Problem
Gemini engine runs fail with 400 API_KEY_INVALID even when using a valid Google AI Studio API key. Squid access logs confirm requests originate from the agent container (172.30.0.20) directly, not from the api-proxy (172.30.0.30). The api-proxy intercept on port 10003 is not functioning — `GEMINI_API_BASE_URL=(host.docker.internal/redacted) is set in the agent environment but the Gemini CLI bypasses it.
Context
Original issue: github/gh-aw#29417
Root Cause
host.docker.internal may not resolve inside the agent container in all environments, causing the Gemini CLI to fall back to direct requests to generativelanguage.googleapis.com without the api-proxy injecting the key. Alternatively, the Gemini CLI ignores the GEMINI_API_BASE_URL env var in certain versions.
Proposed Solution
In src/services/api-proxy-service.ts and src/docker-manager.ts, set GEMINI_API_BASE_URL to the api-proxy container's fixed IP ((172.30.0.30/redacted) instead of host.docker.internal. Add an integration test verifying Gemini traffic routes through the api-proxy (source IP is 172.30.0.30in Squid logs, not172.30.0.20`).
Generated by Firewall Issue Dispatcher · ● 876.2K · ◷
Problem
Gemini engine runs fail with
400 API_KEY_INVALIDeven when using a valid Google AI Studio API key. Squid access logs confirm requests originate from the agent container (172.30.0.20) directly, not from the api-proxy (172.30.0.30). The api-proxy intercept on port 10003 is not functioning — `GEMINI_API_BASE_URL=(host.docker.internal/redacted) is set in the agent environment but the Gemini CLI bypasses it.Context
Original issue: github/gh-aw#29417
Root Cause
host.docker.internalmay not resolve inside the agent container in all environments, causing the Gemini CLI to fall back to direct requests togenerativelanguage.googleapis.comwithout the api-proxy injecting the key. Alternatively, the Gemini CLI ignores theGEMINI_API_BASE_URLenv var in certain versions.Proposed Solution
In
src/services/api-proxy-service.tsandsrc/docker-manager.ts, setGEMINI_API_BASE_URLto the api-proxy container's fixed IP ((172.30.0.30/redacted) instead ofhost.docker.internal. Add an integration test verifying Gemini traffic routes through the api-proxy (source IP is172.30.0.30in Squid logs, not172.30.0.20`).