Skip to content

feat: supervise user-defined workspace services - #921

Merged
ppat merged 1 commit into
mainfrom
feat/supervised-workspace-services
Sep 16, 2026
Merged

ppat merged 1 commit into
mainfrom
feat/supervised-workspace-services

Conversation

@homelab-agent-bot

@homelab-agent-bot homelab-agent-bot Bot commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • install Supervisor in the workspace image
  • add a mutable service_commands list parameter, with one automatically restarted Supervisor program per command
  • start Supervisor only after the external Chezmoi apply script succeeds, while preserving the no-dotfiles path
  • mount a native supervisord.conf; no shell or Terraform generates configuration for another tool

Design

flowchart LR
    Parameter[service_commands list] --> JSON[Coder environment JSON]
    Dotfiles[Chezmoi update or apply] -->|success| Launcher[Supervisor launcher]
    JSON --> Launcher
    Launcher --> P0[service-0]
    Launcher --> PN[service-N]
Loading

Command text remains in JSON and each Supervisor process invokes a wrapper by list index. The static Supervisor configuration expands only the process count from the environment, avoiding interpolation of user commands into INI syntax. Supervisor and its children run as the existing unprivileged coder user; PID 1 remains the Coder agent.

A failed Chezmoi run starts no services. With no dotfiles repository configured, the explicit no-op path completes before services start.

Verification

  • pre-commit run --all-files
  • tofu validate
  • tflint --config=../../../.tflint.hcl
  • shellcheck templates/kubernetes/homelab-workspace/script-*.sh
  • built the complete image on sandbox-docker
  • ran two Supervisor processes as UID 10001 from the static config and verified both intentionally exiting commands restarted
  • verified indexed JSON command execution with shell metacharacters

For template-only changes, test-template continues to use the latest released image. For image changes, test-image passes its published branch image into the reusable template integration workflow. That workflow loads the existing image into Kind rather than rebuilding it, then runs two services: one deliberately exits to prove restart and one remains running to prove multiple commands become independent processes. Both record any pre-Chezmoi start. The assertions require no early-start marker, at least two invocations of the restarting service, the steady-service marker, and both Supervisor process statuses.

The commit uses the required empty scope for an atomic image-plus-template feature.

@homelab-agent-bot
homelab-agent-bot Bot force-pushed the feat/supervised-workspace-services branch 11 times, most recently from d1de790 to 497337c Compare September 15, 2026 23:35
Install Supervisor in the workspace image and expose a dynamic list of service commands through the template.

Apply dotfiles before launching the unprivileged supervisor and resolve each command from JSON by index.

Keep shell implementations in mounted scripts rather than HCL.
@homelab-agent-bot
homelab-agent-bot Bot force-pushed the feat/supervised-workspace-services branch from 497337c to d347b4e Compare September 15, 2026 23:47
@ppat
ppat merged commit 0329913 into main Sep 16, 2026
19 checks passed
@ppat
ppat deleted the feat/supervised-workspace-services branch September 16, 2026 18:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant