diff --git a/.github/workflows/test-template.yaml b/.github/workflows/test-template.yaml index 8eb8ceda..53ec7d3a 100644 --- a/.github/workflows/test-template.yaml +++ b/.github/workflows/test-template.yaml @@ -178,51 +178,6 @@ jobs: # this otherwise unrelated readiness check ambiguous. run: coder ping --num 3 --timeout 30s "${WORKSPACE_NAME}.main" - - name: Confirm File Browser sidecar and Coder app - shell: bash - run: | - deployment_name="$(kubectl --namespace coder get deployment \ - --selector "com.coder.workspace.name=${WORKSPACE_NAME}" \ - --output jsonpath='{.items[0].metadata.name}')" - session_token="$(<"${HOME}/.config/coderv2/session")" - - # The second agent is the sidecar's PID 1. Prove Coder can route to it - # before probing the process and application that it owns. - coder ping --num 3 --timeout 30s "${WORKSPACE_NAME}.filebrowser" - - kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \ - sh -c 'tr "\0" " " /dev/null - # Expand the command substitution inside the sidecar, not on the runner. - # shellcheck disable=SC2016 - kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \ - sh -c 'test "$(cat /srv/.filebrowser-sidecar-test)" = workspace && printf sidecar > /srv/.filebrowser-sidecar-test' - [[ "$(coder ssh "${WORKSPACE_NAME}.main" -- cat /home/coder/.filebrowser-sidecar-test)" == "sidecar" ]] - - # File Browser requires the subdomain proxy because its root-relative - # assets cannot survive Coder's path-prefix stripping. Exercise both the - # configured home source and frontend through that proxy, not only the - # Pod-local listener. - app_url="http://files--${WORKSPACE_NAME}--ci.localhost:7080" - served_marker="$(curl --fail --silent --show-error \ - --header "Coder-Session-Token: ${session_token}" \ - "${app_url}/api/resources/download?source=srv&file=/.filebrowser-sidecar-test")" - [[ "${served_marker}" == "sidecar" ]] - app_html="$(curl --fail --silent --show-error \ - --header "Coder-Session-Token: ${session_token}" "${app_url}/")" - grep --quiet '' <<<"${app_html}" - asset_path="$(grep --only-matching --max-count=1 '/public/static/[^"]*' <<<"${app_html}")" - [[ -n "${asset_path}" ]] - curl --fail --silent --show-error \ - --header "Coder-Session-Token: ${session_token}" \ - --output /dev/null "${app_url}${asset_path}" - - name: Run command over workspace SSH shell: bash run: | @@ -378,11 +333,4 @@ jobs: kubectl --namespace coder logs \ --selector "com.coder.workspace.name=${WORKSPACE_NAME}" \ --all-containers --prefix --tail=200 || true - pod_name="$(kubectl --namespace coder get pods \ - --selector "com.coder.workspace.name=${WORKSPACE_NAME}" \ - --output jsonpath='{.items[0].metadata.name}')" - kubectl --namespace coder exec "pod/${pod_name}" --container filebrowser -- \ - cat /tmp/coder-startup-script.log || true - kubectl --namespace coder exec "pod/${pod_name}" --container filebrowser -- \ - cat /tmp/filebrowser.log || true docker compose -f "${COMPOSE_FILE}" logs diff --git a/templates/kubernetes/homelab-workspace/config/filebrowser.yaml b/templates/kubernetes/homelab-workspace/config/filebrowser.yaml deleted file mode 100644 index 7021e90e..00000000 --- a/templates/kubernetes/homelab-workspace/config/filebrowser.yaml +++ /dev/null @@ -1,32 +0,0 @@ ---- -server: - port: 8080 - baseURL: "/" - cacheDir: "/home/filebrowser/data/tmp" - logging: - - levels: "info|warning|error" - sources: - - path: "/srv" - -# Coder's owner-only application proxy is the authentication boundary. The -# sidecar has no Service and File Browser is not reachable outside the Pod. -auth: - methods: - noauth: true - -frontend: - name: "Workspace Files" - disableDefaultLinks: true - -userDefaults: - listing: - showHidden: true - account: - permissions: - admin: false - api: false - create: true - delete: true - download: true - modify: true - share: false diff --git a/templates/kubernetes/homelab-workspace/configmap.tf b/templates/kubernetes/homelab-workspace/configmap.tf index 80ad63f4..7ff01ef1 100644 --- a/templates/kubernetes/homelab-workspace/configmap.tf +++ b/templates/kubernetes/homelab-workspace/configmap.tf @@ -18,8 +18,6 @@ resource "kubernetes_config_map_v1" "workspace_scripts" { "script-start-services.sh" = file("${path.cwd}/scripts/script-start-services.sh") "supervisord.conf" = file("${path.cwd}/config/supervisord.conf") "script-vscode-server-gc.sh" = file("${path.cwd}/scripts/script-vscode-server-gc.sh") - "filebrowser-agent-init.sh" = coder_agent.filebrowser.init_script - "filebrowser.yaml" = file("${path.cwd}/config/filebrowser.yaml") "workspace-init.sh" = coder_agent.main.init_script } } diff --git a/templates/kubernetes/homelab-workspace/deployment.tf b/templates/kubernetes/homelab-workspace/deployment.tf index 5887b8da..708b2f97 100644 --- a/templates/kubernetes/homelab-workspace/deployment.tf +++ b/templates/kubernetes/homelab-workspace/deployment.tf @@ -141,84 +141,6 @@ resource "kubernetes_deployment_v1" "deployment" { name = "tmp" } } - container { - name = "filebrowser" - command = ["/bin/sh", "/scripts/filebrowser-agent-init.sh"] - image = "gtstef/filebrowser:1.5.6-stable@sha256:7c5d7ac8ffda31294d278063cf9d2e04303b39e6dce1f4c691342240ca7703b8" - env { - name = "CODER_AGENT_TOKEN" - value = coder_agent.filebrowser.token - } - env { - name = "FILEBROWSER_CONFIG" - value = "/config/filebrowser.yaml" - } - env { - name = "HOME" - value = "/home/filebrowser/data" - } - env { - name = "USER" - # The image's filebrowser account uses /bin/true. The agent uses - # this account only to select a shell; the Pod still enforces the - # non-root UID below. - value = "root" - } - port { - container_port = 8080 - name = "filebrowser" - protocol = "TCP" - } - liveness_probe { - http_get { - path = "/health" - port = 8080 - scheme = "HTTP" - } - initial_delay_seconds = 15 - period_seconds = 30 - timeout_seconds = 3 - failure_threshold = 3 - } - resources { - requests = { - "cpu" = "25m" - "memory" = "128Mi" - } - limits = { - "memory" = "256Mi" - } - } - security_context { - allow_privilege_escalation = false - read_only_root_filesystem = false - privileged = false - run_as_user = 10001 - run_as_group = 10001 - run_as_non_root = true - } - volume_mount { - mount_path = "/srv" - name = "home" - sub_path = data.coder_workspace.me.name - } - volume_mount { - mount_path = "/scripts/filebrowser-agent-init.sh" - name = "coder-scripts" - sub_path = "filebrowser-agent-init.sh" - read_only = true - } - volume_mount { - mount_path = "/config/filebrowser.yaml" - name = "coder-scripts" - sub_path = "filebrowser.yaml" - read_only = true - } - volume_mount { - mount_path = "/home/filebrowser/data" - name = "filebrowser-data" - } - } enable_service_links = false hostname = local.sanitized_workspace_name node_selector = { @@ -246,10 +168,6 @@ resource "kubernetes_deployment_v1" "deployment" { default_mode = "0750" } } - volume { - name = "filebrowser-data" - empty_dir {} - } # /tmp is scratch space (agent/tool tempfiles, build caches, downloaded # archives) and needs to be fast - it cannot be the NFS-backed "home" # PVC, and it cannot be an empty_dir either, because empty_dir lives on diff --git a/templates/kubernetes/homelab-workspace/filebrowser.tf b/templates/kubernetes/homelab-workspace/filebrowser.tf deleted file mode 100644 index 14b87891..00000000 --- a/templates/kubernetes/homelab-workspace/filebrowser.tf +++ /dev/null @@ -1,36 +0,0 @@ -resource "coder_agent" "filebrowser" { - arch = "amd64" - os = "linux" - api_key_scope = "no_user_data" - order = 1 - startup_script = "cd /home/filebrowser && ./filebrowser >/tmp/filebrowser.log 2>&1 &" - startup_script_behavior = "non-blocking" - - display_apps { - port_forwarding_helper = false - ssh_helper = false - vscode = false - vscode_insiders = false - web_terminal = false - } -} - -resource "coder_app" "filebrowser" { - agent_id = coder_agent.filebrowser.id - slug = "files" - display_name = "Files" - icon = "/icon/folder.svg" - url = "http://localhost:8080" - share = "owner" - # File Browser emits root-relative URLs and expects its configured base path - # on inbound requests. Coder path apps strip that path before proxying, so an - # isolated app subdomain is the only mode that preserves both contracts. - subdomain = true - open_in = "tab" - - healthcheck { - url = "http://localhost:8080/health" - interval = 5 - threshold = 6 - } -}