Course
ai-dev-tools-zoomcamp
Question
In Homework 4 (incident responder), my service starts Claude Code in headless mode with claude -p ... --allowedTools "Bash(uv *) Bash(docker compose *) Bash(curl *)". The agent diagnoses the bug and edits the code, but every uv run, docker compose and curl command is blocked and it says it cannot get approval. Why, and how do I fix it on Windows?
Answer
On Windows, Claude Code can run shell commands through its PowerShell tool instead of Bash. Bash(...) rules in --allowedTools only cover the Bash tool, so commands that go through PowerShell are not allowlisted and, in headless mode (-p), nobody can approve them, so they are denied. Editing files with Read/Edit/Write still works, which is why the agent can diagnose and change the code but cannot run tests, rebuild or verify.
Fix: allowlist the same commands for the PowerShell tool as well, for example:
--allowedTools "Read Edit Write Bash(uv *) Bash(docker compose *) Bash(curl *) PowerShell(uv *) PowerShell(docker compose *) PowerShell(curl.exe *) PowerShell(git status) PowerShell(git diff *)"
Tip 1: test the permissions before the real incident with a throwaway claude -p run that only runs docker compose ps, curl.exe -s http://localhost:8000/healthz and uv run pytest -q.
Tip 2: keep the list narrow. Do not allow git push or delete commands, and note that a broad rule like uv * also allows uv run python -c ....
Tip 3: in PowerShell use curl.exe, because plain curl is an alias for Invoke-WebRequest.
Checklist
Course
ai-dev-tools-zoomcamp
Question
In Homework 4 (incident responder), my service starts Claude Code in headless mode with
claude -p ... --allowedTools "Bash(uv *) Bash(docker compose *) Bash(curl *)". The agent diagnoses the bug and edits the code, but everyuv run,docker composeandcurlcommand is blocked and it says it cannot get approval. Why, and how do I fix it on Windows?Answer
On Windows, Claude Code can run shell commands through its PowerShell tool instead of Bash.
Bash(...)rules in--allowedToolsonly cover the Bash tool, so commands that go through PowerShell are not allowlisted and, in headless mode (-p), nobody can approve them, so they are denied. Editing files with Read/Edit/Write still works, which is why the agent can diagnose and change the code but cannot run tests, rebuild or verify.Fix: allowlist the same commands for the PowerShell tool as well, for example:
Tip 1: test the permissions before the real incident with a throwaway
claude -prun that only runsdocker compose ps,curl.exe -s http://localhost:8000/healthzanduv run pytest -q.Tip 2: keep the list narrow. Do not allow
git pushor delete commands, and note that a broad rule likeuv *also allowsuv run python -c ....Tip 3: in PowerShell use
curl.exe, because plaincurlis an alias for Invoke-WebRequest.Checklist