Problem: With engine: copilot, tools: web-fetch: compiles to --allow-tool web_fetch, but Copilot CLI never exposes the tool. AWF's Copilot setup runs it with COPILOT_OFFLINE=true plus COPILOT_PROVIDER_BASE_URL pointing at the api-proxy sidecar (172.30.0.30:10002). Offline mode disables web tools, so web-fetch (and likely web-search) silently does nothing and Squid never sees the requests.
Context: github/gh-aw#65043 (AWF v0.27.44, Copilot CLI 1.0.82+, GHE data residency).
Root Cause: Offline BYOK mode (COPILOT_OFFLINE) is set for the Copilot api-proxy path. The Copilot CLI documents that offline mode skips all network access, including web tools. The compiler (gh-aw) does not account for this, so the mismatch is silent.
Proposed Solution:
- Check whether AWF must set
COPILOT_OFFLINE=true in the api-proxy flow (src/docker-manager.ts and the agent env setup). If a CLI option or env var can keep web tools enabled while using the proxy provider, use it.
- If offline mode is unavoidable, log a warning at startup when the Copilot engine runs offline and the allowlist contains extra domains, and document that web tools are unavailable.
- Document the
curl plus --allow-all-urls / --allow-url workaround in docs/troubleshooting.md.
- Coordinate with gh-aw so the compiler warns on
web-fetch/web-search when the run is offline.
Generated by Firewall Issue Dispatcher · copilot · auto · 22.2 AIC · ⊞ 9.1K · ◷
Problem: With
engine: copilot,tools: web-fetch:compiles to--allow-tool web_fetch, but Copilot CLI never exposes the tool. AWF's Copilot setup runs it withCOPILOT_OFFLINE=trueplusCOPILOT_PROVIDER_BASE_URLpointing at the api-proxy sidecar (172.30.0.30:10002). Offline mode disables web tools, so web-fetch (and likely web-search) silently does nothing and Squid never sees the requests.Context: github/gh-aw#65043 (AWF v0.27.44, Copilot CLI 1.0.82+, GHE data residency).
Root Cause: Offline BYOK mode (
COPILOT_OFFLINE) is set for the Copilot api-proxy path. The Copilot CLI documents that offline mode skips all network access, including web tools. The compiler (gh-aw) does not account for this, so the mismatch is silent.Proposed Solution:
COPILOT_OFFLINE=truein the api-proxy flow (src/docker-manager.tsand the agent env setup). If a CLI option or env var can keep web tools enabled while using the proxy provider, use it.curlplus--allow-all-urls/--allow-urlworkaround indocs/troubleshooting.md.web-fetch/web-searchwhen the run is offline.