You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the VS Code Desktop module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
IDE Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
12 / 17
13 / 19
16 / 20
3.5 / 20
10 / 10
63 / 100
Drilldown
Presentation & Onboarding — 12 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
README documents default launch, folder example, and extensions pre-install example, each with sensible defaults and clear explanation of behavior (e.g. 30-minute install-block window).
Visual preview
5
0
No image, GIF, or video embedded in README — only text and code blocks.
Credential Hygiene — 16 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
Module has no secret-bearing inputs; session token is handled automatically by the provider and never appears as a literal/placeholder value in any example.
Non-hardcoded auth path
4
0
README does not describe or document any auth mechanism (e.g. how the session token is obtained/used) as a non-hardcoded credential path.
Restricted-Environment Readiness — 3.5 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
install-remote-server.sh.tftpl hardcodes https://update.code.visualstudio.com/... for both the update API and archive download; no module variable overrides this URL.
Bring-your-own binary
10
0
The script skips re-download only if code-server binary is already executable at a fixed cache path — this is incidental caching behavior, not a documented, user-facing way to disable install when the tool is baked into the image.
Egress transparency
3
1.5
Extensions example mentions "HTTPS egress to the VS Code update and artifact hosts" but this is a vague note inside a config example, not a dedicated network/offline section, and no actual domains are enumerated.
Runs without sudo
2
2
install-remote-server.sh.tftpl never invokes sudo; all paths are under $HOME.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All variables (agent_id, folder, open_recent, order, group, extensions) have clear descriptions and sensible defaults; extensions has a validation block rejecting empty entries.
Test coverage
4
4
main.tftest.hcl covers defaults, extension variable acceptance, and validation failure; main.test.ts covers end-to-end coder_app output, URL construction across flag combinations, and extension-install script behavior including idempotent re-run.
IDE Integration — 13 / 19 (Pre-installed extensions marked N/A — desktop IDE, not web-based)
Criterion
Max
Score
Notes
Dashboard entry point
7
7
Uses vscode-desktop-core module to create a coder_app with icon, slug, display name, order, and group — documented via the module composition.
Managed configuration
6
0
config_dir = "$HOME/.vscode" is hardcoded internally in main.tf and never exposed as a variable or documented as a configurable/managed setting path.
Configurable folder or workdir
6
6
folder variable documented with a dedicated "Open in a specific directory" example.
Pre-installed extensions (web IDEs only)
6
N/A
VS Code Desktop is a native desktop app launched via vscode:// protocol, not a web IDE — criterion excluded from denominator.
Overall — 63 / 100
Raw 54.5 / 86 → round(54.5 / 86 × 100) = 63
Scored against SCORECARD.md on 2026-10-05 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the VS Code Desktop module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 12 / 17
folderexample, andextensionspre-install example, each with sensible defaults and clear explanation of behavior (e.g. 30-minute install-block window).Credential Hygiene — 16 / 20
Restricted-Environment Readiness — 3.5 / 20
install-remote-server.sh.tftplhardcodeshttps://update.code.visualstudio.com/...for both the update API and archive download; no module variable overrides this URL.code-serverbinary is already executable at a fixed cache path — this is incidental caching behavior, not a documented, user-facing way to disable install when the tool is baked into the image.install-remote-server.sh.tftplnever invokessudo; all paths are under$HOME.Engineering Quality — 10 / 10
agent_id,folder,open_recent,order,group,extensions) have clear descriptions and sensible defaults;extensionshas avalidationblock rejecting empty entries.main.tftest.hclcovers defaults, extension variable acceptance, and validation failure;main.test.tscovers end-to-endcoder_appoutput, URL construction across flag combinations, and extension-install script behavior including idempotent re-run.IDE Integration — 13 / 19 (Pre-installed extensions marked N/A — desktop IDE, not web-based)
vscode-desktop-coremodule to create acoder_appwith icon, slug, display name, order, and group — documented via the module composition.config_dir = "$HOME/.vscode"is hardcoded internally inmain.tfand never exposed as a variable or documented as a configurable/managed setting path.foldervariable documented with a dedicated "Open in a specific directory" example.vscode://protocol, not a web IDE — criterion excluded from denominator.Overall — 63 / 100
Raw 54.5 / 86 → round(54.5 / 86 × 100) = 63
Scored against SCORECARD.md on 2026-10-05 with
solstice-1.All reactions