Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
25 changes: 8 additions & 17 deletions templates/kubernetes/homelab-workspace/deployment.tf
Original file line number Diff line number Diff line change
Expand Up @@ -54,10 +54,6 @@ resource "kubernetes_deployment_v1" "deployment" {
name = "HOMEBREW_PREFIX"
value = local.homebrew_directory
}
env {
name = "NORMALISE_TMP_PERMISSIONS"
value = "true"
}
volume_mount {
mount_path = local.home_directory
name = "home"
Expand All @@ -84,19 +80,19 @@ resource "kubernetes_deployment_v1" "deployment" {
}
}
container {
name = "workspace"
# Not Coder's generated /scripts/workspace-init.sh directly: the entrypoint
# wipes /tmp and then execs it. The wipe has to happen before the
# agent unpacks its CLI into /tmp, and this is the only hook that runs
# on a container-only restart within a live Pod (init containers do
# not) - see script-container-entrypoint.sh and the "tmp" volume
# below.
name = "workspace"
command = ["/bin/bash", "/scripts/script-container-entrypoint.sh"]
image = var.workspace_image
env {
name = "CODER_AGENT_TOKEN"
value = coder_agent.main.token
}
env_from {
secret_ref {
name = "coder-workspace-env"
optional = true
}
}
liveness_probe {
exec {
command = ["/bin/sh", "-c", "pgrep -f \"coder agent\" || exit 1"]
Expand Down Expand Up @@ -270,12 +266,7 @@ resource "kubernetes_deployment_v1" "deployment" {
# node notices. Its lifecycle matches the Pod's (created fresh, deleted
# with it) - like the "system" volume above, that means a Pod restart
# gets a clean volume but a container-only restart within a live Pod
# does not, which is why the container's entrypoint
# (script-container-entrypoint.sh) wipes /tmp's contents explicitly on
# every container start instead of relying on this. That wipe belongs in
# the entrypoint and nowhere later: the Coder agent unpacks its own CLI
# into /tmp before it runs anything else, so a wipe from the agent
# startup script deletes it.
# does not.
volume {
name = "tmp"
ephemeral {
Expand Down
Original file line number Diff line number Diff line change
@@ -1,6 +1,9 @@
#!/bin/bash
set -eo pipefail

ENV_VARS_FILE="/home/coder/.env.pod"


# Coder's bootstrap unpacks the agent CLI into a per-boot directory under /tmp
# and the agent appends that directory to the PATH of everything it runs, so
# resolving "coder" here goes through exactly the same lookup a metadata script
Expand Down Expand Up @@ -32,6 +35,9 @@ main() {
echo 'set -o allexport; source /etc/environment; set +o allexport' >> ~/.bashrc
echo '------------------------------------------------------------'
fi
if [[ -f "${ENV_VARS_FILE}" ]]; then
set -a; source "${ENV_VARS_FILE}"; set +a
fi
echo 'Done'
}

Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,23 @@
#!/bin/bash
set -eo pipefail

ENV_VARS_FILE="/home/coder/.env.pod"


record_env_vars() {
if [[ -f "${ENV_VARS_FILE}" ]]; then
rm -f "${ENV_VARS_FILE}"
fi
touch "${ENV_VARS_FILE}"
for key in $(env | cut -d= -f1 | grep '^CODER_VAR_'); do
value=$(printenv "$key")
echo "$key=\"$value\"" >> "${ENV_VARS_FILE}"
done
}

main() {
record_env_vars

# Hand off to Coder's generated agent bootstrap, replacing this process rather
# than spawning it: the agent has to stay PID 1, both because it reaps orphans
# in this container and because the Deployment's liveness probe pgreps for it.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -81,10 +81,6 @@ prepare_environment() {
}

normalise_tmp_permissions() {
if [[ "${NORMALISE_TMP_PERMISSIONS:-}" != "true" ]]; then
return
fi

# fsGroup makes the production volume group-writable. The sticky bit keeps
# processes that share /tmp from replacing one another's entries.
chmod 1777 /tmp
Expand Down