Cloud containers stop reinstalling proxy certificates that are already trusted
In cloud sessions, Claude Code's proxy now leaves the certificate store alone when it already trusts the right certificates, not deleting and re-adding them
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Cloud SessionsArea: what it touches
ImprovementsKind: in v2.1.282,
ImprovementsSection of the release
What
In cloud sessions, Claude Code runs a proxy, a go-between for network traffic. The proxy has its own certificates, the files that let other programs trust its connections. It installs them into an NSS database, a certificate store that programs such as browsers use on Linux.
It used to delete the ccr-agent-proxy and ccr-agent-proxy-2 certificates and add them again every time. Now it first lists what the database holds. If exactly the certificates it serves are already there and trusted, it leaves the database as it is.
Why
This cuts needless rewriting of the certificate store in remote containers. It also avoids a short gap during which the certificate is missing from the store.