Claude Code 2.1.229 Adds SSE Keepalives for Vertex and Bedrock — And Locks Down the Git Push Path

Claude Code 2.1.229 injects SSE keepalive pings into gateway streaming responses during long thinking pauses, preventing silent idle-timeout disconnects on Vertex AI and Bedrock. Plus: /commit-push-pr now blocks dangerous git flags and the sandbox enforces IPv6 fail-closed.

TheRouter Newsroomvia Claude Code Changelog
Claude Code 2.1.229 SSE keepalive and gateway streaming operator guide for Vertex AI and Bedrock

When Claude Code runs a long-reasoning task through Vertex AI or AWS Bedrock, the thinking pause can last tens of seconds. During that silence, most gateway proxies and load balancers count elapsed time since the last byte — and disconnect. The symptom is a clean-looking stream that simply stops, with no HTTP error, no retry signal, and no record in your cost ledger that the request ever completed.

Version 2.1.229 addresses this directly by injecting SSE keepalive pings into gateway streaming responses while long thinking pauses are in progress. The fix is upstream of your infrastructure: it happens in Claude Code's gateway layer, not in the model call or in client-side retry logic.

The idle-timeout problem on cloud upstreams

Vertex AI and Bedrock both sit behind managed load balancers with configurable idle timeouts. Vertex AI's default HTTP/2 stream idle timeout is 600 seconds, but many enterprise deployments reduce this for security. Bedrock's managed VPC endpoints carry AWS Network Load Balancer defaults, typically 350 seconds on TCP, shorter on HTTP. A Claude reasoning response that takes 90–120 seconds of silent compute routinely hit these ceilings in multi-step agent sessions.

The failure mode was subtle. The model returned its full reasoning, but the SSE stream closed before the delta reached the client. The client saw a partial response or an empty content block. Retry logic that keyed on HTTP 5xx got nothing actionable to retry. Meanwhile the Bedrock invocation was billed.

2.1.229 keeps the stream alive through the thinking gap by periodically emitting blank keepalive events. The interval is not configurable from the client side in this release — it is handled by Claude Code's gateway streaming path. What matters operationally is that the fix applies to all sessions routed through Vertex and Bedrock, without any configuration change on your end.

What /commit-push-pr now refuses

Before 2.1.229, Claude Code's auto-approval for /commit-push-pr could accept git and gh commands with flags like --force, --amend, --no-verify, and --force-with-lease. These flags bypass protections that most engineering teams rely on: branch protection, commit-message hooks, and the force-push audit trail.

The change removes these from the auto-approved set. Any git or gh command with a dangerous flag now requires explicit human confirmation, the same way any other sensitive tool use does in Claude Code's permission model.

The routing implication is narrow but real: agents running automated commit workflows through a Claude Code self-hosted runner will hit an approval gate they did not hit before. If your CI pipeline runs /commit-push-pr unattended, test it against 2.1.229 before rolling out to all runners — specifically for any workflow that uses --amend to update the last commit or --no-verify to skip hook overhead.

Sandbox fail-closed on IPv6

Claude Code's sandbox network domain allowlist previously had ambiguous behavior for IPv6 literals. An address like ::1 could be formatted as ::1, [::1], or [::1]:443 depending on where it appeared. The behavior on mismatched formats was permissive: the check would pass rather than refuse.

2.1.229 standardizes IPv6 literals in domain lists to bracketed form ([::1]:443) and enforces fail-closed on ambiguous spellings — meaning anything that does not match the canonical format is treated as blocked, not allowed. The /doctor command now flags non-canonical IPv6 entries in your sandbox config.

For teams that run Claude Code in container environments with IPv6 loopback or link-local addresses in their domain lists, audit your .claude/settings.json sandbox entries before upgrading. The /doctor output will tell you exactly which entries need updating.

Plugin marketplace command sources

2.1.229 adds a command source type for the plugin marketplace. Instead of a static directory path, a local command — for example, an IDE integration — prints the plugin directory on stdout. Claude Code resolves this path at session start and applies the result without a restart. The mode: "link" setting uses the printed path in place, as a symlink-style reference.

For operators who manage plugin distribution centrally — through a shared enterprise tools server or an IDE plugin that controls the local Claude Code configuration — this removes the requirement to hardcode plugin paths in settings files. The plugin directory can be computed dynamically by the IDE process.

The cross-upstream view: what this release means across providers

Every provider-routed session that runs long reasoning goes through this stack: the model API, a gateway layer, and one or more infrastructure hops between your client and the provider endpoint. The SSE keepalive fix sits at the gateway layer. That means it benefits Vertex AI and Bedrock sessions regardless of which upstream model you are using — Claude Sonnet 5 on Vertex, Claude Opus 5 on Bedrock, or any model accessed through a custom ANTHROPIC_BASE_URL gateway that passes through to these platforms.

The fix does not change pricing or concurrency behavior. It changes observability: sessions that previously appeared to complete (from the model's perspective) but delivered partial output will now deliver the full response. If you have been tracking reasoning-session success rates and seeing a gap between invocations billed and responses fully received, 2.1.229 is the first change that closes that gap from the infrastructure side.

What to audit before rolling out 2.1.229

  • CI pipelines using /commit-push-pr with amend or no-verify flags. These now require human approval. Identify any unattended runner jobs that use these flags and decide whether to rewrite them or gate them.
  • Sandbox IPv6 entries in .claude/settings.json. Run /doctor on representative machines. Non-canonical IPv6 literals will appear as flagged items. Rewrite them to bracketed form ([::1]:443) before upgrading containers that depend on loopback network rules.
  • Self-hosted runner startup on Windows. 2.1.229 requires an explicit --base-dir flag on Windows; there is no default checkout directory. Update your runner launch configuration if you run Windows-based CI environments.
  • managed-mcp.json deployments on self-hosted runners. Previously, runner sessions could exit at startup if managed-mcp.json was deployed but the server could not deliver MCP servers. 2.1.229 logs a warning and skips those servers instead of exiting. Confirm your runner monitoring is watching for these skip events if MCP connectivity matters to your workflow.

What TheRouter users should watch

TheRouter routes Claude Code sessions to cloud upstreams including Vertex AI and Bedrock. The SSE keepalive behavior in 2.1.229 reduces the rate of silent stream termination on long-thinking requests without any configuration change. If you have been tracking delivery failures on reasoning-heavy sessions routed to Vertex or Bedrock, upgrading to 2.1.229 is the first measure to apply before looking at gateway timeout configuration.

For teams managing multiple Claude Code deployments across runner environments, the new plugin command source type in 2.1.229 is worth examining as a mechanism for centralizing plugin distribution without hardcoding paths in per-machine settings files.

Help & contact