{"name":"CCR_AGENT_PROXY_CA_CERT_B64","slug":"ccr-agent-proxy-ca-cert-b64","family":"env","title":"Environment variables","noun":"environment variable","description":"In hosted remote sessions, the agent proxy can read its certificate authority from `CCR_AGENT_PROXY_CA_CERT_B64` instead of always downloading it","description_source":"entry","described_by":{"version":"2.1.285","anchor":"agent-proxy-accepts-ca-cert-from-env-var-ccr-agent-proxy-ca"},"presence":{"first_seen":"2.1.285","removed_in":null,"in_current_build":true,"newest_mined":"2.1.285","builds":1,"mined_builds":128,"first_cited":{"version":"2.1.285","released_at":"2026-09-29 17:32:09","spans":1}},"aliases":[],"entries":[{"version":"2.1.285","anchor":"agent-proxy-accepts-ca-cert-from-env-var-ccr-agent-proxy-ca","heading":"Hosted remote sessions can take the agent proxy certificate from an environment variable","line":"In hosted remote sessions, the agent proxy can read its certificate authority from `CCR_AGENT_PROXY_CA_CERT_B64` instead of always downloading it","released_at":"2026-09-29 17:32:09","reason":"found in this entry's text, named in this entry"}],"entries_total":1,"docs":[],"docs_total":0,"gates":[],"related":[{"name":"CCR_AGENT_PROXY_ENABLED","slug":"ccr-agent-proxy-enabled","description":"The remote agent proxy now caps stalled uploads and reads, with two env vars to disable each."},{"name":"CCR_AGENT_PROXY_FRAME_HOSTS","slug":"ccr-agent-proxy-frame-hosts","description":"Artifact traffic can take a direct tunnel when the runner environment names hosts; local runs keep the old route."},{"name":"CCR_AGENT_PROXY_INCLUDE_HOSTS","slug":"ccr-agent-proxy-include-hosts","description":null},{"name":"CCR_AGENT_PROXY_NO_PROXY_LOCAL_ONLY","slug":"ccr-agent-proxy-no-proxy-local-only","description":"New CCR_AGENT_PROXY_NO_PROXY_LOCAL_ONLY environment variable narrows the agent proxy's no-proxy list to local addresses"},{"name":"CCR_AGENT_PROXY_RECEIVE_GATE_DISABLED","slug":"ccr-agent-proxy-receive-gate-disabled","description":"The remote agent proxy now caps stalled uploads and reads, with two env vars to disable each."},{"name":"CCR_AGENT_PROXY_RELAY_MODE","slug":"ccr-agent-proxy-relay-mode","description":"Read once, then removed from the environment, when the agent proxy starts in a remote session (`CLAUDE_CODE_REMOTE` and `CCR_AGENT_PROXY_ENABLED` both set). The value `selective` relays only the hosts listed in `CCR_AGENT_PROXY_INCLUDE_HOSTS` (comma-separated) and lets other hosts use normal networking; if that list is empty or unparsable, all traffic is relayed. Any other value relays all traffic, and `selective` is ignored when `AGENT_PROXY_URL` is set."},{"name":"CCR_AGENT_PROXY_UPLOAD_GATE_DISABLED","slug":"ccr-agent-proxy-upload-gate-disabled","description":"The remote agent proxy now caps stalled uploads and reads, with two env vars to disable each."}],"url":"https:\/\/changelogs.core-directive.com\/reference\/env\/ccr-agent-proxy-ca-cert-b64","family_url":"https:\/\/changelogs.core-directive.com\/reference\/env.json"}