Skip to content

Document denying the aws CLI so calls go through the proxy - #11

Merged
winebarrel merged 1 commit into
mainfrom
deny-aws-cli
Aug 9, 2026
Merged

Document denying the aws CLI so calls go through the proxy#11
winebarrel merged 1 commit into
mainfrom
deny-aws-cli

Conversation

@winebarrel

Copy link
Copy Markdown
Owner

Registering awsmcproxy as an MCP server does not stop an agent reaching AWS through the aws CLI, which bypasses the profile argument, the proxy's SigV4 signing, and --sso-role.

Adds a note to the Claude Code section covering the Bash(aws *) deny rule, where to put it, what it does and does not match, and that it routes the agent to the proxy rather than acting as a boundary.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@winebarrel
winebarrel enabled auto-merge August 9, 2026 05:11
@codecov

codecov Bot commented Aug 9, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 98.40%. Comparing base (41029e2) to head (253258c).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main      #11   +/-   ##
=======================================
  Coverage   98.40%   98.40%           
=======================================
  Files           5        5           
  Lines         377      377           
=======================================
  Hits          371      371           
  Misses          3        3           
  Partials        3        3           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@winebarrel
winebarrel merged commit 65e4c84 into main Aug 9, 2026
5 checks passed
@winebarrel
winebarrel deleted the deny-aws-cli branch August 9, 2026 05:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant