Skip to content

fix: allowlist claude.exe so refine can reach Vertex STS - #15

Merged
johnmcollier merged 1 commit into
mainfrom
fix/refine-allowlist-claude-exe
Sep 1, 2026
Merged

johnmcollier merged 1 commit into
mainfrom
fix/refine-allowlist-claude-exe

Conversation

@johnmcollier

Copy link
Copy Markdown
Contributor

Summary

  • Run 33534818512 requested claude-opus-4-6 and still got policy_denied. OpenShell denied /usr/lib/node_modules/@anthropic-ai/claude-code/bin/claude.exe → sts.googleapis.com:443 (_provider_vertex_ai).
  • Same fix as node-api#13, rhdh-plugins#12, and overlays#13/#14: pin claude-opus-4-6 on the agent entry and allowlist **/claude.exe.

Test plan

  • Merge, new /fs-refine on DEVREG-281, then dispatch the Jira poll
  • Refine logs show Vertex STS allowed (no claude.exe DENIED) and requested_model: claude-opus-4-6
  • Job posts a plan to the ticket instead of failing on policy_denied

Made with Cursor

Claude Code 2.1+ talks to sts.googleapis.com as claude.exe, which
**/claude does not match. OpenShell denied that binary and surfaced
policy_denied. Match the other rhdh-parasol repos: pin Opus 4.6 on
the agent entry and allowlist claude.exe.

Co-authored-by: Cursor <cursoragent@cursor.com>
@fullsend-ai-review

fullsend-ai-review Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

🤖 Finished Review · ✅ Success · Started 5:11 PM UTC · Completed 5:21 PM UTC

Commit: 8aa94c5 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $2.53

@fullsend-ai-review

Copy link
Copy Markdown

Looks good to me

@fullsend-ai-review fullsend-ai-review Bot added the ready-for-merge All reviewers approved — ready to merge label Sep 1, 2026
@johnmcollier
johnmcollier merged commit 0a81563 into main Sep 1, 2026
30 checks passed
@fullsend-ai-retro

fullsend-ai-retro Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

🤖 Finished Retro · ✅ Success · Started 5:39 PM UTC · Completed 5:51 PM UTC

Commit: 8aa94c5 · View workflow run →

Runtime: claude · Model: opus → claude-opus-4-6 · Effort: high · Cost: $4.59

@fullsend-ai-retro

Copy link
Copy Markdown

Retro: PR #15 — allowlist claude.exe so refine can reach Vertex STS

This was a clean, fast workflow with zero rework. PR #15 fixed a known issue where Claude Code 2.1+ ships as claude.exe (bun compile) but the OpenShell Vertex AI profile only allowed **/claude, causing policy_denied when the refine agent tried to reach sts.googleapis.com. The same fix was applied across 4 other rhdh-parasol repos.

Timeline: PR opened at 17:10 UTC, review agent approved at 17:21 UTC ("Looks good to me", $2.53, 4 sub-agents at opus), merged at 17:38 UTC. Total: 28 minutes.

Review quality: Correct approval of a correct fix. The review agent dispatched correctness, security, style-conventions, and intent-coherence sub-agents — appropriate thoroughness for a profile change that controls binary network access.

Upstream status: The upstream fix exists as fullsend-ai/agents#1118 (open, not yet merged). Once it lands, repos without per-repo profile overrides will inherit **/claude.exe automatically. However, repos with local overrides — including this one — will still use their stale local copy unless the override is removed.

Evidence for existing issue: fullsend-ai/agents#1117 tracks the upstream outage that prompted this class of fix. This retro confirms the per-repo workaround pattern: 5 independent repos needed the same 1-line profile addition because each maintains a local fullsend-vertex-ai.yaml override that shadows the upstream profile.

Proposals filed

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ready-for-merge All reviewers approved — ready to merge

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant