One read of Claude Code CLIclaude-code-20260925T200701Z
2 pages moved out of 210 read.
Pages moved
2
significant first
Pages read
210
in this capture
Captured
20:07 UTC
Corpus hash
6e40c8238030
corpus-hash
What this read moved
1-2 of 2claude-apps-gateway-config Changed · +7 / -5 lines
from line 31
3131* [`managed`](#managed): managed settings policies by IdP group
3232* [`telemetry`](#telemetry): OTLP forwarding to your observability stack
3333* [`access_control`, `limits`, `timeouts`, `rate_limits`](#http-tuning): IP allow/deny, request size caps, upstream time-to-first-byte, and per-IP sign-in limits
34* [`load_test_mode`](#load_test_mode): load test the gateway without calling a model provider
34* [`load_test_mode`](#load_test_mode): load testing the gateway without calling a model provider
3535
3636## Secret expansion
3737
from line 956
956956
957957The `load_test_mode` block lets you load test a gateway without calling a model provider. While it's on, the gateway builds and signs each provider request as usual, discards it instead of sending it, and streams a canned reply back through its normal response path. The reply is filler text that begins with a sentence saying it is canned.
958958
959Requires v2.1.283 or later. Earlier versions refuse to start when the key is set, so upgrade every replica before you add the block and remove it before you roll back.
959Requires Claude Code v2.1.282 or later on the gateway server. An earlier gateway refuses to start when it finds the key. Upgrade every replica before you add the block, and remove the block before you roll back.
960960
961The example below turns the mode on with the defaults, a reply of 750 output tokens streamed over about 10 seconds:
961The example below turns the mode on with the defaults, a reply of roughly 750 tokens of text streamed over about 10 seconds:
962962
963963```yaml theme={null}
964964load_test_mode:
from line 975
975975
976976A load test in this mode covers the gateway, your Postgres, and everything in front of the gateway. It doesn't cover the provider's limits, speed, or network path.
977977
978While the mode is on, a request can carry an `x-load-test-user` header holding a whole number of up to seven digits, and the gateway counts each number as a separate developer with the email and groups of the developer whose token came with the request. Give the load-test deployment its own empty database, because the gateway refuses to start with the mode on against a database in which any developer has already spent anything.
978While the mode is on, a request can carry an `x-load-test-user` header holding a whole number of up to seven digits. The gateway counts each number as a separate developer, with the email and groups of the developer whose token came with the request.
979
980Give the load-test deployment its own empty database, because the gateway refuses to start with the mode on against a database in which any developer has already spent anything.
979981
980982<Warning>
981983 Never turn this on for a gateway that developers use. Every request gets the canned reply and no model is called. The gateway logs a `load_test_mode is on` warning at boot and marks each `inference` [audit event](/docs/en/claude-apps-gateway-deploy#logs) with `load_test: true` while the mode is on.
claude-apps-gateway-deploy Changed · +1 / -1 lines
from line 191
191191* **[Spend-limit enforcement](/docs/en/claude-apps-gateway-spend-limits#postgres-availability)**: fails open by default during the outage, so inference still flows; flip it to fail closed if you'd rather block than run unmetered
192192* **Readiness**: `/readyz` reports not-ready during the outage, so orchestrators that gate traffic on readiness remove every replica from rotation at once. In that topology all traffic, including inference the gateway could still serve, fails at the load balancer until Postgres recovers. The liveness probe on `/healthz` keeps passing, so replicas aren't restarted. Point the readiness probe at `/healthz` instead if you'd rather signed-in developers keep working through a store outage; the cost is that new sign-ins fail against a replica that still reports ready.
193193
194If your IdP goes down, existing sessions work until `ttl_hours`, new logins fail, and a session refresh gets a try-again answer and goes through once the IdP is back. Set a longer `ttl_hours` if your IdP has frequent maintenance windows.
194If your IdP goes down, existing sessions work until `ttl_hours` and new logins fail. A session refresh gets a try-again answer and succeeds once the IdP is back. Set a longer `ttl_hours` if your IdP has frequent maintenance windows.
195195
196196### JWT secret rotation
197197