Skip to content

feat(packer): stop baking the Claude Code binary into AWS images - #2504

Merged
Brad-Edwards merged 2 commits into
devfrom
feat/2463-unbake-claude-aws
Oct 5, 2026
Merged

Brad-Edwards merged 2 commits into
devfrom
feat/2463-unbake-claude-aws

Conversation

@Brad-Edwards

Copy link
Copy Markdown
Owner

#2463 phase 6 (AWS).

Why

Claude Code's license is "all rights reserved"; it must not ship in a published image. Since #2501, AWS ranges receive it as a scenario-declared artifact that Shifter acquires and streams to the guest at realization (live-proven by the aws-dev post-deploy smoke).

Change

  • scripts/kali/claude-code.sh and scripts/ubuntu/claude-code.sh now only configure Claude Code: the Bedrock environment and the autostart hook. The hook already skips when the binary is absent. They no longer install the binary.
  • The npm install moves to a temporary scripts/common/claude-code-binary.sh, referenced only by the GCE Kali and Ubuntu templates until GCP acquires and delivers the binary (feat(gcp): feature-artifact acquisition on GKE and Claude Code in smoke-linux #2479). The AWS Kali and Ubuntu templates never reference it.
  • tests/test_packer.py now requires that the shared scripts never install the binary, that the AWS Linux templates never reference the binary script, and that the GCE templates reference it only through the temporary script.

Windows and DC bakes still install Claude Code via claude-code.ps1; there is no Windows acquisition recipe yet (tracked separately).

Verification

  • tests/test_packer.py, tests/test_packer_gcp.py pass.
  • A Kali bake from aws-dev with this change (Debian base, HTTPS apt source, no binary) is running; its fresh-boot gate publishes the dev Kali AMI on success.

Refs #2463

Claude Code is "all rights reserved" and must not ship in a published image.
AWS ranges now receive it as a scenario-declared artifact that Shifter acquires
and delivers at realization (#2463, ADR-034-R11/R12), so the AWS Kali and Ubuntu
bakes keep only Shifter's own configuration: the Bedrock environment and the
autostart hook (which already skips when the binary is absent).

The binary install moves out of the shared claude-code.sh scripts into a
temporary scripts/common/claude-code-binary.sh referenced only by the GCE Kali
and Ubuntu templates, until GCP acquires and delivers it (#2479). Tests now
require the shared scripts and AWS templates never to bake the binary.

Refs #2463
@Brad-Edwards
Brad-Edwards merged commit f80a277 into dev Oct 5, 2026
5 checks passed
@Brad-Edwards
Brad-Edwards deleted the feat/2463-unbake-claude-aws branch October 5, 2026 21:18
@sonarqubecloud

sonarqubecloud Bot commented Oct 5, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant