Skip to content

Release 1.14.5 - #122

Merged
lpezet merged 3 commits into
mainfrom
release/1.14.5
Aug 19, 2026
Merged

lpezet merged 3 commits into
mainfrom
release/1.14.5

Conversation

@lpezet

@lpezet lpezet commented Aug 19, 2026

Copy link
Copy Markdown
Owner

Cuts 1.14.5. The release is #121 and nothing else, which closes #119.

What's in it

bank/anthropic's OPTIONAL block describes the client people are running. Comments only, in one file — no uncommented line changes, no hosts change, boundary unchanged.

Measured on one lab (Claude Code 2.1.234, every host in its trail over one run): the block offered statsig.anthropic.com, which that client never contacted once, and omitted downloads.claude.ai (the auto-updater, failing on a loop) and http-intake.logs.us5.datadoghq.com (client telemetry, and not the sentry.io line already present).

Each ships with the reasoning that makes it decidable rather than just listed — including why downloads.claude.ai should stay off in a lab that pins CLAUDE_VERSION, and why the us5 shard in that hostname is per-account and should be read off your own trail.

This PR

  • CHANGELOG.md — the 1.14.5 entry.
  • template/deployment/compose.yaml — repinned v1.14.4 → v1.14.5 across all five services.

Upgrading

Nothing to do, nothing to rebuild — no image, addon, provider file or manifest changed.

The one non-obvious note is in the entry: an allowlist is copied into the deployment at install time, so an existing bank/anthropic install holds its own copy and will not pick these comments up. Nothing behaves differently for it, since every line involved is commented on both sides.

Checks

00-config-lint 418 passed / 0 failed / 1 skipped, 05-check-drift 36/0 — both after the repin.

Expect tests/stacks/20-boundary to skip the template for the life of this PR: the repin names v1.14.5, which is only created once this merges.

🤖 Generated with Claude Code

https://claude.ai/code/session_01BLuSkuyQUfogZpMJ5fVMF9

lpezet and others added 3 commits August 19, 2026 23:17
Comments only — no uncommented line changes, `hosts` is untouched, and the
boundary is exactly what it was. What changes is whether the block describes a
client anyone is running.

Measured on one lab: Claude Code 2.1.234, every host that appeared in its trail
over one run. Two the block did not offer, and one it offers that never came up.

downloads.claude.ai is the auto-updater, retrying and failing 32 times in that
run. It is listed with the reason NOT to enable it: a lab that pins
CLAUDE_VERSION updates by rebuild, so blocked is the right default and the only
cost is a noisy trail — which DISABLE_AUTOUPDATER fixes without opening egress.

http-intake.logs.us5.datadoghq.com is client telemetry, and naming it matters
because sentry.io was already here under "error reporting": someone enabling
that line to quiet telemetry blocks would find it changed nothing. The `us5`
shard is per-account, so the line says to copy what your own trail shows rather
than this one.

statsig.anthropic.com keeps its line and gains the finding — never contacted in
that run, with 2.1.x fetching gates over api.anthropic.com instead. Annotated
rather than deleted: one lab is thin evidence for removing an option, and a
commented line costs nothing.

The evidence is scoped in the file itself, since a list of hosts one client
generation contacted is not a claim about the product.

Deliberately not here: raw.githubusercontent.com, which the trail cannot
attribute between the client and the agent's own work, because the proxy logs
host and method and no path. And the Remote Control note #119 suggested — #120
measured that conclusion wrong, so it should not ship in the shape #119 wrote it.

Refs #119

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BLuSkuyQUfogZpMJ5fVMF9
Describe the client bank/anthropic's OPTIONAL block is for
The release is #121 and nothing else: comments in one bank entry's allowlist,
no uncommented line changed and no `hosts` change, so there is no image, addon
or manifest to rebuild.

The Upgrading section carries the one thing that is not obvious. An entry's
allowlist is copied into the deployment at install time, so a deployment that
already has bank/anthropic installed holds its own copy and never sees these
comments. Nothing behaves differently for it — every line involved is commented
on both sides — but "nothing to do" would leave someone wondering why their own
/etc/agent-allowlist did not change, so the entry says to diff it if the
annotations are wanted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01BLuSkuyQUfogZpMJ5fVMF9
@lpezet
lpezet merged commit c0956b2 into main Aug 19, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bank/anthropic: the allowlist's OPTIONAL block does not match what Claude Code 2.1.x actually requests

1 participant