Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 0 additions & 52 deletions .github/workflows/test-template.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -178,51 +178,6 @@ jobs:
# this otherwise unrelated readiness check ambiguous.
run: coder ping --num 3 --timeout 30s "${WORKSPACE_NAME}.main"

- name: Confirm File Browser sidecar and Coder app
shell: bash
run: |
deployment_name="$(kubectl --namespace coder get deployment \
--selector "com.coder.workspace.name=${WORKSPACE_NAME}" \
--output jsonpath='{.items[0].metadata.name}')"
session_token="$(<"${HOME}/.config/coderv2/session")"

# The second agent is the sidecar's PID 1. Prove Coder can route to it
# before probing the process and application that it owns.
coder ping --num 3 --timeout 30s "${WORKSPACE_NAME}.filebrowser"

kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \
sh -c 'tr "\0" " " </proc/1/cmdline | grep -q "coder.*agent"'
kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \
curl --fail --silent --show-error http://localhost:8080/health

# Both containers see the same workspace subpath of whichever home PVC
# the template selected, and the sidecar identity can modify it.
printf workspace | coder ssh "${WORKSPACE_NAME}.main" -- \
tee /home/coder/.filebrowser-sidecar-test >/dev/null
# Expand the command substitution inside the sidecar, not on the runner.
# shellcheck disable=SC2016
kubectl --namespace coder exec "deployment/${deployment_name}" --container filebrowser -- \
sh -c 'test "$(cat /srv/.filebrowser-sidecar-test)" = workspace && printf sidecar > /srv/.filebrowser-sidecar-test'
[[ "$(coder ssh "${WORKSPACE_NAME}.main" -- cat /home/coder/.filebrowser-sidecar-test)" == "sidecar" ]]

# File Browser requires the subdomain proxy because its root-relative
# assets cannot survive Coder's path-prefix stripping. Exercise both the
# configured home source and frontend through that proxy, not only the
# Pod-local listener.
app_url="http://files--${WORKSPACE_NAME}--ci.localhost:7080"
served_marker="$(curl --fail --silent --show-error \
--header "Coder-Session-Token: ${session_token}" \
"${app_url}/api/resources/download?source=srv&file=/.filebrowser-sidecar-test")"
[[ "${served_marker}" == "sidecar" ]]
app_html="$(curl --fail --silent --show-error \
--header "Coder-Session-Token: ${session_token}" "${app_url}/")"
grep --quiet '<title>' <<<"${app_html}"
asset_path="$(grep --only-matching --max-count=1 '/public/static/[^"]*' <<<"${app_html}")"
[[ -n "${asset_path}" ]]
curl --fail --silent --show-error \
--header "Coder-Session-Token: ${session_token}" \
--output /dev/null "${app_url}${asset_path}"

- name: Run command over workspace SSH
shell: bash
run: |
Expand Down Expand Up @@ -378,11 +333,4 @@ jobs:
kubectl --namespace coder logs \
--selector "com.coder.workspace.name=${WORKSPACE_NAME}" \
--all-containers --prefix --tail=200 || true
pod_name="$(kubectl --namespace coder get pods \
--selector "com.coder.workspace.name=${WORKSPACE_NAME}" \
--output jsonpath='{.items[0].metadata.name}')"
kubectl --namespace coder exec "pod/${pod_name}" --container filebrowser -- \
cat /tmp/coder-startup-script.log || true
kubectl --namespace coder exec "pod/${pod_name}" --container filebrowser -- \
cat /tmp/filebrowser.log || true
docker compose -f "${COMPOSE_FILE}" logs
32 changes: 0 additions & 32 deletions templates/kubernetes/homelab-workspace/config/filebrowser.yaml

This file was deleted.

2 changes: 0 additions & 2 deletions templates/kubernetes/homelab-workspace/configmap.tf
Original file line number Diff line number Diff line change
Expand Up @@ -18,8 +18,6 @@ resource "kubernetes_config_map_v1" "workspace_scripts" {
"script-start-services.sh" = file("${path.cwd}/scripts/script-start-services.sh")
"supervisord.conf" = file("${path.cwd}/config/supervisord.conf")
"script-vscode-server-gc.sh" = file("${path.cwd}/scripts/script-vscode-server-gc.sh")
"filebrowser-agent-init.sh" = coder_agent.filebrowser.init_script
"filebrowser.yaml" = file("${path.cwd}/config/filebrowser.yaml")
"workspace-init.sh" = coder_agent.main.init_script
}
}
82 changes: 0 additions & 82 deletions templates/kubernetes/homelab-workspace/deployment.tf
Original file line number Diff line number Diff line change
Expand Up @@ -141,84 +141,6 @@ resource "kubernetes_deployment_v1" "deployment" {
name = "tmp"
}
}
container {
name = "filebrowser"
command = ["/bin/sh", "/scripts/filebrowser-agent-init.sh"]
image = "gtstef/filebrowser:1.5.6-stable@sha256:7c5d7ac8ffda31294d278063cf9d2e04303b39e6dce1f4c691342240ca7703b8"
env {
name = "CODER_AGENT_TOKEN"
value = coder_agent.filebrowser.token
}
env {
name = "FILEBROWSER_CONFIG"
value = "/config/filebrowser.yaml"
}
env {
name = "HOME"
value = "/home/filebrowser/data"
}
env {
name = "USER"
# The image's filebrowser account uses /bin/true. The agent uses
# this account only to select a shell; the Pod still enforces the
# non-root UID below.
value = "root"
}
port {
container_port = 8080
name = "filebrowser"
protocol = "TCP"
}
liveness_probe {
http_get {
path = "/health"
port = 8080
scheme = "HTTP"
}
initial_delay_seconds = 15
period_seconds = 30
timeout_seconds = 3
failure_threshold = 3
}
resources {
requests = {
"cpu" = "25m"
"memory" = "128Mi"
}
limits = {
"memory" = "256Mi"
}
}
security_context {
allow_privilege_escalation = false
read_only_root_filesystem = false
privileged = false
run_as_user = 10001
run_as_group = 10001
run_as_non_root = true
}
volume_mount {
mount_path = "/srv"
name = "home"
sub_path = data.coder_workspace.me.name
}
volume_mount {
mount_path = "/scripts/filebrowser-agent-init.sh"
name = "coder-scripts"
sub_path = "filebrowser-agent-init.sh"
read_only = true
}
volume_mount {
mount_path = "/config/filebrowser.yaml"
name = "coder-scripts"
sub_path = "filebrowser.yaml"
read_only = true
}
volume_mount {
mount_path = "/home/filebrowser/data"
name = "filebrowser-data"
}
}
enable_service_links = false
hostname = local.sanitized_workspace_name
node_selector = {
Expand Down Expand Up @@ -246,10 +168,6 @@ resource "kubernetes_deployment_v1" "deployment" {
default_mode = "0750"
}
}
volume {
name = "filebrowser-data"
empty_dir {}
}
# /tmp is scratch space (agent/tool tempfiles, build caches, downloaded
# archives) and needs to be fast - it cannot be the NFS-backed "home"
# PVC, and it cannot be an empty_dir either, because empty_dir lives on
Expand Down
36 changes: 0 additions & 36 deletions templates/kubernetes/homelab-workspace/filebrowser.tf

This file was deleted.

Loading