Fix Copilot SDK API proxy routing in docker-sbx#52210
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Triage: pr-type:bug · pr-risk:medium · Score 69/100 (impact 30, urgency 25, quality 14)Recommended action: fast_track Fixes a daily security-audit failure: Copilot SDK requests inside docker-sbx fail to reach
|
Triage
Fixes Copilot SDK API proxy routing failure surfaced by daily action/setup security audit. Small, targeted diff (98 additions / 3 deletions). CI unstable — recheck before merge.
|
PR Triage
|
|
✅ Design Decision Gate 🏗️ completed the design decision gate check. No ADR enforcement needed: PR #52210 does not have the 'implementation' label and has 0 new lines of code in business logic directories (threshold: 100).
|
|
🧠 Matt Pocock Skills Reviewer has completed the skills-based review. ✅ Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details.
|
|
✅ PR Code Quality Reviewer completed the code quality review. Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.individual.githubcopilot.com"See Network Configuration for more information.
|
|
❌ Ponytail Reviewer failed. Please review the logs for details. Warning Threat Detection Engine Failure — The analysis engine could not complete. This is a tooling failure, not a security finding. What happenedThe threat detection engine failed to produce results. Review the workflow run logs for details.
|
|
✅ Test Quality Sentinel completed test quality analysis.
|
Re-ran the
No code changes were needed, so nothing was pushed. No remaining blockers — ready for maintainer review/merge. |
|
@copilot Please inspect the latest branch state, refresh the branch if needed, review any remaining blockers, and run the No unresolved review threads were identified in this run.
|
Ran the
So the block is human review approval + the in-flight check, neither of which I can act on. Nothing to fix, nothing pushed — ready for maintainer review/merge. |
|
@copilot Triage nudge from sous-chef. Please refresh this branch as needed, review current status, and run the Run: https://github.com/github/gh-aw/actions/runs/31694426361
|
Ran the
Repeated sous-chef nudges won't change this state. Handing back to maintainers for review/merge. |
|
@copilot Triage nudge from sous-chef. The branch looks healthy; if the only blocker is human review, please leave a concise Run: https://github.com/github/gh-aw/actions/runs/31696345716
|
Final
Handing back to maintainers for review/merge. |
|
@copilot Triage nudge from sous-chef. The branch looks healthy; if the only blocker remains human review, please leave a concise No unresolved review threads were found.
|
PR TriageCategory: bug · Risk: high · Priority: high Fixes broken Copilot SDK proxy routing in docker-sbx — critical execution path. CI green. Recommended for expedited human review.
|
|
@lpcox review |
|
@copilot Triage nudge from sous-chef. Please inspect the latest branch state, address any remaining review feedback, refresh the branch, and run the No failed checks were included in the compact candidate set.
|
Blocker remains human review approval. Handing back to maintainers. |
🔍 PR TriageCategory: bug · Risk: medium · Priority score: 66/100 (impact 25, urgency 22, quality 19) Score breakdown:
Recommend expedited review to restore the daily security-audit workflow.
|
The daily
action/setup/*security audit failed because Copilot SDK requests insidedocker-sbxresolvedapi-proxyto localhost, but only the/reflectmanagement bridge was listening there. Model requests to provider ports such asapi-proxy:10002therefore failed withECONNREFUSED.Runtime routing
HOSTALIASESmode whereapi-proxymaps tolocalhost/127.0.0.1.host.docker.internal) so provider traffic reaches the api-proxy sidecar.Reflect/model helpers
api-proxyURLs outside sbx host-alias mode.Regression coverage
branch refresh requested in run https://github.com/github/gh-aw/actions/runs/31644728185> Generated by 👨🍳 PR Sous Chef · gpt54 · 18.5 AIC · ⌖ 5.27 AIC · ⊞ 8.5K · ◷
Run context: https://github.com/github/gh-aw/actions/runs/31649732812> Generated by 👨🍳 PR Sous Chef · gpt54 · 9.78 AIC · ⌖ 5.39 AIC · ⊞ 8.5K · ◷
Branch update requested by pr-sous-chef for run https://github.com/github/gh-aw/actions/runs/31692375821.> Generated by 👨🍳 PR Sous Chef · gpt54 · 12.7 AIC · ⌖ 5.21 AIC · ⊞ 8.5K · ◷
Run: https://github.com/github/gh-aw/actions/runs/31694426361> Generated by 👨🍳 PR Sous Chef · gpt54 · 7.86 AIC · ⌖ 3.48 AIC · ⊞ 8.5K · ◷