mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
Closes [DOCS-256](https://linear.app/coder/issue/DOCS-256). Sibling to [DOCS-253](https://linear.app/coder/issue/DOCS-253) (#25740). Updates docs URL references across the non-TypeScript surface of `coder/coder` to match the current docs site structure. Source-of-truth for redirects is `coder/coder.com/redirects.json` (parent ticket [DOCS-209](https://linear.app/coder/issue/DOCS-209)). ## What changed | Area | Files | URL mapping | |---|---|---| | Top-level README | `README.md` | `/docs/workspaces` -> `/docs/user-guides/workspace-management`, `/docs/templates` -> `/docs/admin/templates`, `/docs/ides` -> `/docs/user-guides/workspace-access` | | Docs source | `docs/admin/security/0001_user_apikeys_invalidation.md` | `/docs/admin/audit-logs` -> `/docs/admin/security/audit-logs` | | Docs source | `docs/install/cloud/azure-vm.md` | `/docs/coder-oss/latest/install` -> `/docs/install` | | Dogfood | `dogfood/coder/guide.md` | `/docs/ides` -> `/docs/user-guides/workspace-access` | | Helm | `helm/coder/values.yaml` | `/docs/admin/workspace-proxies` -> `/docs/admin/networking/workspace-proxies` | | Enterprise coderd | `enterprise/coderd/coderd.go` | `/docs/admin/encryption` -> `/docs/admin/security/database-encryption` (error message) | | Release tooling | `scripts/release/main_internal_test.go` | `/docs/admin/upgrade` -> `/docs/install/upgrade` (test fixture, matches `generate_release_notes.sh`) | | AI bridge | `aibridge/client.go` | repinned to current `main` SHA on renamed `docs/ai-coder/ai-gateway/monitoring.md`, line range `#L47-L57` | | Example templates | 12 `examples/templates/*/README.md`, `examples/parameters/*`, `examples/parameters-dynamic-options/README.md`, `examples/workspace-tags/README.md`, `examples/parameters/main.tf`, `examples/examples.gen.json` (regenerated) | `/docs/workspaces` -> `/docs/user-guides/workspace-management`, `/docs/templates/parameters` -> `/docs/admin/templates/extending-templates/parameters`, `/docs/templates/dev-containers` -> `/docs/admin/integrations/devcontainers`, `/docs/dotfiles` -> `/docs/user-guides/workspace-dotfiles`, `/docs/about/architecture#agents` -> `/docs/admin/infrastructure/architecture#agents` | | Live notification templates (DB) | New migration `000510_fix_dormancy_notification_docs_urls.up.sql` and `.down.sql` plus the four regenerated SMTP/webhook goldens under `coderd/notifications/testdata/rendered-templates/` | `/docs/templates/schedule#dormancy-threshold-enterprise` -> `/docs/admin/templates/managing-templates/schedule#dormancy-threshold`, `/docs/templates/schedule#dormancy-auto-deletion-enterprise` -> `/docs/admin/templates/managing-templates/schedule#dormancy-auto-deletion` | The migration uses `REPLACE(body_template, ...)` scoped by template id and `LIKE '%/docs/templates/schedule%'`, so it works regardless of which intermediate state (`000232`, `000262`, `000305`, or `000311`) is currently in the row. ## What did not change Historical SQL migrations `000232`, `000262`, `000305`, and `000311` are not modified because migrations are immutable history. The 18 remaining stale URL references in those files are superseded at runtime by migration `000510`. This decision matches the pattern used in the A1 sister PR (#25740). ## Verification - `go test ./coderd/database/migrations/... -count=1` (UP+DOWN) - `go test ./coderd/notifications/ -run TestNotificationTemplates_Golden -update -count=1` to regenerate the four `.golden` files - `go test ./scripts/release/ -run Test_removeMainlineBlurb -count=1` - `make pre-commit` (gen + fmt + lint + slim build) ran clean as part of the commit hook I also fixed a pre-existing emdash on line 35 of `examples/templates/azure-linux/README.md` that the lint flagged once the file entered my diff. The line was already in `main`, but `make gen` rewrites `examples/examples.gen.json` whenever a `README.md` changes, so the line came back as a `+` in the diff against `origin/main` and the `lint/emdash` step refused it. <details> <summary>Pre-mortem</summary> | Risk | Mitigation | |---|---| | Migration overwrites future template edits | Used `REPLACE` instead of full body overwrite. `WHERE id IN (...) AND body_template LIKE '%/docs/templates/schedule%'` further scopes the write | | Goldens drift from migrated body | Regenerated goldens via `-update` after the migration was in place, so the goldens reflect the post-migration state | | Down migration leaves stale URLs | Down migration reverses the REPLACE so a rollback restores the prior URLs | | Fragment loss when redirect strips fragment | Verified the destination `schedule.md` contains `## Dormancy threshold` and `## Dormancy auto-deletion` anchors | | Terraform parse breakage in `examples/parameters/main.tf` | Only comments changed; Terraform parser is unaffected | | Test fixtures in `scripts/release` diverging from `generate_release_notes.sh` | Updated to match the script, which already emits `/docs/install/upgrade` | </details> --- Generated by Coder Agent on behalf of @nickvigilante.
95 lines
3.0 KiB
Markdown
95 lines
3.0 KiB
Markdown
---
|
|
display_name: AWS EC2 (Linux)
|
|
description: Provision AWS EC2 VMs as Coder workspaces
|
|
icon: ../../../site/static/icon/aws.svg
|
|
maintainer_github: coder
|
|
verified: true
|
|
tags: [vm, linux, aws, persistent-vm]
|
|
---
|
|
|
|
# Remote Development on AWS EC2 VMs (Linux)
|
|
|
|
Provision AWS EC2 VMs as [Coder workspaces](https://coder.com/docs/user-guides/workspace-management) with this example template.
|
|
|
|
## Prerequisites
|
|
|
|
### Authentication
|
|
|
|
By default, this template authenticates to AWS using the provider's default [authentication methods](https://registry.terraform.io/providers/hashicorp/aws/latest/docs#authentication-and-configuration).
|
|
|
|
The simplest way (without making changes to the template) is via environment variables (e.g. `AWS_ACCESS_KEY_ID`) or a [credentials file](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-files.html#cli-configure-files-format). If you are running Coder on a VM, this file must be in `/home/coder/aws/credentials`.
|
|
|
|
To use another [authentication method](https://registry.terraform.io/providers/hashicorp/aws/latest/docs#authentication), edit the template.
|
|
|
|
## Required permissions / policy
|
|
|
|
The following sample policy allows Coder to create EC2 instances and modify
|
|
instances provisioned by Coder:
|
|
|
|
```json
|
|
{
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Sid": "VisualEditor0",
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"ec2:GetDefaultCreditSpecification",
|
|
"ec2:DescribeIamInstanceProfileAssociations",
|
|
"ec2:DescribeTags",
|
|
"ec2:DescribeInstances",
|
|
"ec2:DescribeInstanceTypes",
|
|
"ec2:DescribeInstanceStatus",
|
|
"ec2:CreateTags",
|
|
"ec2:RunInstances",
|
|
"ec2:DescribeInstanceCreditSpecifications",
|
|
"ec2:DescribeImages",
|
|
"ec2:ModifyDefaultCreditSpecification",
|
|
"ec2:DescribeVolumes"
|
|
],
|
|
"Resource": "*"
|
|
},
|
|
{
|
|
"Sid": "CoderResources",
|
|
"Effect": "Allow",
|
|
"Action": [
|
|
"ec2:DescribeInstanceAttribute",
|
|
"ec2:UnmonitorInstances",
|
|
"ec2:TerminateInstances",
|
|
"ec2:StartInstances",
|
|
"ec2:StopInstances",
|
|
"ec2:DeleteTags",
|
|
"ec2:MonitorInstances",
|
|
"ec2:CreateTags",
|
|
"ec2:RunInstances",
|
|
"ec2:ModifyInstanceAttribute",
|
|
"ec2:ModifyInstanceCreditSpecification"
|
|
],
|
|
"Resource": "arn:aws:ec2:*:*:instance/*",
|
|
"Condition": {
|
|
"StringEquals": {
|
|
"aws:ResourceTag/Coder_Provisioned": "true"
|
|
}
|
|
}
|
|
}
|
|
]
|
|
}
|
|
```
|
|
|
|
## Architecture
|
|
|
|
This template provisions the following resources:
|
|
|
|
- AWS Instance
|
|
|
|
Coder uses `aws_ec2_instance_state` to start and stop the VM. This example template is fully persistent, meaning the full filesystem is preserved when the workspace restarts. See this [community example](https://github.com/bpmct/coder-templates/tree/main/aws-linux-ephemeral) of an ephemeral AWS instance.
|
|
|
|
> **Note**
|
|
> This template is designed to be a starting point! Edit the Terraform to extend the template to support your use case.
|
|
|
|
## code-server
|
|
|
|
`code-server` is installed via the `startup_script` argument in the `coder_agent`
|
|
resource block. The `coder_app` resource is defined to access `code-server` through
|
|
the dashboard UI over `localhost:13337`.
|