Mastra and Defang: deploy an AI agent to Azure

Learn how to move a local Mastra app to Azure with Defang, configure a Postgres secret, and provision OIDC trust for GitHub Actions.

Player not loading? Watch on YouTube

Jordan, an engineer at Defang, walks through deploying a TypeScript AI agent built with Mastra to a Microsoft Azure account. The sample generates workload items and lets users ask the agent which items seem related. He describes the development app as running entirely locally with Docker Compose Model Runner and locally hosted models.

The deployment starts in the Defang portal with a GitHub sign-in and selection of the Mastra sample. Jordan configures a Postgres password, which he says Defang stores in the stack's GitHub Actions environment. He then names the stack, connects Azure, and selects a subscription. The portal also offers an invite link so someone with cloud access can configure trust, a workflow he suggests for enterprise customers requesting private deployments.

Defang provisions an OIDC trust relationship between GitHub Actions and Azure. Jordan explains that this avoids long-running credentials. He chooses West US and starts the deployment, then checks its progress in GitHub Actions.

The first deployment provisions Postgres, Redis, a web server, a worker, and supporting access and networking resources. Jordan says later deployments replace only what is needed. He opens the deployed app and inspects a production stack diagram containing two language models, then checks the resources in Azure.