Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .github/workflows/test-template.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -170,7 +170,8 @@ jobs:
--parameter dotfiles_url=https://github.com/ppat/dotfiles.git \
--parameter use_existing_home_pvc=false --parameter home_pvc_size=2 --parameter tmp_pvc_size=1 \
--parameter memory=4 --parameter preferred_nodes='[]' --parameter memory_watchdog_mode=enforce \
--parameter "${service_parameter}"
--parameter "${service_parameter}" \
--parameter "filebrowser_enabled=true"

- name: Ping workspace agent
shell: bash
Expand Down
2 changes: 1 addition & 1 deletion templates/kubernetes/homelab-workspace/configmap.tf
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ resource "kubernetes_config_map_v1" "workspace_scripts" {
"script-start-services.sh" = file("${path.cwd}/scripts/script-start-services.sh")
"supervisord.conf" = file("${path.cwd}/config/supervisord.conf")
"script-vscode-server-gc.sh" = file("${path.cwd}/scripts/script-vscode-server-gc.sh")
"filebrowser-agent-init.sh" = coder_agent.filebrowser.init_script
"filebrowser-agent-init.sh" = data.coder_parameter.filebrowser_enabled.value ? coder_agent.filebrowser[0].init_script : ""
"filebrowser.yaml" = file("${path.cwd}/config/filebrowser.yaml")
"workspace-init.sh" = coder_agent.main.init_script
}
Expand Down
160 changes: 84 additions & 76 deletions templates/kubernetes/homelab-workspace/deployment.tf
Original file line number Diff line number Diff line change
Expand Up @@ -141,82 +141,85 @@ resource "kubernetes_deployment_v1" "deployment" {
name = "tmp"
}
}
container {
name = "filebrowser"
command = ["/bin/sh", "/scripts/filebrowser-agent-init.sh"]
image = "gtstef/filebrowser:1.5.6-stable@sha256:7c5d7ac8ffda31294d278063cf9d2e04303b39e6dce1f4c691342240ca7703b8"
env {
name = "CODER_AGENT_TOKEN"
value = coder_agent.filebrowser.token
}
env {
name = "FILEBROWSER_CONFIG"
value = "/config/filebrowser.yaml"
}
env {
name = "HOME"
value = "/home/filebrowser/data"
}
env {
name = "USER"
# The image's filebrowser account uses /bin/true. The agent uses
# this account only to select a shell; the Pod still enforces the
# non-root UID below.
value = "root"
}
port {
container_port = 8080
name = "filebrowser"
protocol = "TCP"
}
liveness_probe {
http_get {
path = "/health"
port = 8080
scheme = "HTTP"
dynamic "container" {
for_each = data.coder_parameter.filebrowser_enabled.value ? toset(["filebrowser"]) : []
content {
name = "filebrowser"
command = ["/bin/sh", "/scripts/filebrowser-agent-init.sh"]
image = "gtstef/filebrowser:1.5.6-stable@sha256:7c5d7ac8ffda31294d278063cf9d2e04303b39e6dce1f4c691342240ca7703b8"
env {
name = "CODER_AGENT_TOKEN"
value = coder_agent.filebrowser.token
}
initial_delay_seconds = 15
period_seconds = 30
timeout_seconds = 3
failure_threshold = 3
}
resources {
requests = {
"cpu" = "25m"
"memory" = "128Mi"
env {
name = "FILEBROWSER_CONFIG"
value = "/config/filebrowser.yaml"
}
limits = {
"memory" = "256Mi"
env {
name = "HOME"
value = "/home/filebrowser/data"
}
env {
name = "USER"
# The image's filebrowser account uses /bin/true. The agent uses
# this account only to select a shell; the Pod still enforces the
# non-root UID below.
value = "root"
}
port {
container_port = 8080
name = "filebrowser"
protocol = "TCP"
}
liveness_probe {
http_get {
path = "/health"
port = 8080
scheme = "HTTP"
}
initial_delay_seconds = 15
period_seconds = 30
timeout_seconds = 3
failure_threshold = 3
}
resources {
requests = {
"cpu" = "25m"
"memory" = "256Mi"
}
limits = {
"memory" = "512Mi"
}
}
security_context {
allow_privilege_escalation = false
read_only_root_filesystem = false
privileged = false
run_as_user = 10001
run_as_group = 10001
run_as_non_root = true
}
volume_mount {
mount_path = "/srv"
name = "home"
sub_path = data.coder_workspace.me.name
}
volume_mount {
mount_path = "/scripts/filebrowser-agent-init.sh"
name = "coder-scripts"
sub_path = "filebrowser-agent-init.sh"
read_only = true
}
volume_mount {
mount_path = "/config/filebrowser.yaml"
name = "coder-scripts"
sub_path = "filebrowser.yaml"
read_only = true
}
volume_mount {
mount_path = "/home/filebrowser/data"
name = "filebrowser-data"
}
}
security_context {
allow_privilege_escalation = false
read_only_root_filesystem = false
privileged = false
run_as_user = 10001
run_as_group = 10001
run_as_non_root = true
}
volume_mount {
mount_path = "/srv"
name = "home"
sub_path = data.coder_workspace.me.name
}
volume_mount {
mount_path = "/scripts/filebrowser-agent-init.sh"
name = "coder-scripts"
sub_path = "filebrowser-agent-init.sh"
read_only = true
}
volume_mount {
mount_path = "/config/filebrowser.yaml"
name = "coder-scripts"
sub_path = "filebrowser.yaml"
read_only = true
}
volume_mount {
mount_path = "/home/filebrowser/data"
name = "filebrowser-data"
}
}
enable_service_links = false
Expand Down Expand Up @@ -246,9 +249,14 @@ resource "kubernetes_deployment_v1" "deployment" {
default_mode = "0750"
}
}
volume {
name = "filebrowser-data"
empty_dir {}
dynamic "volume" {
for_each = data.coder_parameter.filebrowser_enabled.value ? toset(["filebrowser"]) : []
content {
name = "filebrowser-data"
empty_dir {
size_limit = "3Gi"
}
}
}
# /tmp is scratch space (agent/tool tempfiles, build caches, downloaded
# archives) and needs to be fast - it cannot be the NFS-backed "home"
Expand Down
6 changes: 5 additions & 1 deletion templates/kubernetes/homelab-workspace/filebrowser.tf
Original file line number Diff line number Diff line change
@@ -1,4 +1,6 @@
resource "coder_agent" "filebrowser" {
count = data.coder_parameter.filebrowser_enabled.value ? 1 : 0

arch = "amd64"
os = "linux"
api_key_scope = "no_user_data"
Expand All @@ -16,7 +18,9 @@ resource "coder_agent" "filebrowser" {
}

resource "coder_app" "filebrowser" {
agent_id = coder_agent.filebrowser.id
count = data.coder_parameter.filebrowser_enabled.value ? 1 : 0

agent_id = coder_agent.filebrowser[0].id
slug = "files"
display_name = "Files"
icon = "/icon/folder.svg"
Expand Down
11 changes: 11 additions & 0 deletions templates/kubernetes/homelab-workspace/parameters.tf
Original file line number Diff line number Diff line change
Expand Up @@ -148,6 +148,17 @@ data "coder_parameter" "memory_watchdog_mode" {
}
}

data "coder_parameter" "filebrowser_enabled" {
name = "filebrowser_enabled"

default = false
display_name = "File Browser"
description = "Whether to enable the file browser"
mutable = true
type = "bool"
form_type = "checkbox"
}


locals {
# Coder already constrains this to the two option values server-side, but it
Expand Down
Loading