---
title: "Managing Claude Code Sessions Through Lynx"
source: "https://www.tigera.io/blog/managing-claude-code-sessions-through-lynx/"
description: "Your developers already run Claude Code. Point it at the Lynx gateway with one environment variable and every model turn becomes observable and governable."
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# Managing Claude Code Sessions Through Lynx

By [Peter Kelly](https://www.tigera.io/blog/author/peter-kelly/) on Sep 30, 2026 • 3 min read

At Tigera, we spend a lot of time thinking about agent security: identity, policy, runtime controls, and the record left behind after an agent acts.

Coding agents create an interesting problem because, in most organizations, they didn’t arrive through the front door.

Few companies ran a platform evaluation and rolled Claude Code out to 500 developers. Developers installed it themselves. By the time security and platform teams started asking how coding agents should be governed, they were already running on laptops with access to source code, credentials, SSH keys, kubeconfigs, internal services, and whatever else the developer could reach.

The long-term answer is increasingly clear I think: move coding agents into isolated environments you control.

Anthropic’s sandboxing work draws filesystem and network boundaries using OS primitives such as bubblewrap and seatbelt. Its reference devcontainer includes an egress firewall. Docker has introduced sandboxes for running coding agents, and Kubernetes-based approaches can add stronger workload isolation, network policy, and disposable development environments.

That direction makes sense.

***Isolation governs what an agent can do. A gateway governs what it can send.***

And unlike a complete move to remote development environments, the second boundary is something you can introduce today.

## Start with one environment variable

Claude Code allows its model endpoint to be configured through the environment.

Instead of connecting directly to Anthropic, point it at the Lynx gateway.

```
`export ANTHROPIC_BASE_URL="https://<lynx-gateway>/llm/anthropic"`
```

That’s the entire change on the developer’s machine.

- No endpoint agent. No daemon. No certificate installation.

- No rebuilt development environment.

The next model turn goes through Lynx, and every model turn after it does too.

That small change turns otherwise disconnected model calls into something more useful: a coding session that can be observed, governed, and recorded.

![Coding sessions list in Lynx](https://www.tigera.io/app/uploads/2026/09/Managing-Claude-Code-Sessions-Through-Lynx-1.png)Coding sessions list in Lynx
![Coding session summary in Lynx](https://www.tigera.io/app/uploads/2026/09/Managing-Claude-Code-Sessions-Through-Lynx-2.png)Coding session summary in Lynx

## What this gives you

Instead of seeing another HTTPS connection from a developer laptop to an AI provider, the platform can start answering important questions:

- Which coding sessions are using AI?

- Which model providers and models are they using?

- What information is being sent to those models?

- Which policies were applied?

- Which MCP tools were called through the gateway?

- Did the session spawn sub-agents?

- What happened during a particular coding session?

That is a significant improvement over an unmanaged agent talking directly to a model provider.

## What this does not do

A gateway gives you a strong answer to what left the building, not what happened on the machine.

- Local tools run on the laptop and do not transit the gateway.

- Example: Claude Code reads a file, edits source code, or runs a shell command locally.

- Some of that activity may appear in model traffic (e.g., tool calls, results, retrieved files, or other context).

- That is observation, not enforcement.

## A governed laptop is not a sandbox

Routing Claude Code through a gateway does not suddenly give Lynx control over the developer’s machine.

- Every model turn that transits the gateway can be governed.

- MCP calls can also be governed when the MCP server is reached through the gateway.

- Local tools are different. The gateway isn’t on that execution path and cannot prevent it.

But that is observation, not enforcement.

## What a governed coding session looks like

![Diagram: Claude Code on the developer laptop routes model and MCP traffic through the Lynx gateway (identity, Cedar policy, audit) to external services; local tools stay un-governed](https://www.tigera.io/app/uploads/2026/09/Managing-Claude-Code-Sessions-Through-Lynx-3.png)

## From unmanaged laptop to governed sandbox

![Diagram: from unmanaged laptop, to governed coding session on the laptop, to governed sandbox with runtime containment](https://www.tigera.io/app/uploads/2026/09/Managing-Claude-Code-Sessions-Through-Lynx-4.png)

[Learn more about Lynx →](https://www.tigera.io/tigera-products/lynx/)

[AI Agent Security](https://www.tigera.io/tags/ai-agent-security/)

## Related posts

[![The Clearinghouse For AI Agents Has A Blind Spot](https://www.tigera.io/app/uploads/2026/09/Lynx-Clearinghouse-Blog.png)](https://www.tigera.io/blog/clearinghouse/)

#### [The Clearinghouse For AI Agents Has A Blind Spot](https://www.tigera.io/blog/clearinghouse/)

By [Dillon Barry](https://www.tigera.io/blog/author/dillon-barry/)
on Sep 23, 2026

Jamin Ball’s recent piece, “Systems of Record Won the SaaS Era — Clearinghouses Will Win the Agents Era,” is the cleanest articulation I’ve seen of where the durable moat goes next. His argument is simple...

[Read more](https://www.tigera.io/blog/clearinghouse/)

[![HITL for autonomous agents: Where does the human go?](https://www.tigera.io/app/uploads/2026/09/HITL-for-autonomous-agents-Where-does-the-human-go.png)](https://www.tigera.io/blog/hitl-for-autonomous-agents-where-does-the-human-go/)

#### [HITL for autonomous agents: Where does the human go?](https://www.tigera.io/blog/hitl-for-autonomous-agents-where-does-the-human-go/)

By [Peter Kelly](https://www.tigera.io/blog/author/peter-kelly/)
on Sep 16, 2026

Human approval is easy when you are sitting in front of the agent. For an agent running by itself in a cluster, almost none of that holds. You’re in a meeting and your agent is...

[Read more](https://www.tigera.io/blog/hitl-for-autonomous-agents-where-does-the-human-go/)

[![AI Agents on Kubernetes 101: From Laptop Script to Production Pod](https://www.tigera.io/app/uploads/2026/09/AI-Agents-on-Kubernetes-101-From-Laptop-Script-to-Production-Pod.png)](https://www.tigera.io/blog/ai-agents-on-kubernetes-101-from-laptop-script-to-production-pod/)

#### [AI Agents on Kubernetes 101: From Laptop Script to Production Pod](https://www.tigera.io/blog/ai-agents-on-kubernetes-101-from-laptop-script-to-production-pod/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Sep 8, 2026

In short, this is a beginner’s guide to deploying an AI agent on Kubernetes. You will containerize an agent, store its API key as a Kubernetes secret, write a deployment with health probes and resource...

[Read more](https://www.tigera.io/blog/ai-agents-on-kubernetes-101-from-laptop-script-to-production-pod/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=6061 metric#misses=33 metric#hit-ratio=99.5 metric#bytes=2211357 metric#prefetches=0 metric#store-reads=428 metric#store-writes=14 metric#store-hits=429 metric#store-misses=22 metric#sql-queries=31 metric#ms-total=941.48 metric#ms-cache=48.74 metric#ms-cache-avg=0.1105 metric#ms-cache-ratio=5.2 sample#redis-hits=21536783 sample#redis-misses=6709190 sample#redis-hit-ratio=76.2 sample#redis-ops-per-sec=270 sample#redis-evicted-keys=0 sample#redis-used-memory=86409896 sample#redis-used-memory-rss=87060480 sample#redis-memory-fragmentation-ratio=1.0 sample#redis-connected-clients=1 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=24543 -->
