diff --git a/.github/workflows/test-template.yaml b/.github/workflows/test-template.yaml
index 8eb8ceda..53ec7d3a 100644
--- a/.github/workflows/test-template.yaml
+++ b/.github/workflows/test-template.yaml
@@ -178,51 +178,6 @@ jobs:
# this otherwise unrelated readiness check ambiguous.
run: coder ping --num 3 --timeout 30s "${WORKSPACE_NAME}.main"
- - name: Confirm File Browser sidecar and Coder app
- shell: bash
- run: |
- deployment_name="$(kubectl --namespace coder get deployment \
- --selector "com.coder.workspace.name=${WORKSPACE_NAME}" \
- --output jsonpath='{.items[0].metadata.name}')"
- session_token="$(<"${HOME}/.config/coderv2/session")"
-
- # The second agent is the sidecar's PID 1. Prove Coder can route to it
- # before probing the process and application that it owns.
- coder ping --num 3 --timeout 30s "${WORKSPACE_NAME}.filebrowser"
-
- kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \
- sh -c 'tr "\0" " " /dev/null
- # Expand the command substitution inside the sidecar, not on the runner.
- # shellcheck disable=SC2016
- kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \
- sh -c 'test "$(cat /srv/.filebrowser-sidecar-test)" = workspace && printf sidecar > /srv/.filebrowser-sidecar-test'
- [[ "$(coder ssh "${WORKSPACE_NAME}.main" -- cat /home/coder/.filebrowser-sidecar-test)" == "sidecar" ]]
-
- # File Browser requires the subdomain proxy because its root-relative
- # assets cannot survive Coder's path-prefix stripping. Exercise both the
- # configured home source and frontend through that proxy, not only the
- # Pod-local listener.
- app_url="http://files--${WORKSPACE_NAME}--ci.localhost:7080"
- served_marker="$(curl --fail --silent --show-error \
- --header "Coder-Session-Token: ${session_token}" \
- "${app_url}/api/resources/download?source=srv&file=/.filebrowser-sidecar-test")"
- [[ "${served_marker}" == "sidecar" ]]
- app_html="$(curl --fail --silent --show-error \
- --header "Coder-Session-Token: ${session_token}" "${app_url}/")"
- grep --quiet '
' <<<"${app_html}"
- asset_path="$(grep --only-matching --max-count=1 '/public/static/[^"]*' <<<"${app_html}")"
- [[ -n "${asset_path}" ]]
- curl --fail --silent --show-error \
- --header "Coder-Session-Token: ${session_token}" \
- --output /dev/null "${app_url}${asset_path}"
-
- name: Run command over workspace SSH
shell: bash
run: |
@@ -378,11 +333,4 @@ jobs:
kubectl --namespace coder logs \
--selector "com.coder.workspace.name=${WORKSPACE_NAME}" \
--all-containers --prefix --tail=200 || true
- pod_name="$(kubectl --namespace coder get pods \
- --selector "com.coder.workspace.name=${WORKSPACE_NAME}" \
- --output jsonpath='{.items[0].metadata.name}')"
- kubectl --namespace coder exec "pod/${pod_name}" --container filebrowser -- \
- cat /tmp/coder-startup-script.log || true
- kubectl --namespace coder exec "pod/${pod_name}" --container filebrowser -- \
- cat /tmp/filebrowser.log || true
docker compose -f "${COMPOSE_FILE}" logs
diff --git a/templates/kubernetes/homelab-workspace/config/filebrowser.yaml b/templates/kubernetes/homelab-workspace/config/filebrowser.yaml
deleted file mode 100644
index 7021e90e..00000000
--- a/templates/kubernetes/homelab-workspace/config/filebrowser.yaml
+++ /dev/null
@@ -1,32 +0,0 @@
----
-server:
- port: 8080
- baseURL: "/"
- cacheDir: "/home/filebrowser/data/tmp"
- logging:
- - levels: "info|warning|error"
- sources:
- - path: "/srv"
-
-# Coder's owner-only application proxy is the authentication boundary. The
-# sidecar has no Service and File Browser is not reachable outside the Pod.
-auth:
- methods:
- noauth: true
-
-frontend:
- name: "Workspace Files"
- disableDefaultLinks: true
-
-userDefaults:
- listing:
- showHidden: true
- account:
- permissions:
- admin: false
- api: false
- create: true
- delete: true
- download: true
- modify: true
- share: false
diff --git a/templates/kubernetes/homelab-workspace/configmap.tf b/templates/kubernetes/homelab-workspace/configmap.tf
index 80ad63f4..7ff01ef1 100644
--- a/templates/kubernetes/homelab-workspace/configmap.tf
+++ b/templates/kubernetes/homelab-workspace/configmap.tf
@@ -18,8 +18,6 @@ resource "kubernetes_config_map_v1" "workspace_scripts" {
"script-start-services.sh" = file("${path.cwd}/scripts/script-start-services.sh")
"supervisord.conf" = file("${path.cwd}/config/supervisord.conf")
"script-vscode-server-gc.sh" = file("${path.cwd}/scripts/script-vscode-server-gc.sh")
- "filebrowser-agent-init.sh" = coder_agent.filebrowser.init_script
- "filebrowser.yaml" = file("${path.cwd}/config/filebrowser.yaml")
"workspace-init.sh" = coder_agent.main.init_script
}
}
diff --git a/templates/kubernetes/homelab-workspace/deployment.tf b/templates/kubernetes/homelab-workspace/deployment.tf
index 5887b8da..708b2f97 100644
--- a/templates/kubernetes/homelab-workspace/deployment.tf
+++ b/templates/kubernetes/homelab-workspace/deployment.tf
@@ -141,84 +141,6 @@ resource "kubernetes_deployment_v1" "deployment" {
name = "tmp"
}
}
- container {
- name = "filebrowser"
- command = ["/bin/sh", "/scripts/filebrowser-agent-init.sh"]
- image = "gtstef/filebrowser:1.5.6-stable@sha256:7c5d7ac8ffda31294d278063cf9d2e04303b39e6dce1f4c691342240ca7703b8"
- env {
- name = "CODER_AGENT_TOKEN"
- value = coder_agent.filebrowser.token
- }
- env {
- name = "FILEBROWSER_CONFIG"
- value = "/config/filebrowser.yaml"
- }
- env {
- name = "HOME"
- value = "/home/filebrowser/data"
- }
- env {
- name = "USER"
- # The image's filebrowser account uses /bin/true. The agent uses
- # this account only to select a shell; the Pod still enforces the
- # non-root UID below.
- value = "root"
- }
- port {
- container_port = 8080
- name = "filebrowser"
- protocol = "TCP"
- }
- liveness_probe {
- http_get {
- path = "/health"
- port = 8080
- scheme = "HTTP"
- }
- initial_delay_seconds = 15
- period_seconds = 30
- timeout_seconds = 3
- failure_threshold = 3
- }
- resources {
- requests = {
- "cpu" = "25m"
- "memory" = "128Mi"
- }
- limits = {
- "memory" = "256Mi"
- }
- }
- security_context {
- allow_privilege_escalation = false
- read_only_root_filesystem = false
- privileged = false
- run_as_user = 10001
- run_as_group = 10001
- run_as_non_root = true
- }
- volume_mount {
- mount_path = "/srv"
- name = "home"
- sub_path = data.coder_workspace.me.name
- }
- volume_mount {
- mount_path = "/scripts/filebrowser-agent-init.sh"
- name = "coder-scripts"
- sub_path = "filebrowser-agent-init.sh"
- read_only = true
- }
- volume_mount {
- mount_path = "/config/filebrowser.yaml"
- name = "coder-scripts"
- sub_path = "filebrowser.yaml"
- read_only = true
- }
- volume_mount {
- mount_path = "/home/filebrowser/data"
- name = "filebrowser-data"
- }
- }
enable_service_links = false
hostname = local.sanitized_workspace_name
node_selector = {
@@ -246,10 +168,6 @@ resource "kubernetes_deployment_v1" "deployment" {
default_mode = "0750"
}
}
- volume {
- name = "filebrowser-data"
- empty_dir {}
- }
# /tmp is scratch space (agent/tool tempfiles, build caches, downloaded
# archives) and needs to be fast - it cannot be the NFS-backed "home"
# PVC, and it cannot be an empty_dir either, because empty_dir lives on
diff --git a/templates/kubernetes/homelab-workspace/filebrowser.tf b/templates/kubernetes/homelab-workspace/filebrowser.tf
deleted file mode 100644
index 14b87891..00000000
--- a/templates/kubernetes/homelab-workspace/filebrowser.tf
+++ /dev/null
@@ -1,36 +0,0 @@
-resource "coder_agent" "filebrowser" {
- arch = "amd64"
- os = "linux"
- api_key_scope = "no_user_data"
- order = 1
- startup_script = "cd /home/filebrowser && ./filebrowser >/tmp/filebrowser.log 2>&1 &"
- startup_script_behavior = "non-blocking"
-
- display_apps {
- port_forwarding_helper = false
- ssh_helper = false
- vscode = false
- vscode_insiders = false
- web_terminal = false
- }
-}
-
-resource "coder_app" "filebrowser" {
- agent_id = coder_agent.filebrowser.id
- slug = "files"
- display_name = "Files"
- icon = "/icon/folder.svg"
- url = "http://localhost:8080"
- share = "owner"
- # File Browser emits root-relative URLs and expects its configured base path
- # on inbound requests. Coder path apps strip that path before proxying, so an
- # isolated app subdomain is the only mode that preserves both contracts.
- subdomain = true
- open_in = "tab"
-
- healthcheck {
- url = "http://localhost:8080/health"
- interval = 5
- threshold = 6
- }
-}