Skip to content

bug: removing the proxy env makes AWS SDK Bedrock clients use h2-only, which the L7 proxy refuses #3709

Description

@jakolehm

User Story

As a user who runs OpenClaw with Amazon Bedrock in an OpenShell sandbox,
I want the agent's Bedrock chat requests to go through the sandbox's HTTP/1.1 L7 mediation,
so that the agent can call the model while the policy still inspects the traffic and injects credentials.

Problem Statement

Since #2942 (c1f2e71), the boundary removes the proxy variables (PROXY_ENV_VARS in crates/openshell-sandbox/src/process.rs) from every child process and from each exec. Before #2942, child_env.rs set HTTP_PROXY/HTTPS_PROXY=http://10.200.0.1:3128, NO_PROXY=127.0.0.1,localhost,::1 and NODE_USE_ENV_PROXY=1.

The OpenClaw Bedrock plugin (@openclaw/amazon-bedrock-provider@2026.8.2) selects its HTTP handler from these variables:

  • If a proxy variable is set, the chat client uses NodeHttpHandler with a proxy agent (HTTP/1.1 through CONNECT).
  • If no proxy variable is set, it uses the default of @aws-sdk/client-bedrock-runtime, which is NodeHttp2Handler. That handler offers only h2 in ALPN.

The L7 proxy offers only http/1.1 (l7/tls.rs). With no common protocol, the TLS handshake fails with alert 120 (RFC 7301 §3.2).

Related: #2426 (h2 ALPN in the L7 proxy), #3377 (another env regression from #2942, also found with OpenClaw).

Impact / Why This Matters

OpenClaw chat requests to Bedrock fail, so the agent cannot use Bedrock models.

Workarounds:

  • AWS_BEDROCK_FORCE_HTTP1=1 makes the chat client use HTTP/1.1. It is an OpenClaw switch, not an AWS SDK switch.
  • tls: skip for the Bedrock endpoint lets the h2 handshake complete, but it turns off L7 inspection and credential injection.

Other clients that select HTTP/1.1 only when a proxy variable is set probably have the same problem.

Acceptance Criteria

Reproduction Steps

  1. Create a sandbox from an OpenClaw image, and install @openclaw/amazon-bedrock-provider@2026.8.2.
  2. Give it a policy that sends TLS to bedrock-runtime.<region>.amazonaws.com through the L7 proxy, and a Bedrock credential.
  3. Start the OpenClaw gateway, and send a chat message.
  4. The request fails with the error in Logs.
  5. Set AWS_BEDROCK_FORCE_HTTP1=1, and do step 3 again. The request completes.

Environment

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    state:triage-neededOpened without agent diagnostics and needs triage

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions