# 3.9.1

**Release Date:** September 2, 2026

---

## ✨ New Features

- **smithy** - Migrated the Smithy chat model to gpt-5.6-luna and bumped `saif-resources` to 3.9.0 ([`fa992a04`](https://github.com/saif-corp/forge/commit/fa992a04eb15c6843a320126ca8d0974bc6e7455) | [#1118](https://github.com/saif-corp/forge/pull/1118))

---

## 🐛 Bug Fixes

- **terraform** - Fixed an Okta variable-set collision that broke Azure infra tenant resolution across seven Forge modules. The Okta credentials variable set injects `tenant = "ext"` into every app workspace with external auth enabled (the default), which poisoned `module.names.Tenants` lookups (only `Corporate`/`External` keys exist) and caused `Invalid index` errors during plan/apply. `saif-resources/modules/environment`, `saif-api-service`, `saif-web-service`, `saif-staticsite-service`, `saif-event-service`, `saif-event-subscriber-service`, and `site/infra/app` now resolve the Azure infra tenant from a hardcoded `Corporate` value instead of the caller-supplied `var.tenant`, since no app in the fleet legitimately needs a non-Corporate Azure tenant. `saif-event-subscriber-service` also had a related OTEL deploy-tenant bug fixed in the same change. ([`581e441a`](https://github.com/saif-corp/forge/commit/581e441a12fd708acb879b71c232173852a89c22) | [#1119](https://github.com/saif-corp/forge/pull/1119))

---

## 🔄 Breaking Changes

### `variable "tenant"` no longer affects Azure infra tenant resolution

**Scope:** Terraform — `saif-resources/modules/environment`, `saif-api-service`, `saif-web-service`, `saif-staticsite-service`, `saif-event-service`, `saif-event-subscriber-service`, `site/infra/app`

`variable "tenant"` is still accepted on these modules for backward compatibility, but it's now ignored for Azure infra tenant resolution, which is hardcoded to `"Corporate"`. Any caller previously supplying a non-`Corporate` value (e.g. `"External"`) will now silently get `Corporate` naming and workspace behavior instead.

**Impact:**

- No caller relying on a non-`Corporate` Azure tenant value was found in the current fleet, so this fix ships without a required migration.
- Any future or undiscovered caller depending on `var.tenant` resolving to a non-`Corporate` Azure tenant would need a follow-up change — the variable no longer has any effect on that resolution.

---

## 📋 Additional Notes

- Total commits: 6
- Files changed: 29
- Contributors: Emmitt Johnson, GitHub

---

### Support

- 📧 Teams Support Channel: [Support](https://teams.microsoft.com/l/channel/19%3Acb611810fb0b42b080cfff5590bdd51c%40thread.tacv2/Support?groupId=514d2dac-2d62-48ce-bf99-0fa0ce39469c&tenantId=a86cb8ed-369b-4df5-ace5-43811f6e08cf)

---
