What
Governed git is the setup where a session's git traffic goes through a proxy and relay instead of the machine's own credentials. It used to apply to a single host. It now applies to a list of hosts.
- When the self-hosted runner sets up a session with a git config and a host split from its
tool_config(toolConfig.hostSplit.governed), it writesCLAUDE_CODE_AGENT_PROXY_GIT_HOSTSinto the session's environment as a comma-separated list of governed hosts. The variable is added to the environment variables carried into sessions. - Inside the session, the governed-git setup reads that variable and keeps each entry that is a bare hostname. Other entries are ignored with a warning. If the variable is unset or empty, it falls back to a single default host.
- The generated git config writes proxy and credential sections for every governed host. Hosts other than the primary have their
extraHeader,cookieFileand credential helpers cleared and replaced with a helper that answers quit. - If the list has no usable host, the git config setup is skipped with a warning.
- The
ghpath shim is enabled only when the default host is among the governed hosts. - The runner's session-exit environment now includes
gitEnvironment.envOverrides.
Why
Cloud and self-hosted agent sessions can reach more than one governed git host through the proxy, while other hosts stay direct. If you set the host list yourself, entries that are not plain hostnames are dropped.
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not confirmed that `CLAUDE_CODE_AGENT_PROXY_GIT_CONFIG` is what turns this setup on.