Skip to content

Claude engine: pass --strict-mcp-config to avoid a TCP_DENIED for api.anthropic.com on every run #64953

Description

@benissimo

Summary

With gh-aw v0.89.21 (AWF v0.28.23), every Claude-engine run logs one TCP_DENIED for api.anthropic.com:443 from the agent container, within a second of Claude Code starting. The run itself is fine. But the denial lands in the firewall summary on every run, and users read it as a regression after upgrading.

Cause

Claude Code fetches Anthropic's MCP registry (GET /mcp-registry/v0/servers on api.anthropic.com, unauthenticated) at startup. The result only marks which configured MCP servers count as "official" for Claude Code's analytics events; nothing functional reads it. The fetch ignores ANTHROPIC_BASE_URL, so it doesn't go through the api-proxy. Since api.anthropic.com is no longer on the agent allowlist, squid denies it, and claude-debug.log records:

[ERROR] Failed to fetch MCP registry: self signed certificate

Claude Code skips this fetch when it runs with --strict-mcp-config.

Proposal

Have the Claude engine pass --strict-mcp-config next to the --mcp-config argument it already adds (pkg/workflow/claude_engine.go). gh-aw is the sole MCP source for the agent, so no gh-aw-configured server is lost. Strict mode also stops Claude from loading MCP config committed in the target repo (for example .mcp.json), which looks consistent with gh-aw owning the agent's MCP surface.

Re-allowlisting api.anthropic.com for the agent would also silence it. But that reopens the direct agent-to-Anthropic path the api-proxy closes, for a call with no functional value.

Evidence

Same workflow (agent-review-pr), Claude Code 2.1.285, Sonnet 5.5, compiled with gh-aw v0.89.21:

  • Without the flag: sandbox/firewall/logs/access.log has 172.30.0.20 api.anthropic.com:443 ... CONNECT 200 TCP_DENIED:HIER_NONE, and the debug log has the error above.
  • With engine.args: ["--strict-mcp-config"]: 0 TCP_DENIED and no api.anthropic.com connection from the agent. There's no registry line in the debug log, and the GitHub MCP server via the MCP gateway still connects (MCP server "github": Successfully connected (transport: http)).

A local check on Claude Code 2.1.287 matches: the debug log shows [mcp-registry] Loaded 294 official MCP URLs by default and no registry fetch with --strict-mcp-config. Setting CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1 also suppresses it, but it turns off feature-flag fetching too, so it seems a poorer default.

As a workaround, users can add engine.args: ["--strict-mcp-config"] to the workflow's engine: block.

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions