Skip to content

[awf] api-proxy/gemini: key not injected — Gemini CLI bypasses api-proxy, hits Google directly #2807

Description

@lpcox

Problem

Gemini engine runs fail with 400 API_KEY_INVALID even when using a valid Google AI Studio API key. Squid access logs confirm requests originate from the agent container (172.30.0.20) directly, not from the api-proxy (172.30.0.30). The api-proxy intercept on port 10003 is not functioning — `GEMINI_API_BASE_URL=(host.docker.internal/redacted) is set in the agent environment but the Gemini CLI bypasses it.

Context

Original issue: github/gh-aw#29417

Root Cause

host.docker.internal may not resolve inside the agent container in all environments, causing the Gemini CLI to fall back to direct requests to generativelanguage.googleapis.com without the api-proxy injecting the key. Alternatively, the Gemini CLI ignores the GEMINI_API_BASE_URL env var in certain versions.

Proposed Solution

In src/services/api-proxy-service.ts and src/docker-manager.ts, set GEMINI_API_BASE_URL to the api-proxy container's fixed IP ((172.30.0.30/redacted) instead of host.docker.internal. Add an integration test verifying Gemini traffic routes through the api-proxy (source IP is 172.30.0.30in Squid logs, not172.30.0.20`).

Generated by Firewall Issue Dispatcher · ● 876.2K · ◷

Activity

  1. github-actions commented on May 9, 2026

    @github-actions
    Contributor

    👋 Hello! I noticed this issue might be related to several existing issues:

    All of these describe the same core issue: the Gemini CLI bypassing the api-proxy and sending requests directly to Google, resulting in API_KEY_INVALID errors. This new issue adds the specific hypothesis that host.docker.internal may not resolve inside the agent container.

    If any of these closed issues addressed your concern or if the root cause/fix is the same, please consider closing this as a duplicate. Otherwise, feel free to clarify how your issue differs (e.g., a regression or a new environment where the fix doesn't apply)!

    This is an automated message from the issue duplication detector.

    Generated by Issue Duplication Detector for issue #2807 · ● 217.9K · ◷

  2. lpcox commented on May 9, 2026

    @lpcox
    CollaboratorAuthor

    Resolved. Gemini CLI now routes through the api-proxy at http://172.30.0.30:10003 using GEMINI_API_BASE_URL and GOOGLE_GEMINI_BASE_URL environment variables (see src/services/api-proxy-service.ts:275-287). Key injection is handled by containers/api-proxy/providers/gemini.js.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions