Describe the client bank/anthropic's OPTIONAL block is for - #121
Merged
Merged
Conversation
Comments only — no uncommented line changes, `hosts` is untouched, and the boundary is exactly what it was. What changes is whether the block describes a client anyone is running. Measured on one lab: Claude Code 2.1.234, every host that appeared in its trail over one run. Two the block did not offer, and one it offers that never came up. downloads.claude.ai is the auto-updater, retrying and failing 32 times in that run. It is listed with the reason NOT to enable it: a lab that pins CLAUDE_VERSION updates by rebuild, so blocked is the right default and the only cost is a noisy trail — which DISABLE_AUTOUPDATER fixes without opening egress. http-intake.logs.us5.datadoghq.com is client telemetry, and naming it matters because sentry.io was already here under "error reporting": someone enabling that line to quiet telemetry blocks would find it changed nothing. The `us5` shard is per-account, so the line says to copy what your own trail shows rather than this one. statsig.anthropic.com keeps its line and gains the finding — never contacted in that run, with 2.1.x fetching gates over api.anthropic.com instead. Annotated rather than deleted: one lab is thin evidence for removing an option, and a commented line costs nothing. The evidence is scoped in the file itself, since a list of hosts one client generation contacted is not a claim about the product. Deliberately not here: raw.githubusercontent.com, which the trail cannot attribute between the client and the agent's own work, because the proxy logs host and method and no path. And the Remote Control note #119 suggested — #120 measured that conclusion wrong, so it should not ship in the shape #119 wrote it. Refs #119 Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BLuSkuyQUfogZpMJ5fVMF9
lpezet
added a commit
that referenced
this pull request
Aug 19, 2026
The release is #121 and nothing else: comments in one bank entry's allowlist, no uncommented line changed and no `hosts` change, so there is no image, addon or manifest to rebuild. The Upgrading section carries the one thing that is not obvious. An entry's allowlist is copied into the deployment at install time, so a deployment that already has bank/anthropic installed holds its own copy and never sees these comments. Nothing behaves differently for it — every line involved is commented on both sides — but "nothing to do" would leave someone wondering why their own /etc/agent-allowlist did not change, so the entry says to diff it if the annotations are wanted. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BLuSkuyQUfogZpMJ5fVMF9
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #119, minus the one part of it that #120 retracted.
What changes
bank/anthropic/allowlist, comments only. No uncommented line changes,hostsis untouched, and the boundary is exactly what it was — this is about whether the OPTIONAL block describes a client anyone is actually running.downloads.claude.ai— the auto-updater, retrying and failing 32 times in the reported run. Listed with the reason not to enable it: a lab that pinsCLAUDE_VERSIONupdates by rebuild, so blocked is the right default, and the only cost is a noisy trail — whichDISABLE_AUTOUPDATERfixes without opening egress.http-intake.logs.us5.datadoghq.com— client telemetry. Worth naming becausesentry.iowas already here under "error reporting", so anyone reaching for that line to quiet telemetry blocks would find it changed nothing. Departs slightly from the issue: theus5shard is per-account, so the comment says to copy what your own trail shows rather than trusting this line.statsig.anthropic.com— keeps its line, gains the finding. Never contacted in that run; 2.1.x fetches gates overapi.anthropic.com(GET /api/claude_code,POST /api/event_logging, both credentialed). Annotated rather than deleted — one lab is thin evidence for removing an option.The evidence is scoped in the file itself: one client generation, one run, not a claim about the product.
Deliberately not here
raw.githubusercontent.com— the issue's own reasoning: the proxy logs host and method and no path, so the trail cannot attribute it between the client and the agent's own work.Checks
00-config-lint418/0/1,05-check-drift36/0,06-check-invariants70/0.Both bank-allowlist checks strip full-line comments before parsing, so the additions are inert to them by construction — verified that
bank/anthropic/allowlist — every declared host is reachableand— every entry states its methodsstill pass. Separately checked the four lines parse correctly if uncommented: each yields the intended method set,hostmatch.invalid()reports none uninterpretable, and each matches its own hostname.🤖 Generated with Claude Code
https://claude.ai/code/session_01BLuSkuyQUfogZpMJ5fVMF9