Skip to content

Commit 592d541

Browse files
committed
Run workflows that call Claude on the egress-firewall runner in auto permission mode
Move the three workflow jobs that sign in to the Claude API (claude.yml, claude-issue-triage.yml, claude-dedupe-issues.yml) from ubuntu-latest to GitHub's egress-firewall runner (ubuntu-24.04-firewall), and pass --permission-mode auto to the Claude Code action in the triage and dedupe steps. In auto permission mode Claude Code reviews each tool call that needs permission and that the command's allowed-tools list does not cover, and runs it only if Claude Code's safety review passes it. Until now these runs, which have nobody to ask, refused every such call. Anyone can start both jobs by opening an issue, and the triage job also by commenting on one, so both steps also pass a --disallowedTools list for tools they never need. claude.yml answers @claude mentions, and for those the action sets --permission-mode acceptEdits itself. Its permission mode is unchanged. Allowed tools, models, triggers and permissions are unchanged. The network allow list for the firewall follows in the next change.
1 parent 8364969 commit 592d541

3 files changed

Lines changed: 18 additions & 4 deletions

File tree

‎.github/workflows/claude-dedupe-issues.yml‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,9 @@ on:
1212

1313
jobs:
1414
claude-dedupe-issues:
15-
runs-on: ubuntu-latest
15+
# This job calls Claude, so it runs on GitHub's egress-firewall runner, which
16+
# filters the job's outbound network traffic (allow list: .github/egress-firewall.yaml).
17+
runs-on: ubuntu-24.04-firewall
1618
timeout-minutes: 10
1719
permissions:
1820
contents: read
@@ -40,7 +42,10 @@ jobs:
4042
anthropic_organization_id: ${{ vars.ANTHROPIC_ORGANIZATION_ID }}
4143
anthropic_service_account_id: ${{ vars.ANTHROPIC_SERVICE_ACCOUNT_ID }}
4244
anthropic_workspace_id: ${{ vars.ANTHROPIC_WORKSPACE_ID }}
43-
claude_args: "--model claude-sonnet-4-5-20250929"
45+
# --permission-mode auto: a tool call that needs permission and is outside the allowed-tools
46+
# list in .claude/commands/dedupe.md runs only if Claude Code's safety review passes it.
47+
# Tools in --disallowedTools never run.
48+
claude_args: '--model claude-sonnet-4-5-20250929 --permission-mode auto --disallowedTools "WebFetch,WebSearch,Write,Edit,MultiEdit,NotebookEdit"'
4449

4550
- name: Log duplicate comment event to Statsig
4651
if: always()

‎.github/workflows/claude-issue-triage.yml‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,9 @@ on:
77

88
jobs:
99
triage-issue:
10-
runs-on: ubuntu-latest
10+
# This job calls Claude, so it runs on GitHub's egress-firewall runner, which
11+
# filters the job's outbound network traffic (allow list: .github/egress-firewall.yaml).
12+
runs-on: ubuntu-24.04-firewall
1113
timeout-minutes: 10
1214
if: >-
1315
github.event_name == 'issues' ||
@@ -43,5 +45,10 @@ jobs:
4345
anthropic_organization_id: ${{ vars.ANTHROPIC_ORGANIZATION_ID }}
4446
anthropic_service_account_id: ${{ vars.ANTHROPIC_SERVICE_ACCOUNT_ID }}
4547
anthropic_workspace_id: ${{ vars.ANTHROPIC_WORKSPACE_ID }}
48+
# --permission-mode auto: a tool call that needs permission and is outside the allowed-tools
49+
# list in .claude/commands/triage-issue.md runs only if Claude Code's safety review passes
50+
# it. Tools in --disallowedTools never run.
4651
claude_args: |
52+
--permission-mode auto
53+
--disallowedTools "WebFetch,WebSearch,Write,Edit,MultiEdit,NotebookEdit"
4754
--model claude-opus-4-6

‎.github/workflows/claude.yml‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,9 @@ jobs:
1717
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
1818
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
1919
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
20-
runs-on: ubuntu-latest
20+
# This job calls Claude, so it runs on GitHub's egress-firewall runner, which
21+
# filters the job's outbound network traffic (allow list: .github/egress-firewall.yaml).
22+
runs-on: ubuntu-24.04-firewall
2123
permissions:
2224
contents: read
2325
pull-requests: read

0 commit comments

Comments
 (0)