Skip to content

Add GitHub Copilot CLI as a supported tool profile #90

Description

@xai

Summary

Add GitHub Copilot CLI (github/copilot-cli)
as a supported tool profile, alongside claude, codex, mistral-vibe, opencode and
pi.

Enclave ships no GitHub-backed agent harness today. Copilot CLI is the one most likely to be
already approved inside large organisations, where the vendor decision is made centrally and
Copilot is what is licensed.

Installed with npm install -g @github/copilot, so it fits the existing
enclave-install-npm-tool path. It requires an active Copilot subscription.

Scope

A new extensions/tools/copilot/, mirroring the existing profiles file for file:

File Notes
spec.yaml see the fields below
install.sh npm install path; decide --ignore-scripts per #73 — check first whether @github/copilot has a postinstall that places the platform binary, as opencode does
check-update.sh as every other profile has
gateway-allowlist.conf the observed domains, see below
entrypoint.d/setup.sh
templates/<config> whatever config file the CLI reads
skills/enclave-help/SKILL.md as every other profile has
README.md
go/handler.go if it needs one — claude, codex and opencode have one, pi does not

spec.yaml follows the same shape as codex/spec.yaml: sandbox (entrypoint,
configDir, skillsDir, settingsFile/settingsTarget, yoloFlag/yoloEnabled,
continueArgs/resumeArgs, passthroughPaths), then credentials.sources,
network.serviceDomains + network.serviceAuth, and providers.

To establish during implementation

Three things the existing profiles already answer for their own tools — do the same here
rather than inventing a new pattern:

  • Authentication. Which env var(s) the CLI reads, and what kind of token. Model it on
    codex, which declares credentials.sources, maps hosts to a credential in
    serviceDomains, and gives that credential a serviceAuth header format. Per fix: require a serviceAuth entry for every serviceDomains host #59 every
    serviceDomains host needs a matching serviceAuth entry
    — the token is released
    through the gateway, never injected as a raw env var.
  • Non-interactive operation. Which flags drive it unattended, and what that means for
    entrypoint.d/setup.sh, yoloFlag/yoloEnabled and continueArgs/resumeArgs. GitHub
    documents this under
    running Copilot CLI programmatically.
  • The allowlist. Upstream documents no domains. Don't guess: run it once under
    --allow-all-network and read the answer out of enclave network log (feat: add enclave network log #52), then
    write the observed set into gateway-allowlist.conf.

Acceptance

  • enclave --tool copilot starts a working session under the restricted-egress default.
  • The token is released through the gateway, not injected as a raw env var.
  • gateway-allowlist.conf is minimal and derived from observed traffic, not guessed.
  • Non-interactive operation works inside a session.
  • Docs list it among supported tools and state the subscription requirement.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions