Managing Claude Code Sessions Through Lynx Tigera's Lynx gateway can route Claude Code model traffic by setting the ANTHROPIC_BASE_URL environment variable to the gateway's /llm/anthropic endpoint, giving platform teams visibility into which coding sessions use AI, which model providers and models they call, what data is sent, which policies were applied, and which MCP tools and sub-agents were invoked. Tigera notes the gateway governs only what leaves the machine, not local tool execution such as file reads, source edits, or shell commands, and that a governed laptop is not a sandbox. The company positions the gateway as a complement to isolation work from Anthropic's bubblewrap and seatbelt sandboxing and egress-firewall devcontainer, Docker's coding-agent sandboxes, and Kubernetes-based workload isolation. At Tigera, we spend a lot of time thinking about agent security: identity, policy, runtime controls, and the record left behind after an agent acts. Coding agents create an interesting problem because, in most organizations, they didn’t arrive through the front door. Few companies ran a platform evaluation and rolled Claude Code out to 500 developers. Developers installed it themselves. By the time security and platform teams started asking how coding agents should be governed, they were already running on laptops with access to source code, credentials, SSH keys, kubeconfigs, internal services, and whatever else the developer could reach. The long-term answer is increasingly clear I think: move coding agents into isolated environments you control. Anthropic’s sandboxing work draws filesystem and network boundaries using OS primitives such as bubblewrap and seatbelt. Its reference devcontainer includes an egress firewall. Docker has introduced sandboxes for running coding agents, and Kubernetes-based approaches can add stronger workload isolation, network policy, and disposable development environments. That direction makes sense. Isolation governs what an agent can do. A gateway governs what it can send. And unlike a complete move to remote development environments, the second boundary is something you can introduce today. Start with one environment variable Claude Code allows its model endpoint to be configured through the environment. Instead of connecting directly to Anthropic, point it at the Lynx gateway. export ANTHROPIC BASE URL="https://