Run workflows that call Claude on the egress-firewall runner in auto permission mode

Move the three workflow jobs that sign in to the Claude API (claude.yml,
claude-issue-triage.yml, claude-dedupe-issues.yml) from ubuntu-latest to
GitHub's egress-firewall runner (ubuntu-24.04-firewall), and pass
--permission-mode auto to the Claude Code action in the triage and
dedupe steps.

In auto permission mode Claude Code reviews each tool call that needs
permission and that the command's allowed-tools list does not cover, and
runs it only if Claude Code's safety review passes it. Until now these runs, which
have nobody to ask, refused every such call. Anyone can start both jobs by opening
an issue, and the triage job also by commenting on one, so both steps
also pass a --disallowedTools list for tools they never need.

claude.yml answers @claude mentions, and for those the action sets
--permission-mode acceptEdits itself. Its permission mode is unchanged.

Allowed tools, models, triggers and permissions are unchanged. The
network allow list for the firewall follows in the next change.
This commit is contained in:
Claude
2026-09-28 18:52:06 +00:00
parent 8364969e9f
commit 592d541c18
3 changed files with 18 additions and 4 deletions
+7 -2
View File
@@ -12,7 +12,9 @@ on:
jobs:
claude-dedupe-issues:
runs-on: ubuntu-latest
# This job calls Claude, so it runs on GitHub's egress-firewall runner, which
# filters the job's outbound network traffic (allow list: .github/egress-firewall.yaml).
runs-on: ubuntu-24.04-firewall
timeout-minutes: 10
permissions:
contents: read
@@ -40,7 +42,10 @@ jobs:
anthropic_organization_id: ${{ vars.ANTHROPIC_ORGANIZATION_ID }}
anthropic_service_account_id: ${{ vars.ANTHROPIC_SERVICE_ACCOUNT_ID }}
anthropic_workspace_id: ${{ vars.ANTHROPIC_WORKSPACE_ID }}
claude_args: "--model claude-sonnet-4-5-20250929"
# --permission-mode auto: a tool call that needs permission and is outside the allowed-tools
# list in .claude/commands/dedupe.md runs only if Claude Code's safety review passes it.
# Tools in --disallowedTools never run.
claude_args: '--model claude-sonnet-4-5-20250929 --permission-mode auto --disallowedTools "WebFetch,WebSearch,Write,Edit,MultiEdit,NotebookEdit"'
- name: Log duplicate comment event to Statsig
if: always()
+8 -1
View File
@@ -7,7 +7,9 @@ on:
jobs:
triage-issue:
runs-on: ubuntu-latest
# This job calls Claude, so it runs on GitHub's egress-firewall runner, which
# filters the job's outbound network traffic (allow list: .github/egress-firewall.yaml).
runs-on: ubuntu-24.04-firewall
timeout-minutes: 10
if: >-
github.event_name == 'issues' ||
@@ -43,5 +45,10 @@ jobs:
anthropic_organization_id: ${{ vars.ANTHROPIC_ORGANIZATION_ID }}
anthropic_service_account_id: ${{ vars.ANTHROPIC_SERVICE_ACCOUNT_ID }}
anthropic_workspace_id: ${{ vars.ANTHROPIC_WORKSPACE_ID }}
# --permission-mode auto: a tool call that needs permission and is outside the allowed-tools
# list in .claude/commands/triage-issue.md runs only if Claude Code's safety review passes
# it. Tools in --disallowedTools never run.
claude_args: |
--permission-mode auto
--disallowedTools "WebFetch,WebSearch,Write,Edit,MultiEdit,NotebookEdit"
--model claude-opus-4-6
+3 -1
View File
@@ -17,7 +17,9 @@ jobs:
(github.event_name == 'pull_request_review_comment' && contains(github.event.comment.body, '@claude')) ||
(github.event_name == 'pull_request_review' && contains(github.event.review.body, '@claude')) ||
(github.event_name == 'issues' && (contains(github.event.issue.body, '@claude') || contains(github.event.issue.title, '@claude')))
runs-on: ubuntu-latest
# This job calls Claude, so it runs on GitHub's egress-firewall runner, which
# filters the job's outbound network traffic (allow list: .github/egress-firewall.yaml).
runs-on: ubuntu-24.04-firewall
permissions:
contents: read
pull-requests: read