Repository navigation
feat(packer): stop baking the Claude Code binary into AWS images - #2504
Merged
Merged
Conversation
Claude Code is "all rights reserved" and must not ship in a published image. AWS ranges now receive it as a scenario-declared artifact that Shifter acquires and delivers at realization (#2463, ADR-034-R11/R12), so the AWS Kali and Ubuntu bakes keep only Shifter's own configuration: the Bedrock environment and the autostart hook (which already skips when the binary is absent). The binary install moves out of the shared claude-code.sh scripts into a temporary scripts/common/claude-code-binary.sh referenced only by the GCE Kali and Ubuntu templates, until GCP acquires and delivers it (#2479). Tests now require the shared scripts and AWS templates never to bake the binary. Refs #2463
|
This was referenced Oct 6, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



#2463 phase 6 (AWS).
Why
Claude Code's license is "all rights reserved"; it must not ship in a published image. Since #2501, AWS ranges receive it as a scenario-declared artifact that Shifter acquires and streams to the guest at realization (live-proven by the aws-dev post-deploy smoke).
Change
scripts/kali/claude-code.shandscripts/ubuntu/claude-code.shnow only configure Claude Code: the Bedrock environment and the autostart hook. The hook already skips when the binary is absent. They no longer install the binary.npm installmoves to a temporaryscripts/common/claude-code-binary.sh, referenced only by the GCE Kali and Ubuntu templates until GCP acquires and delivers the binary (feat(gcp): feature-artifact acquisition on GKE and Claude Code in smoke-linux #2479). The AWS Kali and Ubuntu templates never reference it.tests/test_packer.pynow requires that the shared scripts never install the binary, that the AWS Linux templates never reference the binary script, and that the GCE templates reference it only through the temporary script.Windows and DC bakes still install Claude Code via
claude-code.ps1; there is no Windows acquisition recipe yet (tracked separately).Verification
tests/test_packer.py,tests/test_packer_gcp.pypass.aws-devwith this change (Debian base, HTTPS apt source, no binary) is running; its fresh-boot gate publishes the dev Kali AMI on success.Refs #2463