You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the VS Code Web module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
IDE Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
17 / 17
25 / 25
20 / 20
7 / 20
10 / 10
86 / 100
Drilldown
Presentation & Onboarding — 17 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
README documents six distinct examples: basic install, custom folder, extensions, machine settings, version pinning (commit_id), and workspace file. Each major mode (folder vs workspace, extensions, settings, version pin) has a dedicated example with sensible defaults.
Visual preview
5
5
README embeds ; file verified to exist at 5,277 KB.
Credential Hygiene — 20 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
The module accepts no credential inputs (no API keys, tokens, or passwords). run.sh uses --without-connection-token, so no auth secret is required. No README example contains an inline secret. Criterion is vacuously satisfied.
Non-hardcoded auth path
4
4
No raw keys or tokens appear in any template or README example. The Coder agent handles workspace connectivity; the VS Code server runs with --without-connection-token. No user-facing credential is needed.
Restricted-Environment Readiness — 7 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
Download URLs in run.sh are hardcoded to update.code.visualstudio.com and vscode.download.prss.microsoft.com. No module input variable overrides the download URL. commit_id pins the version but does not change the source domain; install_prefix controls install location, not download source. No variable names a mirror.
Bring-your-own binary
10
5
offline = true and use_cached = true both skip the download and use a pre-existing binary (verified in run.sh logic). However, neither variable is demonstrated in a README example or dedicated section; they appear only as variable descriptions in main.tf. Partial credit for implemented-but-under-documented.
Egress transparency
3
0
No dedicated README section enumerates external endpoints or provides air-gapped guidance. The two download domains (update.code.visualstudio.com, vscode.download.prss.microsoft.com) are visible only in run.sh source code, not documented in the README.
Runs without sudo
2
2
run.sh never invokes sudo. Default install_prefix is /tmp/vscode-web (user-writable). Settings write to ~/.vscode-server/. Extension installs use the user's code-server binary. No root required for any path.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All 20+ variables have description fields. Sensible defaults throughout (port 13338, telemetry "error", open_in "slim-window"). validation blocks on share, accept_license, telemetry_level, open_in, and platform. lifecycle.precondition enforces mutual exclusions (offline/use_cached, offline/extensions, workspace/folder).
coder_app resource with slug, display_name, icon, subdomain, share, order, group, open_in, and a healthcheck block (/version endpoint, 5s interval, 6 threshold). README states the module "create[s] an app to access it via the dashboard."
Managed configuration
6
6
settings variable merges into Machine settings.json (documented in README "Pre-configure Machine Settings" example). extensions variable pre-installs extensions. auto_install_extensions reads workspace recommendations. All documented with examples.
Configurable folder or workdir
6
6
folder variable opens a directory; workspace variable opens a .code-workspace file. Both documented in README with examples. URL construction in main.tf passes ?folder= or ?workspace= query params. Precondition prevents using both simultaneously.
Pre-installed extensions
6
6
extensions list variable installs extensions at startup (documented in README "Install Extensions" example). auto_install_extensions reads recommendations from .vscode/extensions.json or .code-workspace. extensions_dir allows custom storage location. All documented.
Overall — 86 / 100
Raw 79 / 92 → round(79 / 92 × 100) = 86
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the VS Code Web module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 17 / 17
; file verified to exist at 5,277 KB.Credential Hygiene — 20 / 20
run.shuses--without-connection-token, so no auth secret is required. No README example contains an inline secret. Criterion is vacuously satisfied.--without-connection-token. No user-facing credential is needed.Restricted-Environment Readiness — 7 / 20
run.share hardcoded toupdate.code.visualstudio.comandvscode.download.prss.microsoft.com. No module input variable overrides the download URL.commit_idpins the version but does not change the source domain;install_prefixcontrols install location, not download source. No variable names a mirror.offline = trueanduse_cached = trueboth skip the download and use a pre-existing binary (verified inrun.shlogic). However, neither variable is demonstrated in a README example or dedicated section; they appear only as variable descriptions inmain.tf. Partial credit for implemented-but-under-documented.update.code.visualstudio.com,vscode.download.prss.microsoft.com) are visible only inrun.shsource code, not documented in the README.run.shnever invokessudo. Defaultinstall_prefixis/tmp/vscode-web(user-writable). Settings write to~/.vscode-server/. Extension installs use the user'scode-serverbinary. No root required for any path.Engineering Quality — 10 / 10
descriptionfields. Sensible defaults throughout (port 13338, telemetry "error", open_in "slim-window").validationblocks onshare,accept_license,telemetry_level,open_in, andplatform.lifecycle.preconditionenforces mutual exclusions (offline/use_cached, offline/extensions, workspace/folder).vscode-web.tftest.hclcovers plan-level business logic (open_in default, custom, invalid).main.test.tsprovides 12 end-to-end container tests covering: license validation, mutual-exclusion preconditions, settings creation/merge (jq, python3, neither), JSONC extension parsing (comments, URLs, trailing commas), cached-copy extension install, and cache-hit detection. Thorough and well-structured.IDE Integration — 25 / 25
coder_appresource with slug, display_name, icon, subdomain, share, order, group, open_in, and a healthcheck block (/versionendpoint, 5s interval, 6 threshold). README states the module "create[s] an app to access it via the dashboard."settingsvariable merges into Machinesettings.json(documented in README "Pre-configure Machine Settings" example).extensionsvariable pre-installs extensions.auto_install_extensionsreads workspace recommendations. All documented with examples.foldervariable opens a directory;workspacevariable opens a.code-workspacefile. Both documented in README with examples. URL construction inmain.tfpasses?folder=or?workspace=query params. Precondition prevents using both simultaneously.extensionslist variable installs extensions at startup (documented in README "Install Extensions" example).auto_install_extensionsreads recommendations from.vscode/extensions.jsonor.code-workspace.extensions_dirallows custom storage location. All documented.Overall — 86 / 100
Raw 79 / 92 → round(79 / 92 × 100) = 86
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions