4. **Explicit state**: Treat loading, error, empty, and no-data states as primary states. Every panel handles each state.
5. **Zero ceremony**: Don't add animated introductions or onboarding tours. Open the panel and see the data.

## Accessibility & Inclusion

WCAG AA minimum. SVG charts include `<title>` elements for screen-reader context. Interactive controls have ARIA roles and labels. Capacity heatmaps include values and states as text. Users can operate the tabs with a keyboard. The interface respects reduced-motion preferences.
86 changes: 86 additions & 0 deletions .github/extensions/ftk-local-dashboard/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
# FinOps hub dashboard canvas

The FinOps hub dashboard is a repository-scoped GitHub Copilot canvas. It connects to a local Kusto emulator or a remote Azure Data Explorer cluster.

The canvas supports desktop layouts only. Its minimum width is 1280 pixels. Narrow host surfaces scroll horizontally and do not reflow the dashboard.

The dashboard includes these views:

- Cost overview
- Allocation
- Rate optimization
- Usage and unit economics
- Anomalies and forecast
- AI tokenomics
- AI Foundry platform operations
- Foundry agents
- AI and emerging workloads
- Supply
- Read-only KQL query editor

## Supply

The Supply workspace shows seven quota areas: App Service, Azure AI, Compute, Azure SQL, Storage, capacity reservations, and Premium SSD v2.

The workspace doesn't combine unlike readings into one score. It keeps these concepts separate:

- Provider quota entitlement
- Billed demand
- Observed resource inventory
- Physical Azure capacity
- Pricing commitments

Compute queries load their base KQL from `src/queries/catalog`. The family heatmap reads quota at family level. It reads offer restrictions from the smallest-vCPU SKU in each family and region. Only registered Compute metrics support quota utilization and headroom calculations. Unknown metrics stay visible as descriptive rows. Stale or invalid rows don't receive quota-health calculations.

App Service uses the catalog-backed `AppServiceUsage` source. Its matrix shows exact plan SKU by region, including Total Regional VMs as a separate row. The left bar reports subscription quota status, while the percentage reports aggregate quota utilization. This view doesn't infer physical regional capacity or combine billed demand with quota.

Azure SQL uses the catalog-backed `SqlSubscriptionUsage` source. Its matrix includes the current regional quotas for Azure SQL Database and Synapse vCores, logical servers, and the three SQL Managed Instance hardware generations. Legacy subnet and single-vCore counters and subscription-wide free-offer counters don't receive utilization calculations. Zero and negative limits remain visible as no usable quota instead of being treated as zero utilization or unlimited capacity. Region access and zone-redundant access require separate validation because the usage rows don't report those permissions.

Compute, App Service, and Azure SQL share the dependency-free controls in `public/ui.js` and `public/ui.css`. These helpers render filters, matrix panes, detail tabs, and pagination without owning service data or quota semantics. Other Supply areas continue to use their existing controls.

## AI Foundry

The AI Foundry view uses the configured tenant ID. Azure Resource Graph finds accessible Azure OpenAI and AI Services accounts.

The view reproduces the 11 panels in the canonical Azure Managed Grafana dashboard. It queries these Azure Monitor platform metrics:

- `InputTokens`
- `OutputTokens`
- `TotalTokens`
- `ModelRequests`
- `TimeToLastByte`
- `AzureOpenAITTLTInMS`
- `AzureOpenAITokenPerSecond`
- `AzureOpenAIContextTokensCacheMatchRate`

The default time range is seven days. The dashboard applies the same deployment and status-code filters, aggregations, legends, chart styles, and 24-column panel layout as the Grafana dashboard.

The estate view groups accounts by subscription and region and sends each regional Metrics Batch request for no more than 50 resources. Select an account to drill down to its model deployments. The dashboard uses the configured tenant ID for resource discovery and Azure Monitor authentication.

The **Estimated Cost** panel replaces the Grafana dashboard's fixed prices with rates from `Prices()`. Input, output, and total token tiles and charts also show the corresponding estimated cost for each deployment and time bucket. A match requires the exact model, version, deployment SKU, region class, currency, billing scope, token direction, and pricing block. The view uses the current-period rate first. If that rate isn't available, it can use the immediately previous monthly price sheet and labels the estimate as provisional. It doesn't use older rates. Unmatched or ambiguous usage remains unpriced. Only `Costs()` is authoritative for billed and effective cost.

## Foundry agents

The Foundry agents view uses Azure Resource Graph to find accessible Microsoft Foundry projects. One Azure Resource Manager batch request gets each project's Application Insights connection. The view queries only the linked Log Analytics workspaces. Every panel and control uses the same 30-second cached tenant and time-range result.

The view identifies Microsoft Foundry `invoke_agent`, `chat`, and `execute_tool` spans. Each agent row must have a `microsoft.foundry.project.id` value. Chat spans without an agent identity are assigned by operation ID only when the trace has exactly one Microsoft Foundry agent. Selecting a Foundry account includes only agents whose project is under that account.

Estimated run cost uses uncached input, cached input, and output tokens from chat spans. Each token class uses an eligible `Prices()` rate with the same model, version, deployment SKU, region class, billing scope, currency, and effective-period checks as the Foundry view. Token charts and agent, model, and recent-run tables show each token class beside its estimated cost. Missing or conflicting rates remain explicit as partial or unmatched coverage. Provisioned deployments aren't presented as token-priced.

Trace estimates aren't billed cost. Exact `Costs()` resource ID matches appear in a separate authoritative billed-cost field. Foundry telemetry identities aren't treated as cost resource IDs.

## Run the canvas

Reload GitHub Copilot extensions after you change the source. The repository-scoped extension must report `sourceScope: "project"` from the `get_build_info` action.

The installed user extension uses `http://127.0.0.1:47821/`. The repository-scoped extension uses `http://127.0.0.1:47822/` so both sources can run during development. Connection preferences remain in the user's Copilot extension artifacts directory and aren't stored in the repository.

The tenant ID controls remote Hub authentication and Azure resource discovery. Local Hub queries do not authenticate. The AI Foundry view still requires the tenant ID in local mode. The dashboard passes the tenant to Azure CLI for each access token. Authentication does not inherit the active Azure CLI tenant. The dashboard does not save access tokens or other credentials.

## Test the canvas

Run the dependency-free test suite:

```console
npm run test-dashboard
```
Loading
Loading