Repository navigation
[BUG] Headless claude -p (entrypoint sdk-cli) uses ~1.8× more of the 5-hour window per token than interactive cli, same workload
#271658
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Claude Code | |
| on: | |
| issue_comment: | |
| types: [created] | |
| pull_request_review_comment: | |
| types: [created] | |
| issues: | |
| types: [opened, assigned] | |
| pull_request_review: | |
| types: [submitted] | |
| jobs: | |
| claude: | |
| if: | | |
| (github.event_name == 'issue_comment' && contains(github.event.comment.body, '@claude')) || | |
| (github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) || | |
| (github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) || | |
| (github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude'))) | |
| # This job calls Claude, so it runs on GitHub's egress-firewall runner, which | |
| # filters the job's outbound network traffic (allow list: .github/egress-firewall.yaml). | |
| runs-on: ubuntu-24.04-firewall | |
| permissions: | |
| contents: read | |
| pull-requests: read | |
| issues: read | |
| id-token: write | |
| steps: | |
| - name: Checkout repository | |
| uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4 | |
| with: | |
| fetch-depth: 1 | |
| - name: Run Claude Code | |
| id: claude | |
| uses: anthropics/claude-code-action@v1 | |
| with: | |
| # Authenticate to the Claude API via Workload Identity Federation | |
| # (the workflow's OIDC token is exchanged for a short-lived access | |
| # token) instead of a static API key. | |
| anthropic_federation_rule_id: ${{ vars.ANTHROPIC_FEDERATION_RULE_ID }} | |
| anthropic_organization_id: ${{ vars.ANTHROPIC_ORGANIZATION_ID }} | |
| anthropic_service_account_id: ${{ vars.ANTHROPIC_SERVICE_ACCOUNT_ID }} | |
| anthropic_workspace_id: ${{ vars.ANTHROPIC_WORKSPACE_ID }} | |
| # --permission-mode auto: a tool call that needs permission and that the allowed tools | |
| # do not cover runs only if Claude Code's safety review passes it. The action sets | |
| # --permission-mode acceptEdits for @claude mentions, and this one, which comes after it, wins. | |
| claude_args: "--model claude-sonnet-4-6 --permission-mode auto" | |