mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: adopt markdownlint and markdown-table-formatter for *.md (#15831)
Co-authored-by: Edward Angert <EdwardAngert@users.noreply.github.com>
This commit is contained in:
co-authored by
Edward Angert
parent
08463c27d8
commit
94f5d52fdc
@@ -49,7 +49,7 @@ GitHub provider).
|
||||

|
||||
|
||||
| Name | Permission | Description |
|
||||
| ------------- | ------------ | ------------------------------------------------------ |
|
||||
|---------------|--------------|--------------------------------------------------------|
|
||||
| Contents | Read & Write | Grants access to code and commit statuses. |
|
||||
| Pull requests | Read & Write | Grants access to create and update pull requests. |
|
||||
| Workflows | Read & Write | Grants access to update files in `.github/workflows/`. |
|
||||
@@ -150,7 +150,7 @@ CODER_EXTERNAL_AUTH_0_AUTH_URL="https://gitea.com/login/oauth/authorize"
|
||||
```
|
||||
|
||||
The Redirect URI for Gitea should be
|
||||
https://coder.company.org/external-auth/gitea/callback
|
||||
`https://coder.company.org/external-auth/gitea/callback`.
|
||||
|
||||
## Self-managed git providers
|
||||
|
||||
|
||||
+6
-6
@@ -17,7 +17,7 @@ For any information not strictly contained in these sections, check out our
|
||||
|
||||
## What is an image, template, dev container, or workspace
|
||||
|
||||
**Image**
|
||||
### Image
|
||||
|
||||
- A [base image](./templates/managing-templates/image-management.md) contains
|
||||
OS-level packages and utilities that the Coder workspace is built on. It can
|
||||
@@ -26,28 +26,28 @@ For any information not strictly contained in these sections, check out our
|
||||
defined in each template.
|
||||
- Managed by: Externally to Coder.
|
||||
|
||||
**Template**
|
||||
### Template
|
||||
|
||||
- [Templates](./templates/index.md) include infrastructure-level dependencies
|
||||
for the workspace. For example, a template can include Kubernetes
|
||||
PersistentVolumeClaims, Docker containers, or EC2 VMs.
|
||||
- Managed by: Template administrators from within the Coder deployment.
|
||||
|
||||
**Startup scripts**
|
||||
### Startup scripts
|
||||
|
||||
- Agent startup scripts apply to all users of a template. This is an
|
||||
intentionally flexible area that template authors have at their disposal to
|
||||
manage the "last mile" of workspace creation.
|
||||
- Managed by: Coder template administrators.
|
||||
|
||||
**Workspace**
|
||||
### Workspace
|
||||
|
||||
- A [workspace](../user-guides/workspace-management.md) is the environment that
|
||||
a developer works in. Developers on a team each work from their own workspace
|
||||
and can use [multiple IDEs](../user-guides/workspace-access/index.md).
|
||||
- Managed by: Developers
|
||||
|
||||
**Development containers (dev containers)**
|
||||
### Development containers (dev containers)
|
||||
|
||||
- A
|
||||
[Development Container](./templates/managing-templates/devcontainers/index.md)
|
||||
@@ -57,7 +57,7 @@ For any information not strictly contained in these sections, check out our
|
||||
will be built on-demand.
|
||||
- Managed by: Dev Teams
|
||||
|
||||
**Dotfiles / personalization**
|
||||
### Dotfiles / personalization
|
||||
|
||||
- Users may have their own specific preferences relating to shell prompt, custom
|
||||
keybindings, color schemes, and more. Users can leverage Coder's
|
||||
|
||||
@@ -40,12 +40,12 @@ Our scale tests include the following stages:
|
||||
The scale tests runner can distribute the workload to overlap single scenarios
|
||||
based on the workflow configuration:
|
||||
|
||||
| | T0 | T1 | T2 | T3 | T4 | T5 | T6 |
|
||||
| -------------------- | --- | --- | --- | --- | --- | --- | --- |
|
||||
| SSH connections | X | X | X | X | | | |
|
||||
| Web Terminal (PTY) | | X | X | X | X | | |
|
||||
| Workspace apps | | | X | X | X | X | |
|
||||
| Dashboard (headless) | | | | X | X | X | X |
|
||||
| | T0 | T1 | T2 | T3 | T4 | T5 | T6 |
|
||||
|----------------------|----|----|----|----|----|----|----|
|
||||
| SSH connections | X | X | X | X | | | |
|
||||
| Web Terminal (PTY) | | X | X | X | X | | |
|
||||
| Workspace apps | | | X | X | X | X | |
|
||||
| Dashboard (headless) | | | | X | X | X | X |
|
||||
|
||||
This pattern closely reflects how our customers naturally use the system. SSH
|
||||
connections are heavily utilized because they're the primary communication
|
||||
@@ -137,7 +137,7 @@ When determining scaling requirements, consider the following factors:
|
||||
connections: For a very high number of proxied connections, more memory is
|
||||
required.
|
||||
|
||||
**HTTP API latency**
|
||||
#### HTTP API latency
|
||||
|
||||
For a reliable Coder deployment dealing with medium to high loads, it's
|
||||
important that API calls for workspace/template queries and workspace build
|
||||
@@ -152,7 +152,7 @@ between users and the load balancer. Fortunately, the latency can be improved
|
||||
with a deployment of Coder
|
||||
[workspace proxies](../networking/workspace-proxies.md).
|
||||
|
||||
**Node Autoscaling**
|
||||
#### Node Autoscaling
|
||||
|
||||
We recommend disabling the autoscaling for `coderd` nodes. Autoscaling can cause
|
||||
interruptions for user connections, see
|
||||
@@ -186,7 +186,7 @@ When determining scaling requirements, consider the following factors:
|
||||
provisioners are free/available, the more concurrent workspace builds can be
|
||||
performed.
|
||||
|
||||
**Node Autoscaling**
|
||||
#### Node Autoscaling
|
||||
|
||||
Autoscaling provisioners is not an easy problem to solve unless it can be
|
||||
predicted when a number of concurrent workspace builds increases.
|
||||
@@ -219,7 +219,7 @@ When determining scaling requirements, consider the following factors:
|
||||
running Coder agent and occasional CPU and memory bursts for building
|
||||
projects.
|
||||
|
||||
**Node Autoscaling**
|
||||
#### Node Autoscaling
|
||||
|
||||
Workspace nodes can be set to operate in autoscaling mode to mitigate the risk
|
||||
of prolonged high resource utilization.
|
||||
|
||||
@@ -17,7 +17,7 @@ Learn more about [Coder’s architecture](./architecture.md) and our
|
||||
> hardware sizing recommendations.
|
||||
|
||||
| Environment | Coder CPU | Coder RAM | Coder Replicas | Database | Users | Concurrent builds | Concurrent connections (Terminal/SSH) | Coder Version | Last tested |
|
||||
| ---------------- | --------- | --------- | -------------- | ----------------- | ----- | ----------------- | ------------------------------------- | ------------- | ------------ |
|
||||
|------------------|-----------|-----------|----------------|-------------------|-------|-------------------|---------------------------------------|---------------|--------------|
|
||||
| Kubernetes (GKE) | 3 cores | 12 GB | 1 | db-f1-micro | 200 | 3 | 200 simulated | `v0.24.1` | Jun 26, 2023 |
|
||||
| Kubernetes (GKE) | 4 cores | 8 GB | 1 | db-custom-1-3840 | 1500 | 20 | 1,500 simulated | `v0.24.1` | Jun 27, 2023 |
|
||||
| Kubernetes (GKE) | 2 cores | 4 GB | 1 | db-custom-1-3840 | 500 | 20 | 500 simulated | `v0.27.2` | Jul 27, 2023 |
|
||||
@@ -48,14 +48,14 @@ specified template and extra parameters.
|
||||
|
||||
```shell
|
||||
coder exp scaletest create-workspaces \
|
||||
--retry 5 \
|
||||
--count "${SCALETEST_PARAM_NUM_WORKSPACES}" \
|
||||
--template "${SCALETEST_PARAM_TEMPLATE}" \
|
||||
--concurrency "${SCALETEST_PARAM_CREATE_CONCURRENCY}" \
|
||||
--timeout 5h \
|
||||
--job-timeout 5h \
|
||||
--no-cleanup \
|
||||
--output json:"${SCALETEST_RESULTS_DIR}/create-workspaces.json"
|
||||
--retry 5 \
|
||||
--count "${SCALETEST_PARAM_NUM_WORKSPACES}" \
|
||||
--template "${SCALETEST_PARAM_TEMPLATE}" \
|
||||
--concurrency "${SCALETEST_PARAM_CREATE_CONCURRENCY}" \
|
||||
--timeout 5h \
|
||||
--job-timeout 5h \
|
||||
--no-cleanup \
|
||||
--output json:"${SCALETEST_RESULTS_DIR}/create-workspaces.json"
|
||||
|
||||
# Run `coder exp scaletest create-workspaces --help` for all usage
|
||||
```
|
||||
@@ -79,14 +79,14 @@ Terminal against those workspaces.
|
||||
```shell
|
||||
# Produce load at about 1000MB/s (25MB/40ms).
|
||||
coder exp scaletest workspace-traffic \
|
||||
--template "${SCALETEST_PARAM_GREEDY_AGENT_TEMPLATE}" \
|
||||
--bytes-per-tick $((1024 * 1024 * 25)) \
|
||||
--tick-interval 40ms \
|
||||
--timeout "$((delay))s" \
|
||||
--job-timeout "$((delay))s" \
|
||||
--scaletest-prometheus-address 0.0.0.0:21113 \
|
||||
--target-workspaces "0:100" \
|
||||
--trace=false \
|
||||
--template "${SCALETEST_PARAM_GREEDY_AGENT_TEMPLATE}" \
|
||||
--bytes-per-tick $((1024 * 1024 * 25)) \
|
||||
--tick-interval 40ms \
|
||||
--timeout "$((delay))s" \
|
||||
--job-timeout "$((delay))s" \
|
||||
--scaletest-prometheus-address 0.0.0.0:21113 \
|
||||
--target-workspaces "0:100" \
|
||||
--trace=false \
|
||||
--output json:"${SCALETEST_RESULTS_DIR}/traffic-${type}-greedy-agent.json"
|
||||
```
|
||||
|
||||
@@ -114,8 +114,8 @@ wish to clean up all workspaces, you can run the following command:
|
||||
|
||||
```shell
|
||||
coder exp scaletest cleanup \
|
||||
--cleanup-job-timeout 2h \
|
||||
--cleanup-timeout 15min
|
||||
--cleanup-job-timeout 2h \
|
||||
--cleanup-timeout 15min
|
||||
```
|
||||
|
||||
This will delete all workspaces and users with the prefix `scaletest-`.
|
||||
@@ -168,7 +168,7 @@ that operators can deploy depending on the traffic projections.
|
||||
There are a few cluster options available:
|
||||
|
||||
| Workspace size | vCPU | Memory | Persisted storage | Details |
|
||||
| -------------- | ---- | ------ | ----------------- | ----------------------------------------------------- |
|
||||
|----------------|------|--------|-------------------|-------------------------------------------------------|
|
||||
| minimal | 1 | 2 Gi | None | |
|
||||
| small | 1 | 1 Gi | None | |
|
||||
| medium | 2 | 2 Gi | None | Medium-sized cluster offers the greedy agent variant. |
|
||||
|
||||
@@ -13,7 +13,7 @@ tech startups, educational units, or small to mid-sized enterprises.
|
||||
### Coderd nodes
|
||||
|
||||
| Users | Node capacity | Replicas | GCP | AWS | Azure |
|
||||
| ----------- | ------------------- | ------------------- | --------------- | ---------- | ----------------- |
|
||||
|-------------|---------------------|---------------------|-----------------|------------|-------------------|
|
||||
| Up to 1,000 | 2 vCPU, 8 GB memory | 1-2 / 1 coderd each | `n1-standard-2` | `t3.large` | `Standard_D2s_v3` |
|
||||
|
||||
**Footnotes**:
|
||||
@@ -24,7 +24,7 @@ tech startups, educational units, or small to mid-sized enterprises.
|
||||
### Provisioner nodes
|
||||
|
||||
| Users | Node capacity | Replicas | GCP | AWS | Azure |
|
||||
| ----------- | -------------------- | ------------------------------ | ---------------- | ------------ | ----------------- |
|
||||
|-------------|----------------------|--------------------------------|------------------|--------------|-------------------|
|
||||
| Up to 1,000 | 8 vCPU, 32 GB memory | 2 nodes / 30 provisioners each | `t2d-standard-8` | `t3.2xlarge` | `Standard_D8s_v3` |
|
||||
|
||||
**Footnotes**:
|
||||
@@ -34,7 +34,7 @@ tech startups, educational units, or small to mid-sized enterprises.
|
||||
### Workspace nodes
|
||||
|
||||
| Users | Node capacity | Replicas | GCP | AWS | Azure |
|
||||
| ----------- | -------------------- | ----------------------- | ---------------- | ------------ | ----------------- |
|
||||
|-------------|----------------------|-------------------------|------------------|--------------|-------------------|
|
||||
| Up to 1,000 | 8 vCPU, 32 GB memory | 64 / 16 workspaces each | `t2d-standard-8` | `t3.2xlarge` | `Standard_D8s_v3` |
|
||||
|
||||
**Footnotes**:
|
||||
@@ -47,5 +47,5 @@ tech startups, educational units, or small to mid-sized enterprises.
|
||||
### Database nodes
|
||||
|
||||
| Users | Node capacity | Replicas | Storage | GCP | AWS | Azure |
|
||||
| ----------- | ------------------- | -------- | ------- | ------------------ | ------------- | ----------------- |
|
||||
|-------------|---------------------|----------|---------|--------------------|---------------|-------------------|
|
||||
| Up to 1,000 | 2 vCPU, 8 GB memory | 1 | 512 GB | `db-custom-2-7680` | `db.t3.large` | `Standard_D2s_v3` |
|
||||
|
||||
@@ -18,13 +18,13 @@ deployment reliability under load.
|
||||
### Coderd nodes
|
||||
|
||||
| Users | Node capacity | Replicas | GCP | AWS | Azure |
|
||||
| ----------- | -------------------- | ----------------------- | --------------- | ----------- | ----------------- |
|
||||
|-------------|----------------------|-------------------------|-----------------|-------------|-------------------|
|
||||
| Up to 2,000 | 4 vCPU, 16 GB memory | 2 nodes / 1 coderd each | `n1-standard-4` | `t3.xlarge` | `Standard_D4s_v3` |
|
||||
|
||||
### Provisioner nodes
|
||||
|
||||
| Users | Node capacity | Replicas | GCP | AWS | Azure |
|
||||
| ----------- | -------------------- | ------------------------------ | ---------------- | ------------ | ----------------- |
|
||||
|-------------|----------------------|--------------------------------|------------------|--------------|-------------------|
|
||||
| Up to 2,000 | 8 vCPU, 32 GB memory | 4 nodes / 30 provisioners each | `t2d-standard-8` | `t3.2xlarge` | `Standard_D8s_v3` |
|
||||
|
||||
**Footnotes**:
|
||||
@@ -37,7 +37,7 @@ deployment reliability under load.
|
||||
### Workspace nodes
|
||||
|
||||
| Users | Node capacity | Replicas | GCP | AWS | Azure |
|
||||
| ----------- | -------------------- | ------------------------ | ---------------- | ------------ | ----------------- |
|
||||
|-------------|----------------------|--------------------------|------------------|--------------|-------------------|
|
||||
| Up to 2,000 | 8 vCPU, 32 GB memory | 128 / 16 workspaces each | `t2d-standard-8` | `t3.2xlarge` | `Standard_D8s_v3` |
|
||||
|
||||
**Footnotes**:
|
||||
@@ -50,7 +50,7 @@ deployment reliability under load.
|
||||
### Database nodes
|
||||
|
||||
| Users | Node capacity | Replicas | Storage | GCP | AWS | Azure |
|
||||
| ----------- | -------------------- | -------- | ------- | ------------------- | -------------- | ----------------- |
|
||||
|-------------|----------------------|----------|---------|---------------------|----------------|-------------------|
|
||||
| Up to 2,000 | 4 vCPU, 16 GB memory | 1 | 1 TB | `db-custom-4-15360` | `db.t3.xlarge` | `Standard_D4s_v3` |
|
||||
|
||||
**Footnotes**:
|
||||
|
||||
@@ -19,13 +19,13 @@ continuously improve the reliability and performance of the platform.
|
||||
### Coderd nodes
|
||||
|
||||
| Users | Node capacity | Replicas | GCP | AWS | Azure |
|
||||
| ----------- | -------------------- | ----------------- | --------------- | ----------- | ----------------- |
|
||||
|-------------|----------------------|-------------------|-----------------|-------------|-------------------|
|
||||
| Up to 3,000 | 8 vCPU, 32 GB memory | 4 / 1 coderd each | `n1-standard-4` | `t3.xlarge` | `Standard_D4s_v3` |
|
||||
|
||||
### Provisioner nodes
|
||||
|
||||
| Users | Node capacity | Replicas | GCP | AWS | Azure |
|
||||
| ----------- | -------------------- | ------------------------ | ---------------- | ------------ | ----------------- |
|
||||
|-------------|----------------------|--------------------------|------------------|--------------|-------------------|
|
||||
| Up to 3,000 | 8 vCPU, 32 GB memory | 8 / 30 provisioners each | `t2d-standard-8` | `t3.2xlarge` | `Standard_D8s_v3` |
|
||||
|
||||
**Footnotes**:
|
||||
@@ -39,7 +39,7 @@ continuously improve the reliability and performance of the platform.
|
||||
### Workspace nodes
|
||||
|
||||
| Users | Node capacity | Replicas | GCP | AWS | Azure |
|
||||
| ----------- | -------------------- | ------------------------------ | ---------------- | ------------ | ----------------- |
|
||||
|-------------|----------------------|--------------------------------|------------------|--------------|-------------------|
|
||||
| Up to 3,000 | 8 vCPU, 32 GB memory | 256 nodes / 12 workspaces each | `t2d-standard-8` | `t3.2xlarge` | `Standard_D8s_v3` |
|
||||
|
||||
**Footnotes**:
|
||||
@@ -53,7 +53,7 @@ continuously improve the reliability and performance of the platform.
|
||||
### Database nodes
|
||||
|
||||
| Users | Node capacity | Replicas | Storage | GCP | AWS | Azure |
|
||||
| ----------- | -------------------- | -------- | ------- | ------------------- | --------------- | ----------------- |
|
||||
|-------------|----------------------|----------|---------|---------------------|-----------------|-------------------|
|
||||
| Up to 3,000 | 8 vCPU, 32 GB memory | 2 | 1.5 TB | `db-custom-8-30720` | `db.t3.2xlarge` | `Standard_D8s_v3` |
|
||||
|
||||
**Footnotes**:
|
||||
|
||||
@@ -23,7 +23,7 @@ This guide targets the following personas. It assumes a basic understanding of
|
||||
cloud/on-premise computing, containerization, and the Coder platform.
|
||||
|
||||
| Role | Description |
|
||||
| ------------------------- | ------------------------------------------------------------------------------ |
|
||||
|---------------------------|--------------------------------------------------------------------------------|
|
||||
| Platform Engineers | Responsible for deploying, operating the Coder deployment and infrastructure |
|
||||
| Enterprise Architects | Responsible for architecting Coder deployments to meet enterprise requirements |
|
||||
| Managed Service Providers | Entities that deploy and run Coder software as a service for customers |
|
||||
@@ -31,7 +31,7 @@ cloud/on-premise computing, containerization, and the Coder platform.
|
||||
## CVA Guidance
|
||||
|
||||
| CVA provides: | CVA does not provide: |
|
||||
| ---------------------------------------------- | ---------------------------------------------------------------------------------------- |
|
||||
|------------------------------------------------|------------------------------------------------------------------------------------------|
|
||||
| Single and multi-region K8s deployment options | Prescribing OS, or cloud vs. on-premise |
|
||||
| Reference architectures for up to 3,000 users | An approval of your architecture; the CVA solely provides recommendations and guidelines |
|
||||
| Best practices for building a Coder deployment | Recommendations for every possible deployment scenario |
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
<div>
|
||||
<a href="https://github.com/ericpaulsen" style="text-decoration: none; color: inherit;">
|
||||
<span style="vertical-align:middle;">Eric Paulsen</span>
|
||||
<img src="https://github.com/ericpaulsen.png" width="24px" height="24px" style="vertical-align:middle; margin: 0px;"/>
|
||||
<img src="https://github.com/ericpaulsen.png" alt="ericpaulsen" width="24px" height="24px" style="vertical-align:middle; margin: 0px;"/>
|
||||
</a>
|
||||
</div>
|
||||
April 24, 2024
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
<div>
|
||||
<a href="https://github.com/matifali" style="text-decoration: none; color: inherit;">
|
||||
<span style="vertical-align:middle;">M Atif Ali</span>
|
||||
<img src="https://github.com/matifali.png" width="24px" height="24px" style="vertical-align:middle; margin: 0px;"/>
|
||||
<img src="https://github.com/matifali.png" alt="matifali" width="24px" height="24px" style="vertical-align:middle; margin: 0px;"/>
|
||||
</a>
|
||||
</div>
|
||||
January 24, 2024
|
||||
@@ -31,84 +31,83 @@ by using our official Coder [modules](https://registry.coder.com). We publish
|
||||
two type of modules that automate the JFrog Artifactory and Coder integration.
|
||||
|
||||
1. [JFrog-OAuth](https://registry.coder.com/modules/jfrog-oauth)
|
||||
2. [JFrog-Token](https://registry.coder.com/modules/jfrog-token)
|
||||
1. [JFrog-Token](https://registry.coder.com/modules/jfrog-token)
|
||||
|
||||
### JFrog-OAuth
|
||||
|
||||
This module is usable by JFrog self-hosted (on-premises) Artifactory as it
|
||||
requires configuring a custom integration. This integration benefits from
|
||||
Coder's [external-auth](https://coder.com/docs/admin/external-auth) feature and
|
||||
allows each user to authenticate with Artifactory using an OAuth flow and issues
|
||||
user-scoped tokens to each user.
|
||||
Coder's [external-auth](../../admin/external-auth.md) feature and allows each
|
||||
user to authenticate with Artifactory using an OAuth flow and issues user-scoped
|
||||
tokens to each user.
|
||||
|
||||
To set this up, follow these steps:
|
||||
|
||||
1. Modify your Helm chart `values.yaml` for JFrog Artifactory to add,
|
||||
|
||||
```yaml
|
||||
artifactory:
|
||||
enabled: true
|
||||
frontend:
|
||||
extraEnvironmentVariables:
|
||||
- name: JF_FRONTEND_FEATURETOGGLER_ACCESSINTEGRATION
|
||||
value: "true"
|
||||
access:
|
||||
accessConfig:
|
||||
integrations-enabled: true
|
||||
integration-templates:
|
||||
- id: "1"
|
||||
name: "CODER"
|
||||
redirect-uri: "https://CODER_URL/external-auth/jfrog/callback"
|
||||
scope: "applied-permissions/user"
|
||||
```
|
||||
```yaml
|
||||
artifactory:
|
||||
enabled: true
|
||||
frontend:
|
||||
extraEnvironmentVariables:
|
||||
- name: JF_FRONTEND_FEATURETOGGLER_ACCESSINTEGRATION
|
||||
value: "true"
|
||||
access:
|
||||
accessConfig:
|
||||
integrations-enabled: true
|
||||
integration-templates:
|
||||
- id: "1"
|
||||
name: "CODER"
|
||||
redirect-uri: "https://CODER_URL/external-auth/jfrog/callback"
|
||||
scope: "applied-permissions/user"
|
||||
```
|
||||
|
||||
> Note Replace `CODER_URL` with your Coder deployment URL, e.g.,
|
||||
> <coder.example.com>
|
||||
> Note Replace `CODER_URL` with your Coder deployment URL, e.g.,
|
||||
> <coder.example.com>
|
||||
|
||||
2. Create a new Application Integration by going to
|
||||
1. Create a new Application Integration by going to
|
||||
<https://JFROG_URL/ui/admin/configuration/integrations/new> and select the
|
||||
Application Type as the integration you created in step 1.
|
||||
|
||||

|
||||

|
||||
|
||||
3. Add a new
|
||||
[external authentication](https://coder.com/docs/admin/external-auth) to
|
||||
Coder by setting these env variables,
|
||||
1. Add a new [external authentication](../../admin/external-auth.md) to Coder by
|
||||
setting these env variables,
|
||||
|
||||
```env
|
||||
# JFrog Artifactory External Auth
|
||||
CODER_EXTERNAL_AUTH_1_ID="jfrog"
|
||||
CODER_EXTERNAL_AUTH_1_TYPE="jfrog"
|
||||
CODER_EXTERNAL_AUTH_1_CLIENT_ID="YYYYYYYYYYYYYYY"
|
||||
CODER_EXTERNAL_AUTH_1_CLIENT_SECRET="XXXXXXXXXXXXXXXXXXX"
|
||||
CODER_EXTERNAL_AUTH_1_DISPLAY_NAME="JFrog Artifactory"
|
||||
CODER_EXTERNAL_AUTH_1_DISPLAY_ICON="/icon/jfrog.svg"
|
||||
CODER_EXTERNAL_AUTH_1_AUTH_URL="https://JFROG_URL/ui/authorization"
|
||||
CODER_EXTERNAL_AUTH_1_SCOPES="applied-permissions/user"
|
||||
```
|
||||
```env
|
||||
# JFrog Artifactory External Auth
|
||||
CODER_EXTERNAL_AUTH_1_ID="jfrog"
|
||||
CODER_EXTERNAL_AUTH_1_TYPE="jfrog"
|
||||
CODER_EXTERNAL_AUTH_1_CLIENT_ID="YYYYYYYYYYYYYYY"
|
||||
CODER_EXTERNAL_AUTH_1_CLIENT_SECRET="XXXXXXXXXXXXXXXXXXX"
|
||||
CODER_EXTERNAL_AUTH_1_DISPLAY_NAME="JFrog Artifactory"
|
||||
CODER_EXTERNAL_AUTH_1_DISPLAY_ICON="/icon/jfrog.svg"
|
||||
CODER_EXTERNAL_AUTH_1_AUTH_URL="https://JFROG_URL/ui/authorization"
|
||||
CODER_EXTERNAL_AUTH_1_SCOPES="applied-permissions/user"
|
||||
```
|
||||
|
||||
> Note Replace `JFROG_URL` with your JFrog Artifactory base URL, e.g.,
|
||||
> <example.jfrog.io>
|
||||
> Note Replace `JFROG_URL` with your JFrog Artifactory base URL, e.g.,
|
||||
> <example.jfrog.io>
|
||||
|
||||
4. Create or edit a Coder template and use the
|
||||
1. Create or edit a Coder template and use the
|
||||
[JFrog-OAuth](https://registry.coder.com/modules/jfrog-oauth) module to
|
||||
configure the integration.
|
||||
|
||||
```tf
|
||||
module "jfrog" {
|
||||
source = "registry.coder.com/modules/jfrog-oauth/coder"
|
||||
version = "1.0.0"
|
||||
agent_id = coder_agent.example.id
|
||||
jfrog_url = "https://jfrog.example.com"
|
||||
configure_code_server = true # this depends on the code-server
|
||||
username_field = "username" # If you are using GitHub to login to both Coder and Artifactory, use username_field = "username"
|
||||
package_managers = {
|
||||
"npm": "npm",
|
||||
"go": "go",
|
||||
"pypi": "pypi"
|
||||
}
|
||||
}
|
||||
```
|
||||
```tf
|
||||
module "jfrog" {
|
||||
source = "registry.coder.com/modules/jfrog-oauth/coder"
|
||||
version = "1.0.0"
|
||||
agent_id = coder_agent.example.id
|
||||
jfrog_url = "https://jfrog.example.com"
|
||||
configure_code_server = true # this depends on the code-server
|
||||
username_field = "username" # If you are using GitHub to login to both Coder and Artifactory, use username_field = "username"
|
||||
package_managers = {
|
||||
"npm": "npm",
|
||||
"go": "go",
|
||||
"pypi": "pypi"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
### JFrog-Token
|
||||
|
||||
@@ -123,37 +122,36 @@ To set this up, follow these steps:
|
||||
1. Get a JFrog access token from your Artifactory instance. The token must be an
|
||||
[admin token](https://registry.terraform.io/providers/jfrog/artifactory/latest/docs#access-token)
|
||||
with scope `applied-permissions/admin`.
|
||||
2. Create or edit a Coder template and use the
|
||||
1. Create or edit a Coder template and use the
|
||||
[JFrog-Token](https://registry.coder.com/modules/jfrog-token) module to
|
||||
configure the integration and pass the admin token. It is recommended to
|
||||
store the token in a sensitive terraform variable to prevent it from being
|
||||
displayed in plain text in the terraform state.
|
||||
|
||||
```tf
|
||||
variable "artifactory_access_token" {
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
```tf
|
||||
variable "artifactory_access_token" {
|
||||
type = string
|
||||
sensitive = true
|
||||
}
|
||||
|
||||
module "jfrog" {
|
||||
source = "registry.coder.com/modules/jfrog-token/coder"
|
||||
version = "1.0.0"
|
||||
agent_id = coder_agent.example.id
|
||||
jfrog_url = "https://example.jfrog.io"
|
||||
configure_code_server = true # this depends on the code-server
|
||||
artifactory_access_token = var.artifactory_access_token
|
||||
package_managers = {
|
||||
"npm": "npm",
|
||||
"go": "go",
|
||||
"pypi": "pypi"
|
||||
}
|
||||
}
|
||||
```
|
||||
module "jfrog" {
|
||||
source = "registry.coder.com/modules/jfrog-token/coder"
|
||||
version = "1.0.0"
|
||||
agent_id = coder_agent.example.id
|
||||
jfrog_url = "https://example.jfrog.io"
|
||||
configure_code_server = true # this depends on the code-server
|
||||
artifactory_access_token = var.artifactory_access_token
|
||||
package_managers = {
|
||||
"npm": "npm",
|
||||
"go": "go",
|
||||
"pypi": "pypi"
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
<blockquote class="info">
|
||||
The admin-level access token is used to provision user tokens and is never exposed to
|
||||
developers or stored in workspaces.
|
||||
</blockquote>
|
||||
<blockquote class="info">
|
||||
The admin-level access token is used to provision user tokens and is never exposed to developers or stored in workspaces.
|
||||
</blockquote>
|
||||
|
||||
If you do not want to use the official modules, you can check example template
|
||||
that uses Docker as the underlying compute
|
||||
|
||||
@@ -3,7 +3,8 @@
|
||||
<div>
|
||||
<a href="https://github.com/matifali" style="text-decoration: none; color: inherit;">
|
||||
<span style="vertical-align:middle;">Muhammad Atif Ali</span>
|
||||
<img src="https://github.com/matifali.png" width="24px" height="24px" style="vertical-align:middle; margin: 0px;"/>
|
||||
<img src="https://github.com/matifali.png" alt="matifali" width="24px" height="24px" style="vertical-align:middle; margin: 0px;"/>
|
||||
|
||||
</a>
|
||||
</div>
|
||||
March 17, 2024
|
||||
|
||||
@@ -104,7 +104,7 @@ deployment. They will always be available from the agent.
|
||||
<!-- Code generated by 'make docs/admin/integrations/prometheus.md'. DO NOT EDIT -->
|
||||
|
||||
| Name | Type | Description | Labels |
|
||||
| ------------------------------------------------------------- | --------- | -------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------ |
|
||||
|---------------------------------------------------------------|-----------|----------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------|
|
||||
| `agent_scripts_executed_total` | counter | Total number of scripts executed by the Coder agent. Includes cron scheduled scripts. | `agent_name` `success` `template_name` `username` `workspace_name` |
|
||||
| `coderd_agents_apps` | gauge | Agent applications with statuses. | `agent_name` `app_name` `health` `username` `workspace_name` |
|
||||
| `coderd_agents_connection_latencies_seconds` | gauge | Agent connection latencies in seconds. | `agent_name` `derp_region` `preferred` `username` `workspace_name` |
|
||||
|
||||
@@ -3,7 +3,8 @@
|
||||
<div>
|
||||
<a href="https://github.com/matifali" style="text-decoration: none; color: inherit;">
|
||||
<span style="vertical-align:middle;">Muhammad Atif Ali</span>
|
||||
<img src="https://github.com/matifali.png" width="24px" height="24px" style="vertical-align:middle; margin: 0px;"/>
|
||||
<img src="https://github.com/matifali.png" alt="matifali" width="24px" height="24px" style="vertical-align:middle; margin: 0px;"/>
|
||||
|
||||
</a>
|
||||
</div>
|
||||
August 05, 2024
|
||||
|
||||
@@ -24,7 +24,7 @@ If there is an issue, you may see one of the following errors reported:
|
||||
|
||||
### EACS01
|
||||
|
||||
_Access URL not set_
|
||||
### Access URL not set
|
||||
|
||||
**Problem:** no access URL has been configured.
|
||||
|
||||
@@ -32,7 +32,7 @@ _Access URL not set_
|
||||
|
||||
### EACS02
|
||||
|
||||
_Access URL invalid_
|
||||
#### Access URL invalid
|
||||
|
||||
**Problem:** `${CODER_ACCESS_URL}/healthz` is not a valid URL.
|
||||
|
||||
@@ -44,7 +44,7 @@ _Access URL invalid_
|
||||
|
||||
### EACS03
|
||||
|
||||
_Failed to fetch `/healthz`_
|
||||
#### Failed to fetch `/healthz`
|
||||
|
||||
**Problem:** Coder was unable to execute a GET request to
|
||||
`${CODER_ACCESS_URL}/healthz`.
|
||||
@@ -74,7 +74,7 @@ The output of this command should aid further diagnosis.
|
||||
|
||||
### EACS04
|
||||
|
||||
_/healthz did not return 200 OK_
|
||||
#### /healthz did not return 200 OK
|
||||
|
||||
**Problem:** Coder was able to execute a GET request to
|
||||
`${CODER_ACCESS_URL}/healthz`, but the response code was not `200 OK` as
|
||||
@@ -97,7 +97,7 @@ its configured database, and also measures the median latency over 5 attempts.
|
||||
|
||||
### EDB01
|
||||
|
||||
_Database Ping Failed_
|
||||
#### Database Ping Failed
|
||||
|
||||
**Problem:** This error code is returned if any attempt to execute this database
|
||||
query fails.
|
||||
@@ -106,7 +106,7 @@ query fails.
|
||||
|
||||
### EDB02
|
||||
|
||||
_Database Latency High_
|
||||
#### Database Latency High
|
||||
|
||||
**Problem:** This code is returned if the median latency is higher than the
|
||||
[configured threshold](../../reference/cli/server.md#--health-check-threshold-database).
|
||||
@@ -138,7 +138,7 @@ following:
|
||||
|
||||
### EDERP01
|
||||
|
||||
_DERP Node Uses Websocket_
|
||||
#### DERP Node Uses Websocket
|
||||
|
||||
**Problem:** When Coder attempts to establish a connection to one or more DERP
|
||||
servers, it sends a specific `Upgrade: derp` HTTP header. Some load balancers
|
||||
@@ -157,7 +157,7 @@ still be able to reach their workspaces, connection performance may be degraded.
|
||||
|
||||
### EDERP02
|
||||
|
||||
_One or more DERP nodes are unhealthy_
|
||||
#### One or more DERP nodes are unhealthy
|
||||
|
||||
**Problem:** This is shown if Coder is unable to reach one or more configured
|
||||
DERP servers. Clients will fall back to use the remaining DERP servers, but
|
||||
@@ -176,7 +176,7 @@ curl -v "https://coder.company.com/derp"
|
||||
|
||||
### ESTUN01
|
||||
|
||||
_No STUN servers available._
|
||||
#### No STUN servers available
|
||||
|
||||
**Problem:** This is shown if no STUN servers are available. Coder will use STUN
|
||||
to establish [direct connections](../networking/stun.md). Without at least one
|
||||
@@ -189,7 +189,7 @@ configured port.
|
||||
|
||||
### ESTUN02
|
||||
|
||||
_STUN returned different addresses; you may be behind a hard NAT._
|
||||
#### STUN returned different addresses; you may be behind a hard NAT
|
||||
|
||||
**Problem:** This is a warning shown when multiple attempts to determine our
|
||||
public IP address/port via STUN resulted in different `ip:port` combinations.
|
||||
@@ -218,7 +218,7 @@ message over the connection, and attempt to read back that same message.
|
||||
|
||||
### EWS01
|
||||
|
||||
_Failed to establish a WebSocket connection_
|
||||
#### Failed to establish a WebSocket connection
|
||||
|
||||
**Problem:** Coder was unable to establish a WebSocket connection over its own
|
||||
Access URL.
|
||||
@@ -237,7 +237,7 @@ Access URL.
|
||||
|
||||
### EWS02
|
||||
|
||||
_Failed to echo a WebSocket message_
|
||||
#### Failed to echo a WebSocket message
|
||||
|
||||
**Problem:** Coder was able to establish a WebSocket connection, but was unable
|
||||
to write a message.
|
||||
@@ -258,7 +258,7 @@ Coder will periodically query their availability and show their status here.
|
||||
|
||||
### EWP01
|
||||
|
||||
_Error Updating Workspace Proxy Health_
|
||||
#### Error Updating Workspace Proxy Health
|
||||
|
||||
**Problem:** Coder was unable to query the connected workspace proxies for their
|
||||
health status.
|
||||
@@ -268,7 +268,7 @@ connectivity issue.
|
||||
|
||||
### EWP02
|
||||
|
||||
_Error Fetching Workspace Proxies_
|
||||
#### Error Fetching Workspace Proxies
|
||||
|
||||
**Problem:** Coder was unable to fetch the stored workspace proxy health data
|
||||
from the database.
|
||||
@@ -278,7 +278,7 @@ issue with Coder's configured database.
|
||||
|
||||
### EWP04
|
||||
|
||||
_One or more Workspace Proxies Unhealthy_
|
||||
#### One or more Workspace Proxies Unhealthy
|
||||
|
||||
**Problem:** One or more workspace proxies are not reachable.
|
||||
|
||||
@@ -287,7 +287,7 @@ workspace proxies.
|
||||
|
||||
### EPD01
|
||||
|
||||
_No Provisioner Daemons Available_
|
||||
#### No Provisioner Daemons Available
|
||||
|
||||
**Problem:** No provisioner daemons are registered with Coder. No workspaces can
|
||||
be built until there is at least one provisioner daemon running.
|
||||
@@ -305,7 +305,7 @@ is set to a value greater than 0.
|
||||
|
||||
### EPD02
|
||||
|
||||
_Provisioner Daemon Version Mismatch_
|
||||
#### Provisioner Daemon Version Mismatch
|
||||
|
||||
**Problem:** One or more provisioner daemons are more than one major or minor
|
||||
version out of date with the main deployment. It is important that provisioner
|
||||
@@ -320,7 +320,7 @@ version of Coder.
|
||||
|
||||
### EPD03
|
||||
|
||||
_Provisioner Daemon API Version Mismatch_
|
||||
#### Provisioner Daemon API Version Mismatch
|
||||
|
||||
**Problem:** One or more provisioner daemons are using APIs that are marked as
|
||||
deprecated. These deprecated APIs may be removed in a future release of Coder,
|
||||
@@ -333,9 +333,9 @@ version of Coder.
|
||||
> Note: This may be a transient issue if you are currently in the process of
|
||||
> updating your deployment.
|
||||
|
||||
## EUNKNOWN
|
||||
### EUNKNOWN
|
||||
|
||||
_Unknown Error_
|
||||
#### Unknown Error
|
||||
|
||||
**Problem:** This error is shown when an unexpected error occurred evaluating
|
||||
deployment health. It may resolve on its own.
|
||||
|
||||
@@ -8,7 +8,7 @@ If you don't have an Prometheus server installed, you can follow the Prometheus
|
||||
[Getting started](https://prometheus.io/docs/prometheus/latest/getting_started/)
|
||||
guide.
|
||||
|
||||
### Setting up metrics
|
||||
## Setting up metrics
|
||||
|
||||
To set up metrics monitoring, please read our
|
||||
[Prometheus integration guide](../integrations/prometheus.md). The following
|
||||
|
||||
@@ -64,7 +64,7 @@ You can modify the notification delivery behavior using the following server
|
||||
flags.
|
||||
|
||||
| Required | CLI | Env | Type | Description | Default |
|
||||
| :------: | ----------------------------------- | --------------------------------------- | ---------- | --------------------------------------------------------------------------------------------------------------------- | ------- |
|
||||
|:--------:|-------------------------------------|-----------------------------------------|------------|-----------------------------------------------------------------------------------------------------------------------|---------|
|
||||
| ✔️ | `--notifications-dispatch-timeout` | `CODER_NOTIFICATIONS_DISPATCH_TIMEOUT` | `duration` | How long to wait while a notification is being sent before giving up. | 1m |
|
||||
| ✔️ | `--notifications-method` | `CODER_NOTIFICATIONS_METHOD` | `string` | Which delivery method to use (available options: 'smtp', 'webhook'). See [Delivery Methods](#delivery-methods) below. | smtp |
|
||||
| -️ | `--notifications-max-send-attempts` | `CODER_NOTIFICATIONS_MAX_SEND_ATTEMPTS` | `int` | The upper limit of attempts to send a notification. | 5 |
|
||||
@@ -90,15 +90,15 @@ existing one.
|
||||
**Server Settings:**
|
||||
|
||||
| Required | CLI | Env | Type | Description | Default |
|
||||
| :------: | ------------------- | ----------------------- | -------- | ----------------------------------------- | --------- |
|
||||
|:--------:|---------------------|-------------------------|----------|-------------------------------------------|-----------|
|
||||
| ✔️ | `--email-from` | `CODER_EMAIL_FROM` | `string` | The sender's address to use. | |
|
||||
| ✔️ | `--email-smarthost` | `CODER_EMAIL_SMARTHOST` | `string` | The SMTP relay to send messages |
|
||||
| ✔️ | `--email-smarthost` | `CODER_EMAIL_SMARTHOST` | `string` | The SMTP relay to send messages | |
|
||||
| ✔️ | `--email-hello` | `CODER_EMAIL_HELLO` | `string` | The hostname identifying the SMTP server. | localhost |
|
||||
|
||||
**Authentication Settings:**
|
||||
|
||||
| Required | CLI | Env | Type | Description |
|
||||
| :------: | ---------------------------- | -------------------------------- | -------- | ------------------------------------------------------------------------- |
|
||||
|:--------:|------------------------------|----------------------------------|----------|---------------------------------------------------------------------------|
|
||||
| - | `--email-auth-username` | `CODER_EMAIL_AUTH_USERNAME` | `string` | Username to use with PLAIN/LOGIN authentication. |
|
||||
| - | `--email-auth-password` | `CODER_EMAIL_AUTH_PASSWORD` | `string` | Password to use with PLAIN/LOGIN authentication. |
|
||||
| - | `--email-auth-password-file` | `CODER_EMAIL_AUTH_PASSWORD_FILE` | `string` | File from which to load password for use with PLAIN/LOGIN authentication. |
|
||||
@@ -106,14 +106,14 @@ existing one.
|
||||
|
||||
**TLS Settings:**
|
||||
|
||||
| Required | CLI | Env | Type | Description | Default |
|
||||
| :------: | --------------------------- | ----------------------------- | -------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------- |
|
||||
| - | `--email-force-tls` | `CODER_EMAIL_FORCE_TLS` | `bool` | Force a TLS connection to the configured SMTP smarthost. If port 465 is used, TLS will be forced. See https://datatracker.ietf.org/doc/html/rfc8314#section-3.3. | false |
|
||||
| - | `--email-tls-starttls` | `CODER_EMAIL_TLS_STARTTLS` | `bool` | Enable STARTTLS to upgrade insecure SMTP connections using TLS. Ignored if `CODER_NOTIFICATIONS_EMAIL_FORCE_TLS` is set. | false |
|
||||
| - | `--email-tls-skip-verify` | `CODER_EMAIL_TLS_SKIPVERIFY` | `bool` | Skip verification of the target server's certificate (**insecure**). | false |
|
||||
| - | `--email-tls-server-name` | `CODER_EMAIL_TLS_SERVERNAME` | `string` | Server name to verify against the target certificate. | |
|
||||
| - | `--email-tls-cert-file` | `CODER_EMAIL_TLS_CERTFILE` | `string` | Certificate file to use. | |
|
||||
| - | `--email-tls-cert-key-file` | `CODER_EMAIL_TLS_CERTKEYFILE` | `string` | Certificate key file to use. | |
|
||||
| Required | CLI | Env | Type | Description | Default |
|
||||
|:--------:|-----------------------------|-------------------------------|----------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------|
|
||||
| - | `--email-force-tls` | `CODER_EMAIL_FORCE_TLS` | `bool` | Force a TLS connection to the configured SMTP smarthost. If port 465 is used, TLS will be forced. See <https://datatracker.ietf.org/doc/html/rfc8314#section-3.3>. | false |
|
||||
| - | `--email-tls-starttls` | `CODER_EMAIL_TLS_STARTTLS` | `bool` | Enable STARTTLS to upgrade insecure SMTP connections using TLS. Ignored if `CODER_NOTIFICATIONS_EMAIL_FORCE_TLS` is set. | false |
|
||||
| - | `--email-tls-skip-verify` | `CODER_EMAIL_TLS_SKIPVERIFY` | `bool` | Skip verification of the target server's certificate (**insecure**). | false |
|
||||
| - | `--email-tls-server-name` | `CODER_EMAIL_TLS_SERVERNAME` | `string` | Server name to verify against the target certificate. | |
|
||||
| - | `--email-tls-cert-file` | `CODER_EMAIL_TLS_CERTFILE` | `string` | Certificate file to use. | |
|
||||
| - | `--email-tls-cert-key-file` | `CODER_EMAIL_TLS_CERTKEYFILE` | `string` | Certificate key file to use. | |
|
||||
|
||||
**NOTE:** you _MUST_ use `CODER_EMAIL_FORCE_TLS` if your smarthost supports TLS
|
||||
on a port other than `465`.
|
||||
@@ -123,9 +123,11 @@ on a port other than `465`.
|
||||
After setting the required fields above:
|
||||
|
||||
1. Create an [App Password](https://myaccount.google.com/apppasswords) using the
|
||||
account you wish to send from
|
||||
2. Set the following configuration options:
|
||||
```
|
||||
account you wish to send from.
|
||||
|
||||
1. Set the following configuration options:
|
||||
|
||||
```text
|
||||
CODER_EMAIL_SMARTHOST=smtp.gmail.com:465
|
||||
CODER_EMAIL_AUTH_USERNAME=<user>@<domain>
|
||||
CODER_EMAIL_AUTH_PASSWORD="<app password created above>"
|
||||
@@ -140,8 +142,9 @@ for more options.
|
||||
After setting the required fields above:
|
||||
|
||||
1. Setup an account on Microsoft 365 or outlook.com
|
||||
2. Set the following configuration options:
|
||||
```
|
||||
1. Set the following configuration options:
|
||||
|
||||
```text
|
||||
CODER_EMAIL_SMARTHOST=smtp-mail.outlook.com:587
|
||||
CODER_EMAIL_TLS_STARTTLS=true
|
||||
CODER_EMAIL_AUTH_USERNAME=<user>@<domain>
|
||||
@@ -161,40 +164,40 @@ systems.
|
||||
**Settings**:
|
||||
|
||||
| Required | CLI | Env | Type | Description |
|
||||
| :------: | ---------------------------------- | -------------------------------------- | ----- | --------------------------------------- |
|
||||
|:--------:|------------------------------------|----------------------------------------|-------|-----------------------------------------|
|
||||
| ✔️ | `--notifications-webhook-endpoint` | `CODER_NOTIFICATIONS_WEBHOOK_ENDPOINT` | `url` | The endpoint to which to send webhooks. |
|
||||
|
||||
Here is an example payload for Coder's webhook notification:
|
||||
|
||||
```json
|
||||
{
|
||||
"_version": "1.0",
|
||||
"msg_id": "88750cad-77d4-4663-8bc0-f46855f5019b",
|
||||
"payload": {
|
||||
"_version": "1.0",
|
||||
"notification_name": "Workspace Deleted",
|
||||
"user_id": "4ac34fcb-8155-44d5-8301-e3cd46e88b35",
|
||||
"user_email": "danny@coder.com",
|
||||
"user_name": "danny",
|
||||
"user_username": "danny",
|
||||
"actions": [
|
||||
{
|
||||
"label": "View workspaces",
|
||||
"url": "https://et23ntkhpueak.pit-1.try.coder.app/workspaces"
|
||||
},
|
||||
{
|
||||
"label": "View templates",
|
||||
"url": "https://et23ntkhpueak.pit-1.try.coder.app/templates"
|
||||
}
|
||||
],
|
||||
"labels": {
|
||||
"initiator": "danny",
|
||||
"name": "my-workspace",
|
||||
"reason": "initiated by user"
|
||||
}
|
||||
},
|
||||
"title": "Workspace \"my-workspace\" deleted",
|
||||
"body": "Hi danny\n\nYour workspace my-workspace was deleted.\nThe specified reason was \"initiated by user (danny)\"."
|
||||
"_version": "1.0",
|
||||
"msg_id": "88750cad-77d4-4663-8bc0-f46855f5019b",
|
||||
"payload": {
|
||||
"_version": "1.0",
|
||||
"notification_name": "Workspace Deleted",
|
||||
"user_id": "4ac34fcb-8155-44d5-8301-e3cd46e88b35",
|
||||
"user_email": "danny@coder.com",
|
||||
"user_name": "danny",
|
||||
"user_username": "danny",
|
||||
"actions": [
|
||||
{
|
||||
"label": "View workspaces",
|
||||
"url": "https://et23ntkhpueak.pit-1.try.coder.app/workspaces"
|
||||
},
|
||||
{
|
||||
"label": "View templates",
|
||||
"url": "https://et23ntkhpueak.pit-1.try.coder.app/templates"
|
||||
}
|
||||
],
|
||||
"labels": {
|
||||
"initiator": "danny",
|
||||
"name": "my-workspace",
|
||||
"reason": "initiated by user"
|
||||
}
|
||||
},
|
||||
"title": "Workspace \"my-workspace\" deleted",
|
||||
"body": "Hi danny\n\nYour workspace my-workspace was deleted.\nThe specified reason was \"initiated by user (danny)\"."
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
@@ -34,9 +34,9 @@ To integrate Slack with Coder, follow these steps to create a Slack application:
|
||||
|
||||
3. Under "OAuth & Permissions", add the following OAuth scopes:
|
||||
|
||||
- `chat:write`: To send messages as the app.
|
||||
- `users:read`: To find the user details.
|
||||
- `users:read.email`: To find user emails.
|
||||
- `chat:write`: To send messages as the app.
|
||||
- `users:read`: To find the user details.
|
||||
- `users:read.email`: To find user emails.
|
||||
|
||||
4. Install the app to your workspace and note down the **Bot User OAuth Token**
|
||||
from the "OAuth & Permissions" section.
|
||||
@@ -52,128 +52,128 @@ To build the server to receive webhooks and interact with Slack:
|
||||
|
||||
1. Initialize your project by running:
|
||||
|
||||
```bash
|
||||
npm init -y
|
||||
```
|
||||
```bash
|
||||
npm init -y
|
||||
```
|
||||
|
||||
2. Install the Bolt library:
|
||||
|
||||
```bash
|
||||
npm install @slack/bolt
|
||||
```
|
||||
```bash
|
||||
npm install @slack/bolt
|
||||
```
|
||||
|
||||
3. Create and edit the `app.js` file. Below is an example of the basic
|
||||
structure:
|
||||
|
||||
```js
|
||||
const { App, LogLevel, ExpressReceiver } = require("@slack/bolt");
|
||||
const bodyParser = require("body-parser");
|
||||
```js
|
||||
const { App, LogLevel, ExpressReceiver } = require("@slack/bolt");
|
||||
const bodyParser = require("body-parser");
|
||||
|
||||
const port = process.env.PORT || 6000;
|
||||
const port = process.env.PORT || 6000;
|
||||
|
||||
// Create a Bolt Receiver
|
||||
const receiver = new ExpressReceiver({
|
||||
signingSecret: process.env.SLACK_SIGNING_SECRET,
|
||||
});
|
||||
receiver.router.use(bodyParser.json());
|
||||
// Create a Bolt Receiver
|
||||
const receiver = new ExpressReceiver({
|
||||
signingSecret: process.env.SLACK_SIGNING_SECRET,
|
||||
});
|
||||
receiver.router.use(bodyParser.json());
|
||||
|
||||
// Create the Bolt App, using the receiver
|
||||
const app = new App({
|
||||
token: process.env.SLACK_BOT_TOKEN,
|
||||
logLevel: LogLevel.DEBUG,
|
||||
receiver,
|
||||
});
|
||||
// Create the Bolt App, using the receiver
|
||||
const app = new App({
|
||||
token: process.env.SLACK_BOT_TOKEN,
|
||||
logLevel: LogLevel.DEBUG,
|
||||
receiver,
|
||||
});
|
||||
|
||||
receiver.router.post("/v1/webhook", async (req, res) => {
|
||||
try {
|
||||
if (!req.body) {
|
||||
return res.status(400).send("Error: request body is missing");
|
||||
}
|
||||
receiver.router.post("/v1/webhook", async (req, res) => {
|
||||
try {
|
||||
if (!req.body) {
|
||||
return res.status(400).send("Error: request body is missing");
|
||||
}
|
||||
|
||||
const { title, body } = req.body;
|
||||
if (!title || !body) {
|
||||
return res.status(400).send('Error: missing fields: "title", or "body"');
|
||||
}
|
||||
const { title, body } = req.body;
|
||||
if (!title || !body) {
|
||||
return res.status(400).send('Error: missing fields: "title", or "body"');
|
||||
}
|
||||
|
||||
const payload = req.body.payload;
|
||||
if (!payload) {
|
||||
return res.status(400).send('Error: missing "payload" field');
|
||||
}
|
||||
const payload = req.body.payload;
|
||||
if (!payload) {
|
||||
return res.status(400).send('Error: missing "payload" field');
|
||||
}
|
||||
|
||||
const { user_email, actions } = payload;
|
||||
if (!user_email || !actions) {
|
||||
return res
|
||||
.status(400)
|
||||
.send('Error: missing fields: "user_email", "actions"');
|
||||
}
|
||||
const { user_email, actions } = payload;
|
||||
if (!user_email || !actions) {
|
||||
return res
|
||||
.status(400)
|
||||
.send('Error: missing fields: "user_email", "actions"');
|
||||
}
|
||||
|
||||
// Get the user ID using Slack API
|
||||
const userByEmail = await app.client.users.lookupByEmail({
|
||||
email: user_email,
|
||||
});
|
||||
// Get the user ID using Slack API
|
||||
const userByEmail = await app.client.users.lookupByEmail({
|
||||
email: user_email,
|
||||
});
|
||||
|
||||
const slackMessage = {
|
||||
channel: userByEmail.user.id,
|
||||
text: body,
|
||||
blocks: [
|
||||
{
|
||||
type: "header",
|
||||
text: { type: "plain_text", text: title },
|
||||
},
|
||||
{
|
||||
type: "section",
|
||||
text: { type: "mrkdwn", text: body },
|
||||
},
|
||||
],
|
||||
};
|
||||
const slackMessage = {
|
||||
channel: userByEmail.user.id,
|
||||
text: body,
|
||||
blocks: [
|
||||
{
|
||||
type: "header",
|
||||
text: { type: "plain_text", text: title },
|
||||
},
|
||||
{
|
||||
type: "section",
|
||||
text: { type: "mrkdwn", text: body },
|
||||
},
|
||||
],
|
||||
};
|
||||
|
||||
// Add action buttons if they exist
|
||||
if (actions && actions.length > 0) {
|
||||
slackMessage.blocks.push({
|
||||
type: "actions",
|
||||
elements: actions.map((action) => ({
|
||||
type: "button",
|
||||
text: { type: "plain_text", text: action.label },
|
||||
url: action.url,
|
||||
})),
|
||||
});
|
||||
}
|
||||
// Add action buttons if they exist
|
||||
if (actions && actions.length > 0) {
|
||||
slackMessage.blocks.push({
|
||||
type: "actions",
|
||||
elements: actions.map((action) => ({
|
||||
type: "button",
|
||||
text: { type: "plain_text", text: action.label },
|
||||
url: action.url,
|
||||
})),
|
||||
});
|
||||
}
|
||||
|
||||
// Post message to the user on Slack
|
||||
await app.client.chat.postMessage(slackMessage);
|
||||
// Post message to the user on Slack
|
||||
await app.client.chat.postMessage(slackMessage);
|
||||
|
||||
res.status(204).send();
|
||||
} catch (error) {
|
||||
console.error("Error sending message:", error);
|
||||
res.status(500).send();
|
||||
}
|
||||
});
|
||||
res.status(204).send();
|
||||
} catch (error) {
|
||||
console.error("Error sending message:", error);
|
||||
res.status(500).send();
|
||||
}
|
||||
});
|
||||
|
||||
// Acknowledge clicks on link_button, otherwise Slack UI
|
||||
// complains about missing events.
|
||||
app.action("button_click", async ({ body, ack, say }) => {
|
||||
await ack(); // no specific action needed
|
||||
});
|
||||
// Acknowledge clicks on link_button, otherwise Slack UI
|
||||
// complains about missing events.
|
||||
app.action("button_click", async ({ body, ack, say }) => {
|
||||
await ack(); // no specific action needed
|
||||
});
|
||||
|
||||
// Start the Bolt app
|
||||
(async () => {
|
||||
await app.start(port);
|
||||
console.log("⚡️ Coder Slack bot is running!");
|
||||
})();
|
||||
```
|
||||
// Start the Bolt app
|
||||
(async () => {
|
||||
await app.start(port);
|
||||
console.log("⚡️ Coder Slack bot is running!");
|
||||
})();
|
||||
```
|
||||
|
||||
3. Set environment variables to identify the Slack app:
|
||||
4. Set environment variables to identify the Slack app:
|
||||
|
||||
```bash
|
||||
export SLACK_BOT_TOKEN=xoxb-...
|
||||
export SLACK_SIGNING_SECRET=0da4b...
|
||||
```
|
||||
```bash
|
||||
export SLACK_BOT_TOKEN=xoxb-...
|
||||
export SLACK_SIGNING_SECRET=0da4b...
|
||||
```
|
||||
|
||||
4. Start the web application by running:
|
||||
5. Start the web application by running:
|
||||
|
||||
```bash
|
||||
node app.js
|
||||
```
|
||||
```bash
|
||||
node app.js
|
||||
```
|
||||
|
||||
## Enable Interactivity in Slack
|
||||
|
||||
|
||||
@@ -21,115 +21,115 @@ following:
|
||||
|
||||
The process of setting up a Teams workflow consists of three key steps:
|
||||
|
||||
1. Configure the Webhook Trigger.
|
||||
1. Configure the Webhook Trigger.
|
||||
|
||||
Begin by configuring the trigger: **"When a Teams webhook request is
|
||||
received"**.
|
||||
Begin by configuring the trigger: **"When a Teams webhook request is
|
||||
received"**.
|
||||
|
||||
Ensure the trigger access level is set to **"Anyone"**.
|
||||
Ensure the trigger access level is set to **"Anyone"**.
|
||||
|
||||
2. Setup the JSON Parsing Action.
|
||||
1. Setup the JSON Parsing Action.
|
||||
|
||||
Next, add the **"Parse JSON"** action, linking the content to the **"Body"**
|
||||
of the received webhook request. Use the following schema to parse the
|
||||
notification payload:
|
||||
Add the **"Parse JSON"** action, linking the content to the **"Body"** of the
|
||||
received webhook request. Use the following schema to parse the notification
|
||||
payload:
|
||||
|
||||
```json
|
||||
{
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"_version": {
|
||||
"type": "string"
|
||||
},
|
||||
"payload": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"_version": {
|
||||
"type": "string"
|
||||
},
|
||||
"user_email": {
|
||||
"type": "string"
|
||||
},
|
||||
"actions": {
|
||||
"type": "array",
|
||||
"items": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"label": {
|
||||
"type": "string"
|
||||
},
|
||||
"url": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": ["label", "url"]
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"title": {
|
||||
"type": "string"
|
||||
},
|
||||
"body": {
|
||||
"type": "string"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
```json
|
||||
{
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"_version": {
|
||||
"type": "string"
|
||||
},
|
||||
"payload": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"_version": {
|
||||
"type": "string"
|
||||
},
|
||||
"user_email": {
|
||||
"type": "string"
|
||||
},
|
||||
"actions": {
|
||||
"type": "array",
|
||||
"items": {
|
||||
"type": "object",
|
||||
"properties": {
|
||||
"label": {
|
||||
"type": "string"
|
||||
},
|
||||
"url": {
|
||||
"type": "string"
|
||||
}
|
||||
},
|
||||
"required": ["label", "url"]
|
||||
}
|
||||
}
|
||||
}
|
||||
},
|
||||
"title": {
|
||||
"type": "string"
|
||||
},
|
||||
"body": {
|
||||
"type": "string"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
This action parses the notification's title, body, and the recipient's email
|
||||
address.
|
||||
This action parses the notification's title, body, and the recipient's email
|
||||
address.
|
||||
|
||||
3. Configure the Adaptive Card Action.
|
||||
1. Configure the Adaptive Card Action.
|
||||
|
||||
Finally, set up the **"Post Adaptive Card in a chat or channel"** action
|
||||
with the following recommended settings:
|
||||
Finally, set up the **"Post Adaptive Card in a chat or channel"** action with
|
||||
the following recommended settings:
|
||||
|
||||
**Post as**: Flow Bot
|
||||
**Post as**: Flow Bot
|
||||
|
||||
**Post in**: Chat with Flow Bot
|
||||
**Post in**: Chat with Flow Bot
|
||||
|
||||
**Recipient**: `user_email`
|
||||
**Recipient**: `user_email`
|
||||
|
||||
Use the following _Adaptive Card_ template:
|
||||
Use the following _Adaptive Card_ template:
|
||||
|
||||
```json
|
||||
{
|
||||
"$schema": "https://adaptivecards.io/schemas/adaptive-card.json",
|
||||
"type": "AdaptiveCard",
|
||||
"version": "1.0",
|
||||
"body": [
|
||||
{
|
||||
"type": "Image",
|
||||
"url": "https://coder.com/coder-logo-horizontal.png",
|
||||
"height": "40px",
|
||||
"altText": "Coder",
|
||||
"horizontalAlignment": "center"
|
||||
},
|
||||
{
|
||||
"type": "TextBlock",
|
||||
"text": "**@{replace(body('Parse_JSON')?['title'], '"', '\"')}**"
|
||||
},
|
||||
{
|
||||
"type": "TextBlock",
|
||||
"text": "@{replace(body('Parse_JSON')?['body'], '"', '\"')}",
|
||||
"wrap": true
|
||||
},
|
||||
{
|
||||
"type": "ActionSet",
|
||||
"actions": [@{replace(replace(join(body('Parse_JSON')?['payload']?['actions'], ','), '{', '{"type": "Action.OpenUrl",'), '"label"', '"title"')}]
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
```json
|
||||
{
|
||||
"$schema": "https://adaptivecards.io/schemas/adaptive-card.json",
|
||||
"type": "AdaptiveCard",
|
||||
"version": "1.0",
|
||||
"body": [
|
||||
{
|
||||
"type": "Image",
|
||||
"url": "https://coder.com/coder-logo-horizontal.png",
|
||||
"height": "40px",
|
||||
"altText": "Coder",
|
||||
"horizontalAlignment": "center"
|
||||
},
|
||||
{
|
||||
"type": "TextBlock",
|
||||
"text": "**@{replace(body('Parse_JSON')?['title'], '"', '\"')}**"
|
||||
},
|
||||
{
|
||||
"type": "TextBlock",
|
||||
"text": "@{replace(body('Parse_JSON')?['body'], '"', '\"')}",
|
||||
"wrap": true
|
||||
},
|
||||
{
|
||||
"type": "ActionSet",
|
||||
"actions": [@{replace(replace(join(body('Parse_JSON')?['payload']?['actions'], ','), '{', '{"type": "Action.OpenUrl",'), '"label"', '"title"')}]
|
||||
}
|
||||
]
|
||||
}
|
||||
```
|
||||
|
||||
_Notice_: The Coder `actions` format differs from the `ActionSet` schema, so
|
||||
its properties need to be modified: include `Action.OpenUrl` type, rename
|
||||
`label` to `title`. Unfortunately, there is no straightforward solution for
|
||||
`for-each` pattern.
|
||||
_Notice_: The Coder `actions` format differs from the `ActionSet` schema, so
|
||||
its properties need to be modified: include `Action.OpenUrl` type, rename
|
||||
`label` to `title`. Unfortunately, there is no straightforward solution for
|
||||
`for-each` pattern.
|
||||
|
||||
Feel free to customize the payload to modify the logo, notification title,
|
||||
or body content to suit your needs.
|
||||
Feel free to customize the payload to modify the logo, notification title, or
|
||||
body content to suit your needs.
|
||||
|
||||
## Enable Webhook Integration
|
||||
|
||||
|
||||
@@ -42,7 +42,7 @@ rendezvous for the Coder nodes.
|
||||
Here's an example 3-node network configuration setup:
|
||||
|
||||
| Name | `CODER_HTTP_ADDRESS` | `CODER_DERP_SERVER_RELAY_URL` | `CODER_ACCESS_URL` |
|
||||
| --------- | -------------------- | ----------------------------- | ------------------------ |
|
||||
|-----------|----------------------|-------------------------------|--------------------------|
|
||||
| `coder-1` | `*:80` | `http://10.0.0.1:80` | `https://coder.big.corp` |
|
||||
| `coder-2` | `*:80` | `http://10.0.0.2:80` | `https://coder.big.corp` |
|
||||
| `coder-3` | `*:80` | `http://10.0.0.3:80` | `https://coder.big.corp` |
|
||||
|
||||
@@ -168,7 +168,7 @@ After you have custom DERP servers, you can launch Coder with them like so:
|
||||
```
|
||||
|
||||
```bash
|
||||
$ coder server --derp-config-path derpmap.json
|
||||
coder server --derp-config-path derpmap.json
|
||||
```
|
||||
|
||||
### Dashboard connections
|
||||
|
||||
@@ -156,7 +156,7 @@ protocol configuration for each shared port individually.
|
||||
You can access any port on the workspace and can configure the port protocol
|
||||
manually by appending a `s` to the port in the URL.
|
||||
|
||||
```
|
||||
```text
|
||||
# Uses HTTP
|
||||
https://33295--agent--workspace--user--apps.example.com/
|
||||
# Uses HTTPS
|
||||
@@ -180,8 +180,8 @@ requests cannot be authenticated and you will see an error resembling the
|
||||
following:
|
||||
|
||||
> Access to fetch at
|
||||
> 'https://coder.example.com/api/v2/applications/auth-redirect' from origin
|
||||
> 'https://8000--dev--user--apps.coder.example.com' has been blocked by CORS
|
||||
> '<https://coder.example.com/api/v2/applications/auth-redirect>' from origin
|
||||
> '<https://8000--dev--user--apps.coder.example.com>' has been blocked by CORS
|
||||
> policy: No 'Access-Control-Allow-Origin' header is present on the requested
|
||||
> resource. If an opaque response serves your needs, set the request's mode to
|
||||
> 'no-cors' to fetch the resource with CORS disabled.
|
||||
@@ -190,7 +190,7 @@ following:
|
||||
|
||||
Below is a list of the cross-origin headers Coder sets with example values:
|
||||
|
||||
```
|
||||
```text
|
||||
access-control-allow-credentials: true
|
||||
access-control-allow-methods: PUT
|
||||
access-control-allow-headers: X-Custom-Header
|
||||
|
||||
@@ -14,11 +14,11 @@ connecting with their workspace over SSH, a workspace app, port forwarding, etc.
|
||||
Dashboard connections and API calls (e.g. the workspaces list) are not served
|
||||
over workspace proxies.
|
||||
|
||||
# Deploy a workspace proxy
|
||||
## Deploy a workspace proxy
|
||||
|
||||
Each workspace proxy should be a unique instance. At no point should 2 workspace
|
||||
proxy instances share the same authentication token. They only require port 443
|
||||
to be open and are expected to have network connectivity to the coderd
|
||||
Each workspace proxy should be a unique instance. At no point should two
|
||||
workspace proxy instances share the same authentication token. They only require
|
||||
port 443 to be open and are expected to have network connectivity to the coderd
|
||||
dashboard. Workspace proxies **do not** make any database connections.
|
||||
|
||||
Workspace proxies can be used in the browser by navigating to the user
|
||||
|
||||
+23
-23
@@ -201,33 +201,33 @@ different organizations.
|
||||
This is illustrated in the below table:
|
||||
|
||||
| Provisioner Tags | Job Tags | Same Org | Can Run Job? |
|
||||
| ----------------------------------------------------------------- | ---------------------------------------------------------------- | -------- | ------------ |
|
||||
| scope=organization owner= | scope=organization owner= | ✅ | ✅ |
|
||||
| scope=organization owner= environment=on-prem | scope=organization owner= environment=on-prem | ✅ | ✅ |
|
||||
| scope=organization owner= environment=on-prem datacenter=chicago | scope=organization owner= environment=on-prem | ✅ | ✅ |
|
||||
| scope=organization owner= environment=on-prem datacenter=chicago | scope=organization owner= environment=on-prem datacenter=chicago | ✅ | ✅ |
|
||||
| scope=user owner=aaa | scope=user owner=aaa | ✅ | ✅ |
|
||||
| scope=user owner=aaa environment=on-prem | scope=user owner=aaa | ✅ | ✅ |
|
||||
| scope=user owner=aaa environment=on-prem | scope=user owner=aaa environment=on-prem | ✅ | ✅ |
|
||||
| scope=user owner=aaa environment=on-prem datacenter=chicago | scope=user owner=aaa environment=on-prem | ✅ | ✅ |
|
||||
| scope=user owner=aaa environment=on-prem datacenter=chicago | scope=user owner=aaa environment=on-prem datacenter=chicago | ✅ | ✅ |
|
||||
| scope=organization owner= | scope=organization owner= environment=on-prem | ✅ | ❌ |
|
||||
| scope=organization owner= environment=on-prem | scope=organization owner= | ✅ | ❌ |
|
||||
| scope=organization owner= environment=on-prem | scope=organization owner= environment=on-prem datacenter=chicago | ✅ | ❌ |
|
||||
| scope=organization owner= environment=on-prem datacenter=new_york | scope=organization owner= environment=on-prem datacenter=chicago | ✅ | ❌ |
|
||||
| scope=user owner=aaa | scope=organization owner= | ✅ | ❌ |
|
||||
| scope=user owner=aaa | scope=user owner=bbb | ✅ | ❌ |
|
||||
| scope=organization owner= | scope=user owner=aaa | ✅ | ❌ |
|
||||
| scope=organization owner= | scope=user owner=aaa environment=on-prem | ✅ | ❌ |
|
||||
| scope=user owner=aaa | scope=user owner=aaa environment=on-prem | ✅ | ❌ |
|
||||
| scope=user owner=aaa environment=on-prem | scope=user owner=aaa environment=on-prem datacenter=chicago | ✅ | ❌ |
|
||||
| scope=user owner=aaa environment=on-prem datacenter=chicago | scope=user owner=aaa environment=on-prem datacenter=new_york | ✅ | ❌ |
|
||||
| scope=organization owner= environment=on-prem | scope=organization owner= environment=on-prem | ❌ | ❌ |
|
||||
|-------------------------------------------------------------------|------------------------------------------------------------------|----------|--------------|
|
||||
| scope=organization owner= | scope=organization owner= | ✅ | ✅ |
|
||||
| scope=organization owner= environment=on-prem | scope=organization owner= environment=on-prem | ✅ | ✅ |
|
||||
| scope=organization owner= environment=on-prem datacenter=chicago | scope=organization owner= environment=on-prem | ✅ | ✅ |
|
||||
| scope=organization owner= environment=on-prem datacenter=chicago | scope=organization owner= environment=on-prem datacenter=chicago | ✅ | ✅ |
|
||||
| scope=user owner=aaa | scope=user owner=aaa | ✅ | ✅ |
|
||||
| scope=user owner=aaa environment=on-prem | scope=user owner=aaa | ✅ | ✅ |
|
||||
| scope=user owner=aaa environment=on-prem | scope=user owner=aaa environment=on-prem | ✅ | ✅ |
|
||||
| scope=user owner=aaa environment=on-prem datacenter=chicago | scope=user owner=aaa environment=on-prem | ✅ | ✅ |
|
||||
| scope=user owner=aaa environment=on-prem datacenter=chicago | scope=user owner=aaa environment=on-prem datacenter=chicago | ✅ | ✅ |
|
||||
| scope=organization owner= | scope=organization owner= environment=on-prem | ✅ | ❌ |
|
||||
| scope=organization owner= environment=on-prem | scope=organization owner= | ✅ | ❌ |
|
||||
| scope=organization owner= environment=on-prem | scope=organization owner= environment=on-prem datacenter=chicago | ✅ | ❌ |
|
||||
| scope=organization owner= environment=on-prem datacenter=new_york | scope=organization owner= environment=on-prem datacenter=chicago | ✅ | ❌ |
|
||||
| scope=user owner=aaa | scope=organization owner= | ✅ | ❌ |
|
||||
| scope=user owner=aaa | scope=user owner=bbb | ✅ | ❌ |
|
||||
| scope=organization owner= | scope=user owner=aaa | ✅ | ❌ |
|
||||
| scope=organization owner= | scope=user owner=aaa environment=on-prem | ✅ | ❌ |
|
||||
| scope=user owner=aaa | scope=user owner=aaa environment=on-prem | ✅ | ❌ |
|
||||
| scope=user owner=aaa environment=on-prem | scope=user owner=aaa environment=on-prem datacenter=chicago | ✅ | ❌ |
|
||||
| scope=user owner=aaa environment=on-prem datacenter=chicago | scope=user owner=aaa environment=on-prem datacenter=new_york | ✅ | ❌ |
|
||||
| scope=organization owner= environment=on-prem | scope=organization owner= environment=on-prem | ❌ | ❌ |
|
||||
|
||||
> **Note to maintainers:** to generate this table, run the following command and
|
||||
> copy the output:
|
||||
>
|
||||
> ```
|
||||
> ```go
|
||||
> go test -v -count=1 ./coderd/provisionerdserver/ -test.run='^TestAcquirer_MatchTags/GenTable$'
|
||||
> ```
|
||||
|
||||
|
||||
@@ -8,30 +8,30 @@ We track the following resources:
|
||||
|
||||
<!-- Code generated by 'make docs/admin/security/audit-logs.md'. DO NOT EDIT -->
|
||||
|
||||
| <b>Resource<b> | |
|
||||
| -------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
| APIKey<br><i>login, logout, register, create, delete</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>created_at</td><td>true</td></tr><tr><td>expires_at</td><td>true</td></tr><tr><td>hashed_secret</td><td>false</td></tr><tr><td>id</td><td>false</td></tr><tr><td>ip_address</td><td>false</td></tr><tr><td>last_used</td><td>true</td></tr><tr><td>lifetime_seconds</td><td>false</td></tr><tr><td>login_type</td><td>false</td></tr><tr><td>scope</td><td>false</td></tr><tr><td>token_name</td><td>false</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>user_id</td><td>true</td></tr></tbody></table> |
|
||||
| AuditOAuthConvertState<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>created_at</td><td>true</td></tr><tr><td>expires_at</td><td>true</td></tr><tr><td>from_login_type</td><td>true</td></tr><tr><td>to_login_type</td><td>true</td></tr><tr><td>user_id</td><td>true</td></tr></tbody></table> |
|
||||
| Group<br><i>create, write, delete</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>avatar_url</td><td>true</td></tr><tr><td>display_name</td><td>true</td></tr><tr><td>id</td><td>true</td></tr><tr><td>members</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>quota_allowance</td><td>true</td></tr><tr><td>source</td><td>false</td></tr></tbody></table> |
|
||||
| AuditableOrganizationMember<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>created_at</td><td>true</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>roles</td><td>true</td></tr><tr><td>updated_at</td><td>true</td></tr><tr><td>user_id</td><td>true</td></tr><tr><td>username</td><td>true</td></tr></tbody></table> |
|
||||
| CustomRole<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>created_at</td><td>false</td></tr><tr><td>display_name</td><td>true</td></tr><tr><td>id</td><td>false</td></tr><tr><td>name</td><td>true</td></tr><tr><td>org_permissions</td><td>true</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>site_permissions</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>user_permissions</td><td>true</td></tr></tbody></table> |
|
||||
| GitSSHKey<br><i>create</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>created_at</td><td>false</td></tr><tr><td>private_key</td><td>true</td></tr><tr><td>public_key</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>user_id</td><td>true</td></tr></tbody></table> |
|
||||
| GroupSyncSettings<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>auto_create_missing_groups</td><td>true</td></tr><tr><td>field</td><td>true</td></tr><tr><td>legacy_group_name_mapping</td><td>false</td></tr><tr><td>mapping</td><td>true</td></tr><tr><td>regex_filter</td><td>true</td></tr></tbody></table> |
|
||||
| HealthSettings<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>dismissed_healthchecks</td><td>true</td></tr><tr><td>id</td><td>false</td></tr></tbody></table> |
|
||||
| License<br><i>create, delete</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>exp</td><td>true</td></tr><tr><td>id</td><td>false</td></tr><tr><td>jwt</td><td>false</td></tr><tr><td>uploaded_at</td><td>true</td></tr><tr><td>uuid</td><td>true</td></tr></tbody></table> |
|
||||
| NotificationTemplate<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>actions</td><td>true</td></tr><tr><td>body_template</td><td>true</td></tr><tr><td>group</td><td>true</td></tr><tr><td>id</td><td>false</td></tr><tr><td>kind</td><td>true</td></tr><tr><td>method</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>title_template</td><td>true</td></tr></tbody></table> |
|
||||
| NotificationsSettings<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>id</td><td>false</td></tr><tr><td>notifier_paused</td><td>true</td></tr></tbody></table> |
|
||||
| OAuth2ProviderApp<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>callback_url</td><td>true</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>icon</td><td>true</td></tr><tr><td>id</td><td>false</td></tr><tr><td>name</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr></tbody></table> |
|
||||
| OAuth2ProviderAppSecret<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>app_id</td><td>false</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>display_secret</td><td>false</td></tr><tr><td>hashed_secret</td><td>false</td></tr><tr><td>id</td><td>false</td></tr><tr><td>last_used_at</td><td>false</td></tr><tr><td>secret_prefix</td><td>false</td></tr></tbody></table> |
|
||||
| Organization<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>created_at</td><td>false</td></tr><tr><td>description</td><td>true</td></tr><tr><td>display_name</td><td>true</td></tr><tr><td>icon</td><td>true</td></tr><tr><td>id</td><td>false</td></tr><tr><td>is_default</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>updated_at</td><td>true</td></tr></tbody></table> |
|
||||
| OrganizationSyncSettings<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>assign_default</td><td>true</td></tr><tr><td>field</td><td>true</td></tr><tr><td>mapping</td><td>true</td></tr></tbody></table> |
|
||||
| RoleSyncSettings<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>field</td><td>true</td></tr><tr><td>mapping</td><td>true</td></tr></tbody></table> |
|
||||
| Template<br><i>write, delete</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>active_version_id</td><td>true</td></tr><tr><td>activity_bump</td><td>true</td></tr><tr><td>allow_user_autostart</td><td>true</td></tr><tr><td>allow_user_autostop</td><td>true</td></tr><tr><td>allow_user_cancel_workspace_jobs</td><td>true</td></tr><tr><td>autostart_block_days_of_week</td><td>true</td></tr><tr><td>autostop_requirement_days_of_week</td><td>true</td></tr><tr><td>autostop_requirement_weeks</td><td>true</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>created_by</td><td>true</td></tr><tr><td>created_by_avatar_url</td><td>false</td></tr><tr><td>created_by_username</td><td>false</td></tr><tr><td>default_ttl</td><td>true</td></tr><tr><td>deleted</td><td>false</td></tr><tr><td>deprecated</td><td>true</td></tr><tr><td>description</td><td>true</td></tr><tr><td>display_name</td><td>true</td></tr><tr><td>failure_ttl</td><td>true</td></tr><tr><td>group_acl</td><td>true</td></tr><tr><td>icon</td><td>true</td></tr><tr><td>id</td><td>true</td></tr><tr><td>max_port_sharing_level</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>organization_display_name</td><td>false</td></tr><tr><td>organization_icon</td><td>false</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>organization_name</td><td>false</td></tr><tr><td>provisioner</td><td>true</td></tr><tr><td>require_active_version</td><td>true</td></tr><tr><td>time_til_dormant</td><td>true</td></tr><tr><td>time_til_dormant_autodelete</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>user_acl</td><td>true</td></tr></tbody></table> |
|
||||
| TemplateVersion<br><i>create, write</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>archived</td><td>true</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>created_by</td><td>true</td></tr><tr><td>created_by_avatar_url</td><td>false</td></tr><tr><td>created_by_username</td><td>false</td></tr><tr><td>external_auth_providers</td><td>false</td></tr><tr><td>id</td><td>true</td></tr><tr><td>job_id</td><td>false</td></tr><tr><td>message</td><td>false</td></tr><tr><td>name</td><td>true</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>readme</td><td>true</td></tr><tr><td>source_example_id</td><td>false</td></tr><tr><td>template_id</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr></tbody></table> |
|
||||
| User<br><i>create, write, delete</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>avatar_url</td><td>false</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>deleted</td><td>true</td></tr><tr><td>email</td><td>true</td></tr><tr><td>github_com_user_id</td><td>false</td></tr><tr><td>hashed_one_time_passcode</td><td>false</td></tr><tr><td>hashed_password</td><td>true</td></tr><tr><td>id</td><td>true</td></tr><tr><td>last_seen_at</td><td>false</td></tr><tr><td>login_type</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>one_time_passcode_expires_at</td><td>true</td></tr><tr><td>quiet_hours_schedule</td><td>true</td></tr><tr><td>rbac_roles</td><td>true</td></tr><tr><td>status</td><td>true</td></tr><tr><td>theme_preference</td><td>false</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>username</td><td>true</td></tr></tbody></table> |
|
||||
| WorkspaceBuild<br><i>start, stop</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>build_number</td><td>false</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>daily_cost</td><td>false</td></tr><tr><td>deadline</td><td>false</td></tr><tr><td>id</td><td>false</td></tr><tr><td>initiator_by_avatar_url</td><td>false</td></tr><tr><td>initiator_by_username</td><td>false</td></tr><tr><td>initiator_id</td><td>false</td></tr><tr><td>job_id</td><td>false</td></tr><tr><td>max_deadline</td><td>false</td></tr><tr><td>provisioner_state</td><td>false</td></tr><tr><td>reason</td><td>false</td></tr><tr><td>template_version_id</td><td>true</td></tr><tr><td>transition</td><td>false</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>workspace_id</td><td>false</td></tr></tbody></table> |
|
||||
| WorkspaceProxy<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>created_at</td><td>true</td></tr><tr><td>deleted</td><td>false</td></tr><tr><td>derp_enabled</td><td>true</td></tr><tr><td>derp_only</td><td>true</td></tr><tr><td>display_name</td><td>true</td></tr><tr><td>icon</td><td>true</td></tr><tr><td>id</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>region_id</td><td>true</td></tr><tr><td>token_hashed_secret</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>url</td><td>true</td></tr><tr><td>version</td><td>true</td></tr><tr><td>wildcard_hostname</td><td>true</td></tr></tbody></table> |
|
||||
| WorkspaceTable<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody><tr><td>automatic_updates</td><td>true</td></tr><tr><td>autostart_schedule</td><td>true</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>deleted</td><td>false</td></tr><tr><td>deleting_at</td><td>true</td></tr><tr><td>dormant_at</td><td>true</td></tr><tr><td>favorite</td><td>true</td></tr><tr><td>id</td><td>true</td></tr><tr><td>last_used_at</td><td>false</td></tr><tr><td>name</td><td>true</td></tr><tr><td>next_start_at</td><td>true</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>owner_id</td><td>true</td></tr><tr><td>template_id</td><td>true</td></tr><tr><td>ttl</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr></tbody></table> |
|
||||
| <b>Resource<b> | | |
|
||||
|----------------------------------------------------------|----------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| APIKey<br><i>login, logout, register, create, delete</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>created_at</td><td>true</td></tr><tr><td>expires_at</td><td>true</td></tr><tr><td>hashed_secret</td><td>false</td></tr><tr><td>id</td><td>false</td></tr><tr><td>ip_address</td><td>false</td></tr><tr><td>last_used</td><td>true</td></tr><tr><td>lifetime_seconds</td><td>false</td></tr><tr><td>login_type</td><td>false</td></tr><tr><td>scope</td><td>false</td></tr><tr><td>token_name</td><td>false</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>user_id</td><td>true</td></tr></tbody></table> |
|
||||
| AuditOAuthConvertState<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>created_at</td><td>true</td></tr><tr><td>expires_at</td><td>true</td></tr><tr><td>from_login_type</td><td>true</td></tr><tr><td>to_login_type</td><td>true</td></tr><tr><td>user_id</td><td>true</td></tr></tbody></table> |
|
||||
| Group<br><i>create, write, delete</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>avatar_url</td><td>true</td></tr><tr><td>display_name</td><td>true</td></tr><tr><td>id</td><td>true</td></tr><tr><td>members</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>quota_allowance</td><td>true</td></tr><tr><td>source</td><td>false</td></tr></tbody></table> |
|
||||
| AuditableOrganizationMember<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>created_at</td><td>true</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>roles</td><td>true</td></tr><tr><td>updated_at</td><td>true</td></tr><tr><td>user_id</td><td>true</td></tr><tr><td>username</td><td>true</td></tr></tbody></table> |
|
||||
| CustomRole<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>created_at</td><td>false</td></tr><tr><td>display_name</td><td>true</td></tr><tr><td>id</td><td>false</td></tr><tr><td>name</td><td>true</td></tr><tr><td>org_permissions</td><td>true</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>site_permissions</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>user_permissions</td><td>true</td></tr></tbody></table> |
|
||||
| GitSSHKey<br><i>create</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>created_at</td><td>false</td></tr><tr><td>private_key</td><td>true</td></tr><tr><td>public_key</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>user_id</td><td>true</td></tr></tbody></table> |
|
||||
| GroupSyncSettings<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>auto_create_missing_groups</td><td>true</td></tr><tr><td>field</td><td>true</td></tr><tr><td>legacy_group_name_mapping</td><td>false</td></tr><tr><td>mapping</td><td>true</td></tr><tr><td>regex_filter</td><td>true</td></tr></tbody></table> |
|
||||
| HealthSettings<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>dismissed_healthchecks</td><td>true</td></tr><tr><td>id</td><td>false</td></tr></tbody></table> |
|
||||
| License<br><i>create, delete</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>exp</td><td>true</td></tr><tr><td>id</td><td>false</td></tr><tr><td>jwt</td><td>false</td></tr><tr><td>uploaded_at</td><td>true</td></tr><tr><td>uuid</td><td>true</td></tr></tbody></table> |
|
||||
| NotificationTemplate<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>actions</td><td>true</td></tr><tr><td>body_template</td><td>true</td></tr><tr><td>group</td><td>true</td></tr><tr><td>id</td><td>false</td></tr><tr><td>kind</td><td>true</td></tr><tr><td>method</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>title_template</td><td>true</td></tr></tbody></table> |
|
||||
| NotificationsSettings<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>id</td><td>false</td></tr><tr><td>notifier_paused</td><td>true</td></tr></tbody></table> |
|
||||
| OAuth2ProviderApp<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>callback_url</td><td>true</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>icon</td><td>true</td></tr><tr><td>id</td><td>false</td></tr><tr><td>name</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr></tbody></table> |
|
||||
| OAuth2ProviderAppSecret<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>app_id</td><td>false</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>display_secret</td><td>false</td></tr><tr><td>hashed_secret</td><td>false</td></tr><tr><td>id</td><td>false</td></tr><tr><td>last_used_at</td><td>false</td></tr><tr><td>secret_prefix</td><td>false</td></tr></tbody></table> |
|
||||
| Organization<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>created_at</td><td>false</td></tr><tr><td>description</td><td>true</td></tr><tr><td>display_name</td><td>true</td></tr><tr><td>icon</td><td>true</td></tr><tr><td>id</td><td>false</td></tr><tr><td>is_default</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>updated_at</td><td>true</td></tr></tbody></table> |
|
||||
| OrganizationSyncSettings<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>assign_default</td><td>true</td></tr><tr><td>field</td><td>true</td></tr><tr><td>mapping</td><td>true</td></tr></tbody></table> |
|
||||
| RoleSyncSettings<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>field</td><td>true</td></tr><tr><td>mapping</td><td>true</td></tr></tbody></table> |
|
||||
| Template<br><i>write, delete</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>active_version_id</td><td>true</td></tr><tr><td>activity_bump</td><td>true</td></tr><tr><td>allow_user_autostart</td><td>true</td></tr><tr><td>allow_user_autostop</td><td>true</td></tr><tr><td>allow_user_cancel_workspace_jobs</td><td>true</td></tr><tr><td>autostart_block_days_of_week</td><td>true</td></tr><tr><td>autostop_requirement_days_of_week</td><td>true</td></tr><tr><td>autostop_requirement_weeks</td><td>true</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>created_by</td><td>true</td></tr><tr><td>created_by_avatar_url</td><td>false</td></tr><tr><td>created_by_username</td><td>false</td></tr><tr><td>default_ttl</td><td>true</td></tr><tr><td>deleted</td><td>false</td></tr><tr><td>deprecated</td><td>true</td></tr><tr><td>description</td><td>true</td></tr><tr><td>display_name</td><td>true</td></tr><tr><td>failure_ttl</td><td>true</td></tr><tr><td>group_acl</td><td>true</td></tr><tr><td>icon</td><td>true</td></tr><tr><td>id</td><td>true</td></tr><tr><td>max_port_sharing_level</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>organization_display_name</td><td>false</td></tr><tr><td>organization_icon</td><td>false</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>organization_name</td><td>false</td></tr><tr><td>provisioner</td><td>true</td></tr><tr><td>require_active_version</td><td>true</td></tr><tr><td>time_til_dormant</td><td>true</td></tr><tr><td>time_til_dormant_autodelete</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>user_acl</td><td>true</td></tr></tbody></table> |
|
||||
| TemplateVersion<br><i>create, write</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>archived</td><td>true</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>created_by</td><td>true</td></tr><tr><td>created_by_avatar_url</td><td>false</td></tr><tr><td>created_by_username</td><td>false</td></tr><tr><td>external_auth_providers</td><td>false</td></tr><tr><td>id</td><td>true</td></tr><tr><td>job_id</td><td>false</td></tr><tr><td>message</td><td>false</td></tr><tr><td>name</td><td>true</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>readme</td><td>true</td></tr><tr><td>source_example_id</td><td>false</td></tr><tr><td>template_id</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr></tbody></table> |
|
||||
| User<br><i>create, write, delete</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>avatar_url</td><td>false</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>deleted</td><td>true</td></tr><tr><td>email</td><td>true</td></tr><tr><td>github_com_user_id</td><td>false</td></tr><tr><td>hashed_one_time_passcode</td><td>false</td></tr><tr><td>hashed_password</td><td>true</td></tr><tr><td>id</td><td>true</td></tr><tr><td>last_seen_at</td><td>false</td></tr><tr><td>login_type</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>one_time_passcode_expires_at</td><td>true</td></tr><tr><td>quiet_hours_schedule</td><td>true</td></tr><tr><td>rbac_roles</td><td>true</td></tr><tr><td>status</td><td>true</td></tr><tr><td>theme_preference</td><td>false</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>username</td><td>true</td></tr></tbody></table> |
|
||||
| WorkspaceBuild<br><i>start, stop</i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>build_number</td><td>false</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>daily_cost</td><td>false</td></tr><tr><td>deadline</td><td>false</td></tr><tr><td>id</td><td>false</td></tr><tr><td>initiator_by_avatar_url</td><td>false</td></tr><tr><td>initiator_by_username</td><td>false</td></tr><tr><td>initiator_id</td><td>false</td></tr><tr><td>job_id</td><td>false</td></tr><tr><td>max_deadline</td><td>false</td></tr><tr><td>provisioner_state</td><td>false</td></tr><tr><td>reason</td><td>false</td></tr><tr><td>template_version_id</td><td>true</td></tr><tr><td>transition</td><td>false</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>workspace_id</td><td>false</td></tr></tbody></table> |
|
||||
| WorkspaceProxy<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>created_at</td><td>true</td></tr><tr><td>deleted</td><td>false</td></tr><tr><td>derp_enabled</td><td>true</td></tr><tr><td>derp_only</td><td>true</td></tr><tr><td>display_name</td><td>true</td></tr><tr><td>icon</td><td>true</td></tr><tr><td>id</td><td>true</td></tr><tr><td>name</td><td>true</td></tr><tr><td>region_id</td><td>true</td></tr><tr><td>token_hashed_secret</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr><tr><td>url</td><td>true</td></tr><tr><td>version</td><td>true</td></tr><tr><td>wildcard_hostname</td><td>true</td></tr></tbody></table> |
|
||||
| WorkspaceTable<br><i></i> | <table><thead><tr><th>Field</th><th>Tracked</th></tr></thead><tbody> | <tr><td>automatic_updates</td><td>true</td></tr><tr><td>autostart_schedule</td><td>true</td></tr><tr><td>created_at</td><td>false</td></tr><tr><td>deleted</td><td>false</td></tr><tr><td>deleting_at</td><td>true</td></tr><tr><td>dormant_at</td><td>true</td></tr><tr><td>favorite</td><td>true</td></tr><tr><td>id</td><td>true</td></tr><tr><td>last_used_at</td><td>false</td></tr><tr><td>name</td><td>true</td></tr><tr><td>next_start_at</td><td>true</td></tr><tr><td>organization_id</td><td>false</td></tr><tr><td>owner_id</td><td>true</td></tr><tr><td>template_id</td><td>true</td></tr><tr><td>ttl</td><td>true</td></tr><tr><td>updated_at</td><td>false</td></tr></tbody></table> |
|
||||
|
||||
<!-- End generated by 'make docs/admin/security/audit-logs.md'. -->
|
||||
|
||||
@@ -85,34 +85,34 @@ log entry:
|
||||
|
||||
```json
|
||||
{
|
||||
"ts": "2023-06-13T03:45:37.294730279Z",
|
||||
"level": "INFO",
|
||||
"msg": "audit_log",
|
||||
"caller": "/home/runner/work/coder/coder/enterprise/audit/backends/slog.go:36",
|
||||
"func": "github.com/coder/coder/enterprise/audit/backends.slogBackend.Export",
|
||||
"logger_names": ["coderd"],
|
||||
"fields": {
|
||||
"ID": "033a9ffa-b54d-4c10-8ec3-2aaf9e6d741a",
|
||||
"Time": "2023-06-13T03:45:37.288506Z",
|
||||
"UserID": "6c405053-27e3-484a-9ad7-bcb64e7bfde6",
|
||||
"OrganizationID": "00000000-0000-0000-0000-000000000000",
|
||||
"Ip": "{IPNet:{IP:\u003cnil\u003e Mask:\u003cnil\u003e} Valid:false}",
|
||||
"UserAgent": "{String: Valid:false}",
|
||||
"ResourceType": "workspace_build",
|
||||
"ResourceID": "ca5647e0-ef50-4202-a246-717e04447380",
|
||||
"ResourceTarget": "",
|
||||
"Action": "start",
|
||||
"Diff": {},
|
||||
"StatusCode": 200,
|
||||
"AdditionalFields": {
|
||||
"workspace_name": "linux-container",
|
||||
"build_number": "9",
|
||||
"build_reason": "initiator",
|
||||
"workspace_owner": ""
|
||||
},
|
||||
"RequestID": "bb791ac3-f6ee-4da8-8ec2-f54e87013e93",
|
||||
"ResourceIcon": ""
|
||||
}
|
||||
"ts": "2023-06-13T03:45:37.294730279Z",
|
||||
"level": "INFO",
|
||||
"msg": "audit_log",
|
||||
"caller": "/home/runner/work/coder/coder/enterprise/audit/backends/slog.go:36",
|
||||
"func": "github.com/coder/coder/enterprise/audit/backends.slogBackend.Export",
|
||||
"logger_names": ["coderd"],
|
||||
"fields": {
|
||||
"ID": "033a9ffa-b54d-4c10-8ec3-2aaf9e6d741a",
|
||||
"Time": "2023-06-13T03:45:37.288506Z",
|
||||
"UserID": "6c405053-27e3-484a-9ad7-bcb64e7bfde6",
|
||||
"OrganizationID": "00000000-0000-0000-0000-000000000000",
|
||||
"Ip": "{IPNet:{IP:\u003cnil\u003e Mask:\u003cnil\u003e} Valid:false}",
|
||||
"UserAgent": "{String: Valid:false}",
|
||||
"ResourceType": "workspace_build",
|
||||
"ResourceID": "ca5647e0-ef50-4202-a246-717e04447380",
|
||||
"ResourceTarget": "",
|
||||
"Action": "start",
|
||||
"Diff": {},
|
||||
"StatusCode": 200,
|
||||
"AdditionalFields": {
|
||||
"workspace_name": "linux-container",
|
||||
"build_number": "9",
|
||||
"build_reason": "initiator",
|
||||
"workspace_owner": ""
|
||||
},
|
||||
"RequestID": "bb791ac3-f6ee-4da8-8ec2-f54e87013e93",
|
||||
"ResourceIcon": ""
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
@@ -23,5 +23,5 @@ vulnerability.
|
||||
---
|
||||
|
||||
| Description | Severity | Fix | Vulnerable Versions |
|
||||
| --------------------------------------------------------------------------------------------------------------------------------------------- | -------- | -------------------------------------------------------------- | ------------------- |
|
||||
|-----------------------------------------------------------------------------------------------------------------------------------------------|----------|----------------------------------------------------------------|---------------------|
|
||||
| [API tokens of deleted users not invalidated](https://github.com/coder/coder/blob/main/docs/admin/security/0001_user_apikeys_invalidation.md) | HIGH | [v0.23.0](https://github.com/coder/coder/releases/tag/v0.23.0) | v0.8.25 - v0.22.2 |
|
||||
|
||||
@@ -9,7 +9,7 @@ This article explains how to use secrets in a workspace. To authenticate the
|
||||
workspace provisioner, see the
|
||||
<a href="../provisioners.md#authentication">provisioners documentation</a>.
|
||||
|
||||
## Wait a minute...
|
||||
## Before you begin
|
||||
|
||||
Your first attempt to use secrets with Coder should be your local method. You
|
||||
can do everything you can locally and more with your Coder workspace, so
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
There are a few ways to run Docker within container-based Coder workspaces.
|
||||
|
||||
| Method | Description | Limitations |
|
||||
| ---------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
|------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| [Sysbox container runtime](#sysbox-container-runtime) | Install the Sysbox runtime on your Kubernetes nodes or Docker host(s) for secure docker-in-docker and systemd-in-docker. Works with GKE, EKS, AKS, Docker. | Requires [compatible nodes](https://github.com/nestybox/sysbox#host-requirements). [Limitations](https://github.com/nestybox/sysbox/blob/master/docs/user-guide/limitations.md) |
|
||||
| [Envbox](#envbox) | A container image with all the packages necessary to run an inner Sysbox container. Removes the need to setup sysbox-runc on your nodes. Works with GKE, EKS, AKS. | Requires running the outer container as privileged (the inner container that acts as the workspace is locked down). Requires compatible [nodes](https://github.com/nestybox/sysbox/blob/master/docs/distro-compat.md#sysbox-distro-compatibility). |
|
||||
| [Rootless Podman](#rootless-podman) | Run Podman inside Coder workspaces. Does not require a custom runtime or privileged containers. Works with GKE, EKS, AKS, RKE, OpenShift | Requires smarter-device-manager for FUSE mounts. [See all](https://github.com/containers/podman/blob/main/rootless.md#shortcomings-of-rootless-podman) |
|
||||
|
||||
@@ -52,7 +52,7 @@ coder external-auth access-token <external-auth-id>
|
||||
Note: Some IDE's override the `GIT_ASKPASS` environment variable and need to be
|
||||
configured.
|
||||
|
||||
**VSCode**
|
||||
#### VSCode
|
||||
|
||||
Use the
|
||||
[Coder](https://marketplace.visualstudio.com/items?itemName=coder.coder-remote)
|
||||
|
||||
@@ -90,7 +90,7 @@ data "coder_parameter" "security_groups" {
|
||||
> For the above example, to override the default values of the `security_groups`
|
||||
> parameter, you will need to pass the following argument to `coder create`:
|
||||
>
|
||||
> ```
|
||||
> ```shell
|
||||
> --parameter "\"security_groups=[\"\"DevOps Security Group\"\",\"\"Backend Security Group\"\"]\""
|
||||
> ```
|
||||
>
|
||||
|
||||
@@ -254,28 +254,28 @@ The raw logs will look something like this:
|
||||
|
||||
```json
|
||||
{
|
||||
"ts": "2022-02-28T20:29:38.038452202Z",
|
||||
"level": "INFO",
|
||||
"msg": "exec",
|
||||
"fields": {
|
||||
"labels": {
|
||||
"user_email": "jessie@coder.com",
|
||||
"user_id": "5e876e9a-121663f01ebd1522060d5270",
|
||||
"username": "jessie",
|
||||
"workspace_id": "621d2e52-a6987ef6c56210058ee2593c",
|
||||
"workspace_name": "main"
|
||||
},
|
||||
"cmdline": "uname -a",
|
||||
"event": {
|
||||
"filename": "/usr/bin/uname",
|
||||
"argv": ["uname", "-a"],
|
||||
"truncated": false,
|
||||
"pid": 920684,
|
||||
"uid": 101000,
|
||||
"gid": 101000,
|
||||
"comm": "bash"
|
||||
}
|
||||
}
|
||||
"ts": "2022-02-28T20:29:38.038452202Z",
|
||||
"level": "INFO",
|
||||
"msg": "exec",
|
||||
"fields": {
|
||||
"labels": {
|
||||
"user_email": "jessie@coder.com",
|
||||
"user_id": "5e876e9a-121663f01ebd1522060d5270",
|
||||
"username": "jessie",
|
||||
"workspace_id": "621d2e52-a6987ef6c56210058ee2593c",
|
||||
"workspace_name": "main"
|
||||
},
|
||||
"cmdline": "uname -a",
|
||||
"event": {
|
||||
"filename": "/usr/bin/uname",
|
||||
"argv": ["uname", "-a"],
|
||||
"truncated": false,
|
||||
"pid": 920684,
|
||||
"uid": 101000,
|
||||
"gid": 101000,
|
||||
"comm": "bash"
|
||||
}
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
|
||||
@@ -53,15 +53,15 @@ variables, you can employ a straightforward solution:
|
||||
|
||||
1. Create a `terraform.tfvars` file in in the template directory:
|
||||
|
||||
```tf
|
||||
coder_image = newimage:tag
|
||||
```
|
||||
```tf
|
||||
coder_image = newimage:tag
|
||||
```
|
||||
|
||||
2. Push the new template revision using Coder CLI:
|
||||
1. Push the new template revision using Coder CLI:
|
||||
|
||||
```
|
||||
coder templates push my-template -y # no need to use --var
|
||||
```
|
||||
```shell
|
||||
coder templates push my-template -y # no need to use --var
|
||||
```
|
||||
|
||||
This file serves as a mechanism to override the template settings for variables.
|
||||
It can be stored in the repository for easy access and reference. Coder CLI
|
||||
|
||||
@@ -26,7 +26,7 @@ data "coder_workspace_tags" "custom_workspace_tags" {
|
||||
}
|
||||
```
|
||||
|
||||
**Legend**
|
||||
### Legend
|
||||
|
||||
- `zone` - static tag value set to `developers`
|
||||
- `runtime` - supported by the string-type `coder_parameter` to select
|
||||
@@ -55,7 +55,7 @@ raw values from the database and evaluates them using provided template
|
||||
variables and parameters. This is illustrated in the table below:
|
||||
|
||||
| Value Type | Template Import | Workspace Creation |
|
||||
| ---------- | -------------------------------------------------- | ----------------------- |
|
||||
|------------|----------------------------------------------------|-------------------------|
|
||||
| Static | `{"region": "us"}` | `{"region": "us"}` |
|
||||
| Variable | `{"az": var.az}` | `{"region": "us-east"}` |
|
||||
| Parameter | `{"cluster": data.coder_parameter.cluster.value }` | `{"cluster": "dev"}` |
|
||||
@@ -98,7 +98,7 @@ as immutable and set only once, during workspace creation.
|
||||
You may only specify the following as inputs for `coder_workspace_tags`:
|
||||
|
||||
| | Example |
|
||||
| :----------------- | :-------------------------------------------- |
|
||||
|:-------------------|:----------------------------------------------|
|
||||
| Static values | `"developers"` |
|
||||
| Template variables | `var.az` |
|
||||
| Coder parameters | `data.coder_parameter.runtime_selector.value` |
|
||||
@@ -115,7 +115,7 @@ raw queries on-the-fly without processing the entire Terraform template. This
|
||||
evaluation is simpler but also limited in terms of available functions,
|
||||
variables, and references to other resources.
|
||||
|
||||
**Supported syntax**
|
||||
#### Supported syntax
|
||||
|
||||
- Static string: `foobar_tag = "foobaz"`
|
||||
- Formatted string: `foobar_tag = "foobaz ${data.coder_parameter.foobaz.value}"`
|
||||
@@ -125,7 +125,7 @@ variables, and references to other resources.
|
||||
- Condition:
|
||||
`cache = data.coder_parameter.feature_cache_enabled.value == "true" ? "with-cache" : "no-cache"`
|
||||
|
||||
**Not supported**
|
||||
#### Not supported
|
||||
|
||||
- Function calls: `try(var.foo, "default")`
|
||||
- Resources: `compute_instance.dev.name`
|
||||
|
||||
@@ -121,7 +121,7 @@ their development environments:
|
||||
## Example templates
|
||||
|
||||
| Template | Description |
|
||||
| ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
|---------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| [Docker dev containers](https://github.com/coder/coder/tree/main/examples/templates/docker-devcontainer) | Docker provisions a development container. |
|
||||
| [Kubernetes dev containers](https://github.com/coder/coder/tree/main/examples/templates/kubernetes-devcontainer) | Provisions a development container on the Kubernetes cluster. |
|
||||
| [Google Compute Engine dev container](https://github.com/coder/coder/tree/main/examples/templates/gcp-devcontainer) | Runs a development container inside a single GCP instance. It also mounts the Docker socket from the VM inside the container to enable Docker inside the workspace. |
|
||||
@@ -144,7 +144,3 @@ Lifecycle scripts are managed by project developers.
|
||||
## Next steps
|
||||
|
||||
- [Dev container security and caching](./devcontainer-security-caching.md)
|
||||
|
||||
```
|
||||
|
||||
```
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
Ensure Envbuilder can only pull pre-approved images and artifacts by configuring
|
||||
it with your existing HTTP proxies, firewalls, and artifact managers.
|
||||
|
||||
### Configure registry authentication
|
||||
## Configure registry authentication
|
||||
|
||||
You may need to authenticate to your container registry, such as Artifactory, or
|
||||
Git provider such as GitLab, to use Envbuilder. See the
|
||||
|
||||
@@ -1,6 +1,6 @@
|
||||
## GitHub
|
||||
# GitHub
|
||||
|
||||
### Step 1: Configure the OAuth application in GitHub
|
||||
## Step 1: Configure the OAuth application in GitHub
|
||||
|
||||
First,
|
||||
[register a GitHub OAuth app](https://developer.github.com/apps/building-oauth-apps/creating-an-oauth-app/).
|
||||
@@ -22,7 +22,7 @@ values in the next step.
|
||||
Coder will need permission to access user email addresses. Find the "Account
|
||||
Permissions" settings for your app and select "read-only" for "Email addresses".
|
||||
|
||||
### Step 2: Configure Coder with the OAuth credentials
|
||||
## Step 2: Configure Coder with the OAuth credentials
|
||||
|
||||
Navigate to your Coder host and run the following command to start up the Coder
|
||||
server:
|
||||
|
||||
@@ -17,16 +17,16 @@ which templates developers can use. For example:
|
||||
Roles determine which actions users can take within the platform.
|
||||
|
||||
| | Auditor | User Admin | Template Admin | Owner |
|
||||
| --------------------------------------------------------------- | ------- | ---------- | -------------- | ----- |
|
||||
| Add and remove Users | | ✅ | | ✅ |
|
||||
| Manage groups (enterprise) (premium) | | ✅ | | ✅ |
|
||||
| Change User roles | | | | ✅ |
|
||||
| Manage **ALL** Templates | | | ✅ | ✅ |
|
||||
| View **ALL** Workspaces | | | ✅ | ✅ |
|
||||
| Update and delete **ALL** Workspaces | | | | ✅ |
|
||||
| Run [external provisioners](../provisioners.md) | | | ✅ | ✅ |
|
||||
| Execute and use **ALL** Workspaces | | | | ✅ |
|
||||
| View all user operation [Audit Logs](../security/audit-logs.md) | ✅ | | | ✅ |
|
||||
|-----------------------------------------------------------------|---------|------------|----------------|-------|
|
||||
| Add and remove Users | | ✅ | | ✅ |
|
||||
| Manage groups (enterprise) (premium) | | ✅ | | ✅ |
|
||||
| Change User roles | | | | ✅ |
|
||||
| Manage **ALL** Templates | | | ✅ | ✅ |
|
||||
| View **ALL** Workspaces | | | ✅ | ✅ |
|
||||
| Update and delete **ALL** Workspaces | | | | ✅ |
|
||||
| Run [external provisioners](../provisioners.md) | | | ✅ | ✅ |
|
||||
| Execute and use **ALL** Workspaces | | | | ✅ |
|
||||
| View all user operation [Audit Logs](../security/audit-logs.md) | ✅ | | | ✅ |
|
||||
|
||||
A user may have one or more roles. All users have an implicit Member role that
|
||||
may use personal workspaces.
|
||||
|
||||
@@ -1,3 +1,4 @@
|
||||
<!-- markdownlint-disable MD024 -->
|
||||
# IDP Sync
|
||||
|
||||
<blockquote class="info">
|
||||
@@ -7,6 +8,8 @@ IDP sync is an Enterprise and Premium feature.
|
||||
|
||||
</blockquote>
|
||||
|
||||
## Group Sync
|
||||
|
||||
If your OpenID Connect provider supports group claims, you can configure Coder
|
||||
to synchronize groups in your auth provider to groups within Coder. To enable
|
||||
group sync, ensure that the `groups` claim is being sent by your OpenID
|
||||
@@ -141,10 +144,10 @@ will be able to configure this in the UI. For now, you must use CLI commands.
|
||||
|
||||
```json
|
||||
{
|
||||
"field": "",
|
||||
"mapping": null,
|
||||
"regex_filter": null,
|
||||
"auto_create_missing_groups": false
|
||||
"field": "",
|
||||
"mapping": null,
|
||||
"regex_filter": null,
|
||||
"auto_create_missing_groups": false
|
||||
}
|
||||
```
|
||||
|
||||
@@ -153,10 +156,10 @@ Below is an example that uses the `groups` claim and maps all groups prefixed by
|
||||
|
||||
```json
|
||||
{
|
||||
"field": "groups",
|
||||
"mapping": null,
|
||||
"regex_filter": "^coder-.*$",
|
||||
"auto_create_missing_groups": true
|
||||
"field": "groups",
|
||||
"mapping": null,
|
||||
"regex_filter": "^coder-.*$",
|
||||
"auto_create_missing_groups": true
|
||||
}
|
||||
```
|
||||
|
||||
@@ -174,16 +177,16 @@ group:
|
||||
|
||||
```json
|
||||
{
|
||||
"field": "groups",
|
||||
"mapping": {
|
||||
"coder-admins": [
|
||||
"2ba2a4ff-ddfb-4493-b7cd-1aec2fa4c830",
|
||||
"93371154-150f-4b12-b5f0-261bb1326bb4"
|
||||
],
|
||||
"coder-users": ["2f4bde93-0179-4815-ba50-b757fb3d43dd"]
|
||||
},
|
||||
"regex_filter": null,
|
||||
"auto_create_missing_groups": false
|
||||
"field": "groups",
|
||||
"mapping": {
|
||||
"coder-admins": [
|
||||
"2ba2a4ff-ddfb-4493-b7cd-1aec2fa4c830",
|
||||
"93371154-150f-4b12-b5f0-261bb1326bb4"
|
||||
],
|
||||
"coder-users": ["2f4bde93-0179-4815-ba50-b757fb3d43dd"]
|
||||
},
|
||||
"regex_filter": null,
|
||||
"auto_create_missing_groups": false
|
||||
}
|
||||
```
|
||||
|
||||
@@ -209,7 +212,7 @@ Users who are not in a matching group will see the following error:
|
||||
|
||||
<Image height="412px" src="../../images/admin/group-allowlist.png" alt="Unauthorized group error" align="center" />
|
||||
|
||||
## Role sync
|
||||
## Role Sync
|
||||
|
||||
<blockquote class="info">
|
||||
|
||||
@@ -307,8 +310,8 @@ will be able to configure this in the UI. For now, you must use CLI commands.
|
||||
|
||||
```json
|
||||
{
|
||||
"field": "",
|
||||
"mapping": null
|
||||
"field": "",
|
||||
"mapping": null
|
||||
}
|
||||
```
|
||||
|
||||
@@ -318,11 +321,11 @@ role:
|
||||
|
||||
```json
|
||||
{
|
||||
"field": "roles",
|
||||
"mapping": {
|
||||
"coder-admins": ["organization-admin"],
|
||||
"infra-admins": ["provisioner-admin"]
|
||||
}
|
||||
"field": "roles",
|
||||
"mapping": {
|
||||
"coder-admins": ["organization-admin"],
|
||||
"infra-admins": ["provisioner-admin"]
|
||||
}
|
||||
}
|
||||
```
|
||||
|
||||
@@ -372,7 +375,7 @@ dashboard:
|
||||
|
||||
<div class="tabs">
|
||||
|
||||
### Dashboard
|
||||
## Dashboard
|
||||
|
||||
1. Confirm that your OIDC provider is sending claims. Log in with OIDC and visit
|
||||
the following URL with an `Owner` account:
|
||||
@@ -412,7 +415,7 @@ dashboard:
|
||||
|
||||

|
||||
|
||||
### CLI
|
||||
## CLI
|
||||
|
||||
Use the Coder CLI to show and adjust the settings.
|
||||
|
||||
@@ -455,7 +458,7 @@ settings, a user's memberships will update when they log out and log back in.
|
||||
Analyzing the JSON payload:
|
||||
|
||||
| Field | Explanation |
|
||||
| :-------------------------- | :-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
|
||||
|:----------------------------|:----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|
||||
| field | If this field is the empty string `""`, then org-sync is disabled. </br> Org memberships must be manually configured through the UI or API. |
|
||||
| mapping | Mapping takes a claim from the IdP, and associates it with 1 or more organizations by UUID. </br> No validation is done, so you can put UUID's of orgs that do not exist (a noop). The UI picker will allow selecting orgs from a drop down, and convert it to a UUID for you. |
|
||||
| organization_assign_default | This setting exists for maintaining backwards compatibility with single org deployments, either through their upgrade, or in perpetuity. </br> If this is set to 'true', all users will always be assigned to the default organization regardless of the mappings and their IdP claims. |
|
||||
|
||||
@@ -76,7 +76,7 @@ the sum of their allowances.
|
||||
For example:
|
||||
|
||||
| Group Name | Quota Allowance |
|
||||
| ---------- | --------------- |
|
||||
|------------|-----------------|
|
||||
| Frontend | 10 |
|
||||
| Backend | 20 |
|
||||
| Data | 30 |
|
||||
@@ -84,7 +84,7 @@ For example:
|
||||
<br/>
|
||||
|
||||
| Username | Groups | Effective Budget |
|
||||
| -------- | ----------------- | ---------------- |
|
||||
|----------|-------------------|------------------|
|
||||
| jill | Frontend, Backend | 30 |
|
||||
| jack | Backend, Data | 50 |
|
||||
| sam | Data | 30 |
|
||||
|
||||
Reference in New Issue
Block a user