Skip to content

Incoming call not answered – Cosmos DB RBAC permission errors, missing connection_string fields, and App Configuration access issues #499

Description

Description

I am trying to deploy call-center-ai in a fresh Azure environment (US region) to answer inbound calls from Tunisia on a US toll‑free number. The call event reaches the Azure Storage queue, but the application fails to process it due to multiple configuration and permission problems.

Steps to reproduce

  1. Created a new Azure resource group call-center-ai-us-rg in eastus2.
  2. Deployed the following resources (via CLI):
    • Communication Service wics-acs-us (data location unitedstates)
    • Azure OpenAI wics-openai-us (deployed gpt-4.1-nano)
    • Cosmos DB wics-cosmos-us (NoSQL, database CallCenterDB, container conversations)
    • Storage Account wicsstorageus (queues: call-..., post-..., sms-..., training-...)
    • AI Search wics-search-us
    • App Configuration wics-appconfig-us
  3. Purchased a US toll‑free number +18662353319 and enabled inbound calling with Call Automation.
  4. Created an Event Grid subscription on the Communication Service to send IncomingCall events to the storage queue call-18662353319.
  5. Configured config.yaml with connection strings for all services (see attached).
  6. Started ngrok tunnel and the uvicorn server.
  7. Called the US number from a Tunisian phone.

Expected behavior

The call is answered by the bot.

Actual behavior

The call rings but is never answered. The server logs show various errors:

  • AttributeError: 'CommunicationServicesModel' object has no attribute 'connection_string'
  • AttributeError: 'QueueModel' object has no attribute 'connection_string'
  • CosmosHttpResponseError: (Forbidden) ... does not have required RBAC permissions to perform action [Microsoft.DocumentDB/databaseAccounts/readMetadata]
  • HttpResponseError: Operation returned an invalid status 'Forbidden' (App Configuration)

The event is present in the queue (verified via az storage message peek) but the call_event function never runs because of these errors.

Configuration (redacted)

public_domain: "https://chanceled-tomiko-promissorily.ngrok-free.dev"
version: "0.0.0"

communication_services:
  connection_string: "endpoint=https://wics-acs-us.unitedstates.communication.azure.com/;accesskey=..."
  access_key: "..."
  endpoint: "https://wics-acs-us.unitedstates.communication.azure.com/"
  phone_number: "+18662353319"
  call_queue_name: "call-18662353319"
  post_queue_name: "post-18662353319"
  sms_queue_name: "sms-18662353319"
  training_queue_name: "training-18662353319"
  recording_container_url: "https://wicsstorageus.blob.core.windows.net/recordings"
  resource_id: "/subscriptions/.../providers/Microsoft.Communication/communicationServices/wics-acs-us"

queue:
  connection_string: "DefaultEndpointsProtocol=...;AccountName=wicsstorageus;AccountKey=..."
  account_url: "https://wicsstorageus.queue.core.windows.net"
  call_name: "call-18662353319"
  post_name: "post-18662353319"
  sms_name: "sms-18662353319"
  training_name: "training-18662353319"

database:
  cosmos_db:
    endpoint: "https://wics-cosmos-us.documents.azure.com:443/"
    database: "CallCenterDB"
    container: "conversations"

# ... other sections (llm, ai_search, etc.) ...

Error logs (excerpt)

AttributeError: 'CommunicationServicesModel' object has no attribute 'connection_string'
...
azure.cosmos.exceptions.CosmosHttpResponseError: (Forbidden) Request blocked by Auth wics-cosmos-us : Request is blocked because principal ... does not have required RBAC permissions to perform action [Microsoft.DocumentDB/databaseAccounts/readMetadata]
...
azure.core.exceptions.HttpResponseError: Operation returned an invalid status 'Forbidden' (App Configuration)

Environment

  • Region: East US 2 (except ACS data location unitedstates)
  • Python: 3.13
  • SDK: azure-communication-callautomation latest
  • ngrok: Free tier, HTTPS tunnel
  • Subscription: Sparkle Azure subscription (student/credits)

Questions

  1. Does the project require RBAC roles for Cosmos DB (e.g., "Cosmos DB Built-in Data Contributor")? I am using a connection string, but the code seems to be using token credentials.
  2. Why are connection_string fields missing from CommunicationServicesModel and QueueModel by default? I added them manually, but they are not in the original code.
  3. Is App Configuration mandatory? Can it be disabled to avoid the Forbidden error?
  4. How can I make the Azure Queue Storage trigger work without a manual poller? The AzureQueueStorage class does not seem to poll automatically.
  5. Could you provide a complete, working config.yaml for a new US deployment using connection strings (not RBAC) for all services?

Thank you!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions