1
00:00:00,080 --> 00:00:04,900
Imagine deploying an enterprise AI gateway
inside a locked down cloud network only

2
00:00:04,920 --> 00:00:09,500
to watch every single API request crash
instantly before it even touches the wire.

3
00:00:10,042 --> 00:00:12,802
Yeah, mate, the good old local DNS trap.

4
00:00:13,522 --> 00:00:18,442
You build this pristine zero trust wall,
cut off external name resolution from your

5
00:00:18,482 --> 00:00:20,522
internal servers, and bam!

6
00:00:21,182 --> 00:00:25,761
Node tries to resolve the destination
hostname locally, gets an ENOTFOUND error,

7
00:00:26,182 --> 00:00:27,562
and drops dead on the spot.

8
00:00:27,625 --> 00:00:28,025
Right!

9
00:00:28,055 --> 00:00:32,265
Because the gateway server itself has no
internet DNS access.

10
00:00:32,398 --> 00:00:37,465
It is supposed to pass the whole URL to an
outbound proxy, but it tries to be smart

11
00:00:37,558 --> 00:00:39,865
first and resolve the IP address locally.

12
00:00:39,875 --> 00:00:40,515
Spot on.

13
00:00:40,675 --> 00:00:46,995
But in Claude Code 2.1.277, Anthropic
added a fix for that exact headache.

14
00:00:47,275 --> 00:00:51,875
Brought to you by Jellypod AI, this update
gives us a brand new environment

15
00:00:51,928 --> 00:00:56,435
variable: CLAUDE GATEWAY PROXY IS EGRESS
BOUNDARY set to 1.

16
00:00:56,458 --> 00:01:00,138
That name is a mouthful, but what it does
is huge.

17
00:01:00,266 --> 00:01:05,818
When you set CLAUDE GATEWAY PROXY IS
EGRESS BOUNDARY to 1, the Claude apps gateway

18
00:01:05,869 --> 00:01:07,899
completely skips local DNS lookup.

19
00:01:08,058 --> 00:01:12,138
It just takes the raw target hostname and
hands it straight to your forward proxy.

20
00:01:12,287 --> 00:01:16,727
It is like telling your server, hey, do
not try to read the map yourself,

21
00:01:16,807 --> 00:01:17,067
mate.

22
00:01:17,667 --> 00:01:22,187
Just toss the parcel over the fence to the
proxy and let it handle the directions.

23
00:01:22,250 --> 00:01:23,170
Exactly.

24
00:01:23,237 --> 00:01:29,050
So in practice, you set export CLAUDE
GATEWAY PROXY IS EGRESS BOUNDARY equals 1,

25
00:01:29,150 --> 00:01:35,930
and pair it with HTTPS PROXY set to
something like http proxy internal port 8080.

26
00:01:36,070 --> 00:01:39,210
The gateway delegates all name resolution
to the proxy.

27
00:01:39,250 --> 00:01:43,090
And that is not all they added for
corporate gateways in point 277.

28
00:01:43,154 --> 00:01:48,290
They also gave us a custom headers map
inside gateway dot json under upstreams.

29
00:01:48,492 --> 00:01:49,212
Oh, nice.

30
00:01:49,732 --> 00:01:50,652
How does that map work?

31
00:01:50,708 --> 00:01:54,948
Well, you can define static key value
pairs right in your gateway config,

32
00:01:55,028 --> 00:01:59,428
like quotes X Proxy Auth Token quotes set
to corporate secret,

33
00:01:59,561 --> 00:02:02,548
or X Tenant ID set to eng prod.

34
00:02:02,668 --> 00:02:06,868
The gateway injects those headers directly
into outbound requests to your upstream

35
00:02:06,930 --> 00:02:07,748
provider.

36
00:02:07,750 --> 00:02:09,830
Which is brilliant for security!

37
00:02:09,970 --> 00:02:14,950
You pass required corporate auth or
routing tokens without ever exposing sensitive

38
00:02:14,997 --> 00:02:17,830
credentials to individual developer
terminal sessions.

39
00:02:17,833 --> 00:02:18,553
Too right!

40
00:02:18,644 --> 00:02:22,633
Though, you do need to watch out for a few
gotchas when you set this up.

41
00:02:22,907 --> 00:02:23,507
Yeah, like...

42
00:02:24,427 --> 00:02:29,327
if you delegate DNS to your proxy, that
forward proxy had better be configured to

43
00:02:29,367 --> 00:02:31,327
handle remote name resolution cleanly.

44
00:02:31,967 --> 00:02:36,107
If your proxy fails to resolve the
upstream hostname, you just moved the roadblock

45
00:02:36,207 --> 00:02:37,047
further down the road.

46
00:02:37,083 --> 00:02:37,963
100 percent.

47
00:02:38,103 --> 00:02:43,003
And keep in mind, those upstream headers
in gateway dot json are completely static.

48
00:02:43,131 --> 00:02:47,283
They cannot evaluate dynamic per user
variables at runtime.

49
00:02:47,403 --> 00:02:51,643
If you need user level tokens, that still
has to happen at your identity provider

50
00:02:51,696 --> 00:02:52,043
layer.

51
00:02:52,083 --> 00:02:53,603
Another subtle trap is streaming.

52
00:02:53,763 --> 00:02:58,323
If your forward proxy inspects or rewrites
traffic and strips keep alive pings

53
00:02:58,357 --> 00:03:02,803
during long model reasoning pauses, Claude
Code thinks the connection dropped and

54
00:03:02,870 --> 00:03:04,643
aborts after 300 seconds.

55
00:03:04,667 --> 00:03:06,667
Yeah, like flat tires on a road trip!

56
00:03:06,807 --> 00:03:12,907
But look, 2.1.277 also sneaks in some
sweet quality of life polish.

57
00:03:12,917 --> 00:03:14,037
Oh, what else landed?

58
00:03:14,042 --> 00:03:19,242
For starters, the telemetry relay now
honors NO PROXY environment variables when

59
00:03:19,292 --> 00:03:22,522
sending OpenTelemetry traces to your OTLP
collectors.

60
00:03:22,735 --> 00:03:27,082
So internal telemetry stops getting
accidentally routed through external proxies.

61
00:03:27,083 --> 00:03:27,563
Nice!

62
00:03:27,723 --> 00:03:32,923
And inside the terminal CLI, if you have
the slash tasks panel open and a background

63
00:03:33,003 --> 00:03:37,643
task finishes in the back, it now shows a
clear waiting notice instead of silently

64
00:03:37,687 --> 00:03:39,003
updating behind the scenes.

65
00:03:39,042 --> 00:03:44,162
Plus, if you use git worktrees, untracked
skill folders under dot claude slash

66
00:03:44,253 --> 00:03:48,802
skills now load properly inside dash dash
worktree sessions.

67
00:03:49,095 --> 00:03:53,122
No more missing local skills when you
split off a quick branch.

68
00:03:53,265 --> 00:03:55,845
That makes isolated testing so much
smoother!

69
00:03:56,485 --> 00:04:00,525
Between bypassing local DNS traps and
locking down static upstream headers,

70
00:04:01,105 --> 00:04:05,045
2.1.277 is a massive release for
enterprise networking.

71
00:04:05,225 --> 00:04:05,865
Sure is, mate.

72
00:04:06,725 --> 00:04:10,425
Flip that egress boundary flag on, let
your proxy do the heavy lifting,

73
00:04:10,925 --> 00:04:11,905
and keep your code moving!

