Skip to content

Commit 8336074

Browse files
authored
chore(devel): enable CLI telemetry in the traced sandbox kit (#3382)
Signed-off-by: Miguel Martinez Trivino <miguel@chainloop.dev>
1 parent 1a6bbe6 commit 8336074

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎devel/sandbox-kit/spec.yaml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -258,7 +258,6 @@ environment:
258258
# MUST share it (transcript discovery is os.UserHomeDir()-based; a mismatch
259259
# silently loses usage/cost/tools), but sbx already sets HOME=/home/agent on
260260
# PID 1, so every child inherits it - verified in a plain `claude` sandbox.
261-
DO_NOT_TRACK: "1" # silence PostHog telemetry under restricted egress
262261
# Mode selection - see the traceMode arg above for what each value does.
263262
CHAINLOOP_TRACE_MODE: ${{ kit.args.traceMode }}
264263
# `trace run` identity ONLY. Empty in persistent mode, where the identity
@@ -365,6 +364,7 @@ permissions: # v1: `network.allowedDomains:`
365364
- "api.cp.chainloop.dev:443" # control plane - ALWAYS (attest + keyless signing CSR)
366365
- "api.cas.chainloop.dev:443" # CAS - only if the org CAS backend is external
367366
- "api.app.chainloop.dev:443" # platform backend - the EE CLI also dials this
367+
- "crb.chainloop.dev:443" # CLI usage telemetry (PostHog)
368368
- "timestamp.digicert.com:80" # RFC 3161 timestamp authority (plain HTTP, signed response)
369369
# used during attestation signing; host comes from the
370370
# control plane's signing options

0 commit comments

Comments
 (0)