Warn when Copilot API-proxy mode disables native web tools - #9420
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The sidecar documentation omits base-URL-only configurations that also set COPILOT_OFFLINE=true.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds diagnostics and guidance for Copilot web tools disabled by API-proxy offline mode.
Changes:
- Warns when offline Copilot routing conflicts with allowlisted domains.
- Adds regression tests and documents the
curlworkaround. - Documents the web-tool limitation in sidecar configuration.
| File | Description |
|---|---|
src/services/credentials/copilot-credential-env.ts |
Emits the startup warning. |
src/services/credentials/copilot-credential-env.test.ts |
Tests warning and suppression behavior. |
docs/troubleshooting.md |
Documents symptoms, cause, and workaround. |
docs/api-proxy-sidecar.md |
Notes offline-mode web-tool limitations. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
@copilot merge main and address review feedback |
…ix-web-tools Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Merged |
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit b47aac7 |
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
✅ Smoke Claude passed
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
🚀 Security Guard has started processing this pull request |
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟
|
|
✅ Build Test Suite completed successfully!
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.
|
Smoke Test: Claude Engine Validation
Overall result: PASS
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed: api.github.com returned HTTP 403 (a response, curl exit 0)
|
|
OTEL smoke test
|
|
Services smoke test:
Overall: PASS
|
Smoke Test: Copilot BYOK (Direct Mode)Status: ✅ PASS
Mode: Direct BYOK (COPILOT_PROVIDER_API_KEY) via api-proxy → api.githubcopilot.com
|
|
Smoke Copilot — PR: "Warn when Copilot API-proxy mode disables native web tools"
|
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (2 files)
Coverage comparison generated by |
Chroot version comparison
Node.js differs between host and chroot, so not all tests passed. The
|
Smoke Test: Cloud Hypervisor + Copilot
Overall: 2/4 checks verified; curl-based network checks (#2, #4) could not run due to sandbox denying all curl invocations, unrelated to firewall allow/deny logic.
|
Smoke Test
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS Note: Java's first Maven run failed because
|

Copilot API-proxy routing sets
COPILOT_OFFLINE=true, which disables nativeweb_fetchandweb_searcheven when explicitly permitted. Allowlisted domains therefore remain unused without an explanation.curlwith Copilot URL permissions. Squid continues enforcing the domain allowlist.Example gh-aw configuration:
This enables fetching known URLs through
curl; it does not restore native web tools.