Disabling AI Code review in Air-gapped environment
In an air-gapped environment, you must disable the AI-powered code review that Code Genie runs on pull request creation or update.
About this task
An air-gapped environment is a deployment that is physically or logically isolated from the public internet, with no outbound network access to external services.
The Copilot code review script requires internet access to
communicate with the GitHub Copilot service. In an air-gapped environment, this
communication is not possible. You must comment out the Copilot
entry in the "pull-request" array of
.devops-loop/code-config.jsonc before you use Code Genie in
an air-gapped environment.
Procedure
- Open .devops-loop/code-config.jsonc in the Control repository.
-
Locate the
"pull-request"array. -
Enclose the
Copilotentry in block comments (/* */).Leave theTrivyScanentry active as it does not require internet access and can continue to run on pull request creation and update. - Save the file.
Results
With the Copilot entry disabled, Code Genie continues to run the
Trivy security scan on pull request creation and update, but no longer attempts to
run AI-powered code review.
Copilot code
review is required in air-gapped environments, not optional. If the
Copilot entry is left active, the code review dev container
fails because it cannot reach the GitHub Copilot service.Example
The following example shows the "pull-request" array configured for
an air-gapped environment, with TrivyScan active and
Copilot code review disabled:
"pull-request": [
{
"dev-container": "TrivyScan",
"interactive": false,
"custom-commands": [
{
"run-trivy": "cp /opt/run-trivy.sh /usr/code/ && chmod +x /usr/code/run-trivy.sh && REPO_URL=https://${platform-fqdm}/control/${repo-owner}/${repo}/src/branch/${pr-branch}/ /usr/code/run-trivy.sh ${code-folder} ${result-json} --reject=high --trivyArgs=\"--scanners vuln,misconfig,secret,license --license-full --severity UNKNOWN,LOW,MEDIUM,HIGH,CRITICAL\""
}
]
}
/*,{
"dev-container": "Copilot",
"interactive": true,
"custom-commands": [
{
"code-review-command": "export GH_TOKEN=${loop_property:copilotclitoken} && cp /opt/run-copilot.ts /usr/code/ && tsx /usr/code/run-copilot.ts --prompt-file=${promptFile} --llm_args=\"--allow-all-tools --model claude-sonnet-4.5\""
}
]
}*/
]
What to do next
Installing extensions in dev containers in an air-gapped environment
When a custom dev container, such as the Java devcontainer, is launched in an air-gapped environment, extensions do not get installed by default, with the exception of the DevOps Code extension itself. This occurs because extension installation normally requires outbound access to a public extension marketplace, which is not available in an air-gapped environment. In order to make the required extensions available, you can follow the steps below:
- Identify the extensions required by the custom devcontainer. For example, the Java dev container requires the extensions used for Java development and debugging.
- Add the required extensions to the extension registry. Refer to extension registry documentation.
- Launch the custom devcontainer, for example the Java dev container.
- Install the required extensions manually inside the launched dev container, following the same extension registry documentation.
The required extensions are then available inside the devcontainer, in addition to the default DevOps Code extension.