{"version":"2.1.283","anchor":"agent-proxy-governed-git-now-configures-several-governed-hos","canonical_anchor":"agent-proxy-governed-git-now-configures-several-governed-hos","heading":"Agent-proxy governed git now covers several git hosts","tier":"internal","area":"Cloud Sessions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/agent-proxy-governed-git-now-configures-several-governed-hos","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Agent-proxy governed git now covers several git hosts\n\nSessions set up by the runner get a governed git host list in CLAUDE_CODE_AGENT_PROXY_GIT_HOSTS and configure proxy git access for each host\n\n**Unclear.** It is not confirmed that `CLAUDE_CODE_AGENT_PROXY_GIT_CONFIG` is what turns this setup on.\n\n**What**\n\nGoverned git is the setup where a session's git traffic goes through a proxy and relay instead of the machine's own credentials. It used to apply to a single host. It now applies to a list of hosts.\n\n- When the self-hosted runner sets up a session with a git config and a host split from its `tool_config` (`toolConfig.hostSplit.governed`), it writes `CLAUDE_CODE_AGENT_PROXY_GIT_HOSTS` into the session's environment as a comma-separated list of governed hosts. The variable is added to the environment variables carried into sessions.\n\n- Inside the session, the governed-git setup reads that variable and keeps each entry that is a bare hostname. Other entries are ignored with a warning. If the variable is unset or empty, it falls back to a single default host.\n\n- The generated git config writes proxy and credential sections for every governed host. Hosts other than the primary have their `extraHeader`, `cookieFile` and credential helpers cleared and replaced with a helper that answers quit.\n\n- If the list has no usable host, the git config setup is skipped with a warning.\n\n- The `gh` path shim is enabled only when the default host is among the governed hosts.\n\n- The runner's session-exit environment now includes `gitEnvironment.envOverrides`.\n\n**Why**\n\nCloud and self-hosted agent sessions can reach more than one governed git host through the proxy, while other hosts stay direct. If you set the host list yourself, entries that are not plain hostnames are dropped.\n\n- Area: Cloud Sessions\n- Tier: Under the hood\n- Useful: 2\/5\n- Signal: 3\/5"}