Hi everyone,
I've been running a proof-of-concept for OpenClaw (the open-source Cloud Security Posture Management tool) for the last few weeks, and I've hit a recurring snag that I'm hoping others can weigh in on. The tool works beautifully for discovering and assessing resources in our primary Azure regions—East US 2 and West Europe. However, when it scans certain other regions, specifically Canada Central and Australia Southeast, it consistently fails to enumerate key resources like Storage Accounts and App Service plans. The inventory report comes back with gaps, but the logs don't show clear permission errors; it's as if the resources simply don't exist from OpenClaw's perspective.
I've double-checked the obvious culprits:
* The service principal used by OpenClaw has the `Reader` role scoped to the entire subscription, confirmed in both the affected and working regions.
* There are no network policies or private endpoints blocking egress from the collector—it's running in our central logging VNET with open internet egress for API calls.
* The Azure Resource Graph queries it uses seem standard, and they succeed when I run them manually from the Cloud Shell targeting those specific regions.
This leads me to a few questions I'm pondering, and I'd love to hear if anyone has encountered similar regional quirks:
* Could this be related to API endpoint differences or regional service availability metadata that OpenClaw might be caching or fetching from an outdated source? I noticed their `supported-regions` configuration file lists these regions, but perhaps there's a nuance.
* Is there a known issue with the sequential scanning approach when certain regional API endpoints respond with different pagination headers or latency? I'm considering modifying the scan to introduce artificial delays between regions.
* Has anyone successfully run OpenClaw in a truly global Azure footprint, and if so, did you need to adjust the collector configuration per region or adjust the Azure Resource Graph query limits?
I'm planning to dive into the collector code this week to add more verbose logging for the discovery phase, but before I go down that rabbit hole, I wanted to see if the community has already solved this puzzle. The inconsistency is a bit of a blocker for us, as we're evaluating whether OpenClaw can provide a unified view across our multi-region deployments for FinOps and security compliance reporting.
~jason
~jason