docs: restructure docs (#14421)

Closes #13434 
Supersedes #14182

---------

Co-authored-by: Ethan <39577870+ethanndickson@users.noreply.github.com>
Co-authored-by: Ethan Dickson <ethan@coder.com>
Co-authored-by: Ben Potter <ben@coder.com>
Co-authored-by: Stephen Kirby <58410745+stirby@users.noreply.github.com>
Co-authored-by: Stephen Kirby <me@skirby.dev>
Co-authored-by: EdwardAngert <17991901+EdwardAngert@users.noreply.github.com>
Co-authored-by: Edward Angert <EdwardAngert@users.noreply.github.com>
This commit is contained in:
Muhammad Atif Ali
2024-10-05 10:52:04 -05:00
committed by GitHub
co-authored by Ethan Ethan Dickson Ben Potter Stephen Kirby Stephen Kirby EdwardAngert Edward Angert
parent 288df75686
commit 419eba5fb6
298 changed files with 5009 additions and 3889 deletions
@@ -0,0 +1,302 @@
# Notifications
Notifications are sent by Coder in response to specific internal events, such as
a workspace being deleted or a user being created.
## Enable experiment
In order to activate the notifications feature on Coder v2.15.X, you'll need to
enable the `notifications` experiment. Notifications are enabled by default
starting in v2.16.0.
```bash
# Using the CLI flag
$ coder server --experiments=notifications
# Alternatively, using the `CODER_EXPERIMENTS` environment variable
$ CODER_EXPERIMENTS=notifications coder server
```
More information on experiments can be found
[here](https://coder.com/docs/contributing/feature-stages#experimental-features).
## Event Types
Notifications are sent in response to internal events, to alert the affected
user(s) of this event. Currently we support the following list of events:
### Workspace Events
_These notifications are sent to the workspace owner._
- Workspace Deleted
- Workspace Manual Build Failure
- Workspace Automatic Build Failure
- Workspace Automatically Updated
- Workspace Dormant
- Workspace Marked For Deletion
### User Events
_These notifications are sent to users with **owner** and **user admin** roles._
- User Account Created
- User Account Deleted
- User Account Suspended
- User Account Activated
- _(coming soon) User Password Reset_
- _(coming soon) User Email Verification_
_These notifications are sent to the user themselves._
- User Account Suspended
- User Account Activated
### Template Events
_These notifications are sent to users with **template admin** roles._
- Template Deleted
## Configuration
You can modify the notification delivery behavior using the following server
flags.
| Required | CLI | Env | Type | Description | Default |
| :------: | ----------------------------------- | --------------------------------------- | ---------- | --------------------------------------------------------------------------------------------------------------------- | ------- |
| ✔️ | `--notifications-dispatch-timeout` | `CODER_NOTIFICATIONS_DISPATCH_TIMEOUT` | `duration` | How long to wait while a notification is being sent before giving up. | 1m |
| ✔️ | `--notifications-method` | `CODER_NOTIFICATIONS_METHOD` | `string` | Which delivery method to use (available options: 'smtp', 'webhook'). See [Delivery Methods](#delivery-methods) below. | smtp |
| -️ | `--notifications-max-send-attempts` | `CODER_NOTIFICATIONS_MAX_SEND_ATTEMPTS` | `int` | The upper limit of attempts to send a notification. | 5 |
## Delivery Methods
Notifications can currently be delivered by either SMTP or webhook. Each message
can only be delivered to one method, and this method is configured globally with
[`CODER_NOTIFICATIONS_METHOD`](../../../reference/cli/server.md#--notifications-method)
(default: `smtp`).
Enterprise customers can configure which method to use for each of the supported
[Events](#events); see the [Preferences](#preferences) section below for more
details.
## SMTP (Email)
Use the `smtp` method to deliver notifications by email to your users. Coder
does not ship with an SMTP server, so you will need to configure Coder to use an
existing one.
**Server Settings:**
| Required | CLI | Env | Type | Description | Default |
| :------: | --------------------------------- | ------------------------------------- | ----------- | ----------------------------------------- | ------------- |
| ✔️ | `--notifications-email-from` | `CODER_NOTIFICATIONS_EMAIL_FROM` | `string` | The sender's address to use. | |
| ✔️ | `--notifications-email-smarthost` | `CODER_NOTIFICATIONS_EMAIL_SMARTHOST` | `host:port` | The SMTP relay to send messages through. | localhost:587 |
| ✔️ | `--notifications-email-hello` | `CODER_NOTIFICATIONS_EMAIL_HELLO` | `string` | The hostname identifying the SMTP server. | localhost |
**Authentication Settings:**
| Required | CLI | Env | Type | Description |
| :------: | ------------------------------------------ | ---------------------------------------------- | -------- | ------------------------------------------------------------------------- |
| - | `--notifications-email-auth-username` | `CODER_NOTIFICATIONS_EMAIL_AUTH_USERNAME` | `string` | Username to use with PLAIN/LOGIN authentication. |
| - | `--notifications-email-auth-password` | `CODER_NOTIFICATIONS_EMAIL_AUTH_PASSWORD` | `string` | Password to use with PLAIN/LOGIN authentication. |
| - | `--notifications-email-auth-password-file` | `CODER_NOTIFICATIONS_EMAIL_AUTH_PASSWORD_FILE` | `string` | File from which to load password for use with PLAIN/LOGIN authentication. |
| - | `--notifications-email-auth-identity` | `CODER_NOTIFICATIONS_EMAIL_AUTH_IDENTITY` | `string` | Identity to use with PLAIN authentication. |
**TLS Settings:**
| Required | CLI | Env | Type | Description | Default |
| :------: | ----------------------------------------- | ------------------------------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
| - | `--notifications-email-force-tls` | `CODER_NOTIFICATIONS_EMAIL_FORCE_TLS` | `bool` | Force a TLS connection to the configured SMTP smarthost. If port 465 is used, TLS will be forced. See https://datatracker.ietf.org/doc/html/rfc8314#section-3.3. | false |
| - | `--notifications-email-tls-starttls` | `CODER_NOTIFICATIONS_EMAIL_TLS_STARTTLS` | `bool` | Enable STARTTLS to upgrade insecure SMTP connections using TLS. Ignored if `CODER_NOTIFICATIONS_EMAIL_FORCE_TLS` is set. | false |
| - | `--notifications-email-tls-skip-verify` | `CODER_NOTIFICATIONS_EMAIL_TLS_SKIPVERIFY` | `bool` | Skip verification of the target server's certificate (**insecure**). | false |
| - | `--notifications-email-tls-server-name` | `CODER_NOTIFICATIONS_EMAIL_TLS_SERVERNAME` | `string` | Server name to verify against the target certificate. | |
| - | `--notifications-email-tls-cert-file` | `CODER_NOTIFICATIONS_EMAIL_TLS_CERTFILE` | `string` | Certificate file to use. | |
| - | `--notifications-email-tls-cert-key-file` | `CODER_NOTIFICATIONS_EMAIL_TLS_CERTKEYFILE` | `string` | Certificate key file to use. | |
**NOTE:** you _MUST_ use `CODER_NOTIFICATIONS_EMAIL_FORCE_TLS` if your smarthost
supports TLS on a port other than `465`.
### Send emails using G-Suite
After setting the required fields above:
1. Create an [App Password](https://myaccount.google.com/apppasswords) using the
account you wish to send from
2. Set the following configuration options:
```
CODER_NOTIFICATIONS_EMAIL_SMARTHOST=smtp.gmail.com:465
CODER_NOTIFICATIONS_EMAIL_AUTH_USERNAME=<user>@<domain>
CODER_NOTIFICATIONS_EMAIL_AUTH_PASSWORD="<app password created above>"
```
See
[this help article from Google](https://support.google.com/a/answer/176600?hl=en)
for more options.
### Send emails using Outlook.com
After setting the required fields above:
1. Setup an account on Microsoft 365 or outlook.com
2. Set the following configuration options:
```
CODER_NOTIFICATIONS_EMAIL_SMARTHOST=smtp-mail.outlook.com:587
CODER_NOTIFICATIONS_EMAIL_TLS_STARTTLS=true
CODER_NOTIFICATIONS_EMAIL_AUTH_USERNAME=<user>@<domain>
CODER_NOTIFICATIONS_EMAIL_AUTH_PASSWORD="<account password>"
```
See
[this help article from Microsoft](https://support.microsoft.com/en-us/office/pop-imap-and-smtp-settings-for-outlook-com-d088b986-291d-42b8-9564-9c414e2aa040)
for more options.
## Webhook
The webhook delivery method sends an HTTP POST request to the defined endpoint.
The purpose of webhook notifications is to enable integrations with other
systems.
**Settings**:
| Required | CLI | Env | Type | Description |
| :------: | ---------------------------------- | -------------------------------------- | ----- | --------------------------------------- |
| ✔️ | `--notifications-webhook-endpoint` | `CODER_NOTIFICATIONS_WEBHOOK_ENDPOINT` | `url` | The endpoint to which to send webhooks. |
Here is an example payload for Coder's webhook notification:
```json
{
"_version": "1.0",
"msg_id": "88750cad-77d4-4663-8bc0-f46855f5019b",
"payload": {
"_version": "1.0",
"notification_name": "Workspace Deleted",
"user_id": "4ac34fcb-8155-44d5-8301-e3cd46e88b35",
"user_email": "danny@coder.com",
"user_name": "danny",
"user_username": "danny",
"actions": [
{
"label": "View workspaces",
"url": "https://et23ntkhpueak.pit-1.try.coder.app/workspaces"
},
{
"label": "View templates",
"url": "https://et23ntkhpueak.pit-1.try.coder.app/templates"
}
],
"labels": {
"initiator": "danny",
"name": "my-workspace",
"reason": "initiated by user"
}
},
"title": "Workspace \"my-workspace\" deleted",
"body": "Hi danny\n\nYour workspace my-workspace was deleted.\nThe specified reason was \"initiated by user (danny)\"."
}
```
The top-level object has these keys:
- `_version`: describes the version of this schema; follows semantic versioning
- `msg_id`: the UUID of the notification (matches the ID in the
`notification_messages` table)
- `payload`: contains the specific details of the notification; described below
- `title`: the title of the notification message (equivalent to a subject in
SMTP delivery)
- `body`: the body of the notification message (equivalent to the message body
in SMTP delivery)
The `payload` object has these keys:
- `_version`: describes the version of this inner schema; follows semantic
versioning
- `notification_name`: name of the event which triggered the notification
- `user_id`: Coder internal user identifier of the target user (UUID)
- `user_email`: email address of the target user
- `user_name`: name of the target user
- `user_username`: username of the target user
- `actions`: a list of CTAs (Call-To-Action); these are mainly relevant for SMTP
delivery in which they're shown as buttons
- `labels`: dynamic map of zero or more string key-value pairs; these vary from
event to event
## User Preferences
All users have the option to opt-out of any notifications. Go to **Account** ->
**Notifications** to turn notifications on or off. The delivery method for each
notification is indicated on the right hand side of this table.
![User Notification Preferences](../../../images/admin/monitoring/notifications/user-notification-preferences.png)
## Delivery Preferences (enterprise) (premium)
Administrators can configure which delivery methods are used for each different
[event type](#event-types).
![preferences](../../../images/admin/monitoring/notifications/notification-admin-prefs.png)
You can find this page under
`https://$CODER_ACCESS_URL/deployment/notifications?tab=events`.
## Stop sending notifications
Administrators may wish to stop _all_ notifications across the deployment. We
support a killswitch in the CLI for these cases.
To pause sending notifications, execute
[`coder notifications pause`](../../../reference/cli/notifications_pause.md).
To resume sending notifications, execute
[`coder notifications resume`](../../../reference/cli/notifications_resume.md).
## Troubleshooting
If notifications are not being delivered, use the following methods to
troubleshoot:
1. Ensure notifications are being added to the `notification_messages` table
2. Review any error messages in the `status_reason` column, should an error have
occurred
3. Review the logs (search for the term `notifications`) for diagnostic
information<br> _If you do not see any relevant logs, set
`CODER_VERBOSE=true` or `--verbose` to output debug logs_
## Internals
The notification system is built to operate concurrently in a single- or
multi-replica Coder deployment, and has a built-in retry mechanism. It uses the
configured Postgres database to store notifications in a queue and facilitate
concurrency.
All messages are stored in the `notification_messages` table.
Messages older than 7 days are deleted.
### Message States
![states](../../../images/admin/monitoring/notifications/notification-states.png)
_A notifier here refers to a Coder replica which is responsible for dispatching
the notification. All running replicas act as notifiers to process pending
messages._
- a message begins in `pending` state
- transitions to `leased` when a Coder replica acquires new messages from the
database
- new messages are checked for every `CODER_NOTIFICATIONS_FETCH_INTERVAL`
(default: 15s)
- if a message is delivered successfully, it transitions to `sent` state
- if a message encounters a non-retryable error (e.g. misconfiguration), it
transitions to `permanent_failure`
- if a message encounters a retryable error (e.g. temporary server outage), it
transitions to `temporary_failure`
- this message will be retried up to `CODER_NOTIFICATIONS_MAX_SEND_ATTEMPTS`
(default: 5)
- this message will transition back to `pending` state after
`CODER_NOTIFICATIONS_RETRY_INTERVAL` (default: 5m) and be retried
- after `CODER_NOTIFICATIONS_MAX_SEND_ATTEMPTS` is exceeded, it transitions to
`permanent_failure`
See [Troubleshooting](#troubleshooting) above for more details.
@@ -0,0 +1,206 @@
# Slack Notifications
[Slack](https://slack.com/) is a popular messaging platform designed for teams
and businesses, enabling real-time collaboration through channels, direct
messages, and integrations with external tools. With Coder's integration, you
can enable automated notifications directly within a self-hosted
[Slack app](https://api.slack.com/apps), keeping your team updated on key events
in your Coder environment.
Administrators can configure Coder to send notifications via an incoming webhook
endpoint. These notifications will be delivered as Slack messages direct to the
user. Routing is based on the user's email address, and this should be
consistent between Slack and their Coder login.
## Requirements
Before setting up Slack notifications, ensure that you have the following:
- Administrator access to the Slack platform to create apps
- Coder platform v2.15.0 or greater with
[notifications enabled](./index.md#enable-experiment) for versions <v2.16.0
## Create Slack Application
To integrate Slack with Coder, follow these steps to create a Slack application:
1. Go to the [Slack Apps](https://api.slack.com/apps) dashboard and create a new
Slack App.
2. Under "Basic Information," you'll find a "Signing Secret." The Slack
application uses it to
[verify requests](https://api.slack.com/authentication/verifying-requests-from-slack)
coming from Slack.
3. Under "OAuth & Permissions", add the following OAuth scopes:
- `chat:write`: To send messages as the app.
- `users:read`: To find the user details.
- `users:read.email`: To find user emails.
4. Install the app to your workspace and note down the **Bot User OAuth Token**
from the "OAuth & Permissions" section.
## Build a Webserver to Receive Webhooks
The Slack bot for Coder runs as a _Bolt application_, which is a framework
designed for building Slack apps using the Slack API.
[Bolt for JavaScript](https://github.com/slackapi/bolt-js) provides an
easy-to-use API for responding to events, commands, and interactions from Slack.
To build the server to receive webhooks and interact with Slack:
1. Initialize your project by running:
```bash
npm init -y
```
2. Install the Bolt library:
```bash
npm install @slack/bolt
```
3. Create and edit the `app.js` file. Below is an example of the basic
structure:
```js
const { App, LogLevel, ExpressReceiver } = require("@slack/bolt");
const bodyParser = require("body-parser");
const port = process.env.PORT || 6000;
// Create a Bolt Receiver
const receiver = new ExpressReceiver({
signingSecret: process.env.SLACK_SIGNING_SECRET,
});
receiver.router.use(bodyParser.json());
// Create the Bolt App, using the receiver
const app = new App({
token: process.env.SLACK_BOT_TOKEN,
logLevel: LogLevel.DEBUG,
receiver,
});
receiver.router.post("/v1/webhook", async (req, res) => {
try {
if (!req.body) {
return res.status(400).send("Error: request body is missing");
}
const { title, body } = req.body;
if (!title || !body) {
return res.status(400).send('Error: missing fields: "title", or "body"');
}
const payload = req.body.payload;
if (!payload) {
return res.status(400).send('Error: missing "payload" field');
}
const { user_email, actions } = payload;
if (!user_email || !actions) {
return res
.status(400)
.send('Error: missing fields: "user_email", "actions"');
}
// Get the user ID using Slack API
const userByEmail = await app.client.users.lookupByEmail({
email: user_email,
});
const slackMessage = {
channel: userByEmail.user.id,
text: body,
blocks: [
{
type: "header",
text: { type: "plain_text", text: title },
},
{
type: "section",
text: { type: "mrkdwn", text: body },
},
],
};
// Add action buttons if they exist
if (actions && actions.length > 0) {
slackMessage.blocks.push({
type: "actions",
elements: actions.map((action) => ({
type: "button",
text: { type: "plain_text", text: action.label },
url: action.url,
})),
});
}
// Post message to the user on Slack
await app.client.chat.postMessage(slackMessage);
res.status(204).send();
} catch (error) {
console.error("Error sending message:", error);
res.status(500).send();
}
});
// Acknowledge clicks on link_button, otherwise Slack UI
// complains about missing events.
app.action("button_click", async ({ body, ack, say }) => {
await ack(); // no specific action needed
});
// Start the Bolt app
(async () => {
await app.start(port);
console.log("⚡️ Coder Slack bot is running!");
})();
```
3. Set environment variables to identify the Slack app:
```bash
export SLACK_BOT_TOKEN=xoxb-...
export SLACK_SIGNING_SECRET=0da4b...
```
4. Start the web application by running:
```bash
node app.js
```
## Enable Interactivity in Slack
Slack requires the bot to acknowledge when a user clicks on a URL action button.
This is handled by setting up interactivity.
1. Under "Interactivity & Shortcuts" in your Slack app settings, set the Request
URL to match the public URL of your web server's endpoint.
> Notice: You can use any public endpoint that accepts and responds to POST
> requests with HTTP 200. For temporary testing, you can set it to
> `https://httpbin.org/status/200`.
Once this is set, Slack will send interaction payloads to your server, which
must respond appropriately.
## Enable Webhook Integration in Coder
To enable webhook integration in Coder, ensure the "notifications"
[experiment is activated](./index.md#enable-experiment) (only required in
v2.15.X).
Then, define the POST webhook endpoint matching the deployed Slack bot:
```bash
export CODER_NOTIFICATIONS_WEBHOOK_ENDPOINT=http://localhost:6000/v1/webhook`
```
Finally, go to the **Notification Settings** in Coder and switch the notifier to
**Webhook**.
@@ -0,0 +1,157 @@
# Microsoft Teams Notifications
[Microsoft Teams](https://www.microsoft.com/en-us/microsoft-teams) is a widely
used collaboration platform, and with Coder's integration, you can enable
automated notifications directly within Teams using workflows and
[Adaptive Cards](https://adaptivecards.io/)
Administrators can configure Coder to send notifications via an incoming webhook
endpoint. These notifications appear as messages in Teams chats, either with the
Flow Bot or a specified user/service account.
## Requirements
Before setting up Microsoft Teams notifications, ensure that you have the
following:
- Administrator access to the Teams platform
- Coder platform with [notifications enabled](./index.md#enable-experiment)
## Build Teams Workflow
The process of setting up a Teams workflow consists of three key steps:
1. Configure the Webhook Trigger.
Begin by configuring the trigger: **"When a Teams webhook request is
received"**.
Ensure the trigger access level is set to **"Anyone"**.
2. Setup the JSON Parsing Action.
Next, add the **"Parse JSON"** action, linking the content to the **"Body"**
of the received webhook request. Use the following schema to parse the
notification payload:
```json
{
"type": "object",
"properties": {
"_version": {
"type": "string"
},
"payload": {
"type": "object",
"properties": {
"_version": {
"type": "string"
},
"user_email": {
"type": "string"
},
"actions": {
"type": "array",
"items": {
"type": "object",
"properties": {
"label": {
"type": "string"
},
"url": {
"type": "string"
}
},
"required": ["label", "url"]
}
}
}
},
"title": {
"type": "string"
},
"body": {
"type": "string"
}
}
}
```
This action parses the notification's title, body, and the recipient's email
address.
3. Configure the Adaptive Card Action.
Finally, set up the **"Post Adaptive Card in a chat or channel"** action
with the following recommended settings:
**Post as**: Flow Bot
**Post in**: Chat with Flow Bot
**Recipient**: `user_email`
Use the following _Adaptive Card_ template:
```json
{
"$schema": "https://adaptivecards.io/schemas/adaptive-card.json",
"type": "AdaptiveCard",
"version": "1.0",
"body": [
{
"type": "Image",
"url": "https://coder.com/coder-logo-horizontal.png",
"height": "40px",
"altText": "Coder",
"horizontalAlignment": "center"
},
{
"type": "TextBlock",
"text": "**@{replace(body('Parse_JSON')?['title'], '"', '\"')}**"
},
{
"type": "TextBlock",
"text": "@{replace(body('Parse_JSON')?['body'], '"', '\"')}",
"wrap": true
},
{
"type": "ActionSet",
"actions": [@{replace(replace(join(body('Parse_JSON')?['payload']?['actions'], ','), '{', '{"type": "Action.OpenUrl",'), '"label"', '"title"')}]
}
]
}
```
_Notice_: The Coder `actions` format differs from the `ActionSet` schema, so
its properties need to be modified: include `Action.OpenUrl` type, rename
`label` to `title`. Unfortunately, there is no straightforward solution for
`for-each` pattern.
Feel free to customize the payload to modify the logo, notification title,
or body content to suit your needs.
## Enable Webhook Integration
To enable webhook integration in Coder, ensure the "notifications"
[experiment is activated](./index.md#enable-experiment) (only required in
v2.15.X).
Then, define the POST webhook endpoint created by your Teams workflow:
```bash
export CODER_NOTIFICATIONS_WEBHOOK_ENDPOINT=https://prod-16.eastus.logic.azure.com:443/workflows/f8fbe3e8211e4b638...`
```
Finally, go to the **Notification Settings** in Coder and switch the notifier to
**Webhook**.
## Limitations
1. **Public Webhook Trigger**: The Teams webhook trigger must be open to the
public (**"Anyone"** can send the payload). It's recommended to keep the
endpoint secret and apply additional authorization layers to protect against
unauthorized access.
2. **Markdown Support in Adaptive Cards**: Note that Adaptive Cards support a
[limited set of Markdown tags](https://learn.microsoft.com/en-us/microsoftteams/platform/task-modules-and-cards/cards/cards-format?tabs=adaptive-md%2Cdesktop%2Cconnector-html).