Closes [DOCS-256](https://linear.app/coder/issue/DOCS-256). Sibling to [DOCS-253](https://linear.app/coder/issue/DOCS-253) (#25740). Updates docs URL references across the non-TypeScript surface of `coder/coder` to match the current docs site structure. Source-of-truth for redirects is `coder/coder.com/redirects.json` (parent ticket [DOCS-209](https://linear.app/coder/issue/DOCS-209)). ## What changed | Area | Files | URL mapping | |---|---|---| | Top-level README | `README.md` | `/docs/workspaces` -> `/docs/user-guides/workspace-management`, `/docs/templates` -> `/docs/admin/templates`, `/docs/ides` -> `/docs/user-guides/workspace-access` | | Docs source | `docs/admin/security/0001_user_apikeys_invalidation.md` | `/docs/admin/audit-logs` -> `/docs/admin/security/audit-logs` | | Docs source | `docs/install/cloud/azure-vm.md` | `/docs/coder-oss/latest/install` -> `/docs/install` | | Dogfood | `dogfood/coder/guide.md` | `/docs/ides` -> `/docs/user-guides/workspace-access` | | Helm | `helm/coder/values.yaml` | `/docs/admin/workspace-proxies` -> `/docs/admin/networking/workspace-proxies` | | Enterprise coderd | `enterprise/coderd/coderd.go` | `/docs/admin/encryption` -> `/docs/admin/security/database-encryption` (error message) | | Release tooling | `scripts/release/main_internal_test.go` | `/docs/admin/upgrade` -> `/docs/install/upgrade` (test fixture, matches `generate_release_notes.sh`) | | AI bridge | `aibridge/client.go` | repinned to current `main` SHA on renamed `docs/ai-coder/ai-gateway/monitoring.md`, line range `#L47-L57` | | Example templates | 12 `examples/templates/*/README.md`, `examples/parameters/*`, `examples/parameters-dynamic-options/README.md`, `examples/workspace-tags/README.md`, `examples/parameters/main.tf`, `examples/examples.gen.json` (regenerated) | `/docs/workspaces` -> `/docs/user-guides/workspace-management`, `/docs/templates/parameters` -> `/docs/admin/templates/extending-templates/parameters`, `/docs/templates/dev-containers` -> `/docs/admin/integrations/devcontainers`, `/docs/dotfiles` -> `/docs/user-guides/workspace-dotfiles`, `/docs/about/architecture#agents` -> `/docs/admin/infrastructure/architecture#agents` | | Live notification templates (DB) | New migration `000510_fix_dormancy_notification_docs_urls.up.sql` and `.down.sql` plus the four regenerated SMTP/webhook goldens under `coderd/notifications/testdata/rendered-templates/` | `/docs/templates/schedule#dormancy-threshold-enterprise` -> `/docs/admin/templates/managing-templates/schedule#dormancy-threshold`, `/docs/templates/schedule#dormancy-auto-deletion-enterprise` -> `/docs/admin/templates/managing-templates/schedule#dormancy-auto-deletion` | The migration uses `REPLACE(body_template, ...)` scoped by template id and `LIKE '%/docs/templates/schedule%'`, so it works regardless of which intermediate state (`000232`, `000262`, `000305`, or `000311`) is currently in the row. ## What did not change Historical SQL migrations `000232`, `000262`, `000305`, and `000311` are not modified because migrations are immutable history. The 18 remaining stale URL references in those files are superseded at runtime by migration `000510`. This decision matches the pattern used in the A1 sister PR (#25740). ## Verification - `go test ./coderd/database/migrations/... -count=1` (UP+DOWN) - `go test ./coderd/notifications/ -run TestNotificationTemplates_Golden -update -count=1` to regenerate the four `.golden` files - `go test ./scripts/release/ -run Test_removeMainlineBlurb -count=1` - `make pre-commit` (gen + fmt + lint + slim build) ran clean as part of the commit hook I also fixed a pre-existing emdash on line 35 of `examples/templates/azure-linux/README.md` that the lint flagged once the file entered my diff. The line was already in `main`, but `make gen` rewrites `examples/examples.gen.json` whenever a `README.md` changes, so the line came back as a `+` in the diff against `origin/main` and the `lint/emdash` step refused it. <details> <summary>Pre-mortem</summary> | Risk | Mitigation | |---|---| | Migration overwrites future template edits | Used `REPLACE` instead of full body overwrite. `WHERE id IN (...) AND body_template LIKE '%/docs/templates/schedule%'` further scopes the write | | Goldens drift from migrated body | Regenerated goldens via `-update` after the migration was in place, so the goldens reflect the post-migration state | | Down migration leaves stale URLs | Down migration reverses the REPLACE so a rollback restores the prior URLs | | Fragment loss when redirect strips fragment | Verified the destination `schedule.md` contains `## Dormancy threshold` and `## Dormancy auto-deletion` anchors | | Terraform parse breakage in `examples/parameters/main.tf` | Only comments changed; Terraform parser is unaffected | | Test fixtures in `scripts/release` diverging from `generate_release_notes.sh` | Updated to match the script, which already emits `/docs/install/upgrade` | </details> --- Generated by Coder Agent on behalf of @nickvigilante.
display_name, description, icon, maintainer_github, verified, tags
| display_name | description | icon | maintainer_github | verified | tags | |||
|---|---|---|---|---|---|---|---|---|
| Kubernetes (Envbox) | Provision envbox pods as Coder workspaces | ../../../site/static/icon/k8s.png | coder | true |
|
envbox
Introduction
envbox is an image that enables creating non-privileged containers capable of running system-level software (e.g. dockerd, systemd, etc) in Kubernetes.
It mainly acts as a wrapper for the excellent sysbox runtime developed by Nestybox. For more details on the security of sysbox containers see sysbox's official documentation.
Envbox Configuration
The following environment variables can be used to configure various aspects of the inner and outer container.
| env | usage | required |
|---|---|---|
CODER_INNER_IMAGE |
The image to use for the inner container. | True |
CODER_INNER_USERNAME |
The username to use for the inner container. | True |
CODER_AGENT_TOKEN |
The Coder Agent token to pass to the inner container. | True |
CODER_INNER_ENVS |
The environment variables to pass to the inner container. A wildcard can be used to match a prefix. Ex: CODER_INNER_ENVS=KUBERNETES_*,MY_ENV,MY_OTHER_ENV |
false |
CODER_INNER_HOSTNAME |
The hostname to use for the inner container. | false |
CODER_IMAGE_PULL_SECRET |
The docker credentials to use when pulling the inner container. The recommended way to do this is to create an Image Pull Secret and then reference the secret using an environment variable. | false |
CODER_DOCKER_BRIDGE_CIDR |
The bridge CIDR to start the Docker daemon with. | false |
CODER_MOUNTS |
A list of mounts to mount into the inner container. Mounts default to rw. Ex: CODER_MOUNTS=/home/coder:/home/coder,/var/run/mysecret:/var/run/mysecret:ro |
false |
CODER_USR_LIB_DIR |
The mountpoint of the host /usr/lib directory. Only required when using GPUs. |
false |
CODER_ADD_TUN |
If CODER_ADD_TUN=true add a TUN device to the inner container. |
false |
CODER_ADD_FUSE |
If CODER_ADD_FUSE=true add a FUSE device to the inner container. |
false |
CODER_ADD_GPU |
If CODER_ADD_GPU=true add detected GPUs and related files to the inner container. Requires setting CODER_USR_LIB_DIR and mounting in the hosts /usr/lib/ directory. |
false |
CODER_CPUS |
Dictates the number of CPUs to allocate the inner container. It is recommended to set this using the Kubernetes Downward API. | false |
CODER_MEMORY |
Dictates the max memory (in bytes) to allocate the inner container. It is recommended to set this using the Kubernetes Downward API. | false |
Migrating Existing Envbox Templates
Due to the deprecation and removal of legacy parameters it may be necessary to migrate existing envbox templates on newer versions of Coder. Consult the migration documentation for details on how to do so.
To supply values to existing existing Terraform variables you can specify the
-V flag. For example
coder templates push envbox --var namespace="mynamespace" --var max_cpus=2 --var min_cpus=1 --var max_memory=4 --var min_memory=1
Version Pinning
The template sets the image tag as latest. We highly recommend pinning the image to a specific release of envbox, as the latest tag may change.
Contributions
Contributions are welcome and can be made against the envbox repo.