You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the JFrog (OAuth) module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
17 / 17
20 / 20
14 / 20
10 / 10
91 / 100
Drilldown
Presentation & Onboarding — 17 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
Multiple major modes documented with examples: full package-manager config (main example), access-token-only mode (dedicated section + example), code-server configuration (dedicated example), and individual package-manager examples (pnpm, pip). Each shows sensible defaults and usage.
Visual preview
5
5
README embeds ; file verified to exist at 47.9 KB.
Credential Hygiene — 20 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
output "access_token" is marked sensitive = true. No module input accepts a raw secret. README module-usage examples contain no inline secrets; the admin setup block uses clearly-marked placeholders (YYYYYYYYYYYYYYY, XXXXXXXXXXXXXXXXXXX) for Coder deployment config, not module inputs.
Non-hardcoded auth path
4
4
Module uses Coder external-auth (data.coder_external_auth.jfrog). README explicitly states "no API keys or passwords are stored in the template or the workspace" and documents the full OAuth flow setup.
Restricted-Environment Readiness — 14 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
The JFrog CLI download URL https://install-cli.jfrog.io is hardcoded in run.sh (curl -fL https://install-cli.jfrog.io | sudo sh). No module input variable overrides this URL. jfrog_url is the Artifactory instance URL, not the CLI installer URL. No variable exists to point the download at an internal mirror.
Bring-your-own binary
10
10
install_jfrog_cli = false is documented in the README ("If jf is already on the PATH … set install_jfrog_cli = false to disable the download explicitly"). run.sh checks command -v jf and skips installation when disabled. A REQUIRE_CLI guard fails with a clear error if the CLI is needed but absent.
Egress transparency
3
3
Dedicated "### External endpoints" subsection under "Offline and air-gapped environments" enumerates both endpoints: https://install-cli.jfrog.io (conditional) and the user's jfrog_url (runtime). Includes guidance for air-gapped use.
Runs without sudo
2
1
run.sh invokes sudo sh and sudo chmod 755 during CLI installation. However, this is gated behind install_jfrog_cli = true (an optional feature) and the README documents the no-sudo path: "pre-install jf in your workspace image to avoid both the external download and the sudo step." Core functionality (package-manager config) writes only to $HOME and needs no root. Sudo for optional feature with working fallback → half.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All 9 variables have description blocks. jfrog_url has regex validation (must start with http/https). username_field has regex validation (email|username). package_managers has a multi-line description with examples and a cross-field validation ensuring npm/pnpm repo lists match. Sensible defaults throughout.
Test coverage
4
4
jfrog-oauth.tftest.hcl contains 16 test runs covering: required vars, empty-token edge case, URL/username validation failures, all 7 package managers (npm, pnpm, go, pypi, docker, conda, maven), combined npm+pnpm, mismatched-repo validation, code-server mode, and access-token-only mode. Tests assert on script content, env resources, and resource counts.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the JFrog (OAuth) module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 17 / 17
; file verified to exist at 47.9 KB.Credential Hygiene — 20 / 20
output "access_token"is markedsensitive = true. No module input accepts a raw secret. README module-usage examples contain no inline secrets; the admin setup block uses clearly-marked placeholders (YYYYYYYYYYYYYYY,XXXXXXXXXXXXXXXXXXX) for Coder deployment config, not module inputs.external-auth(data.coder_external_auth.jfrog). README explicitly states "no API keys or passwords are stored in the template or the workspace" and documents the full OAuth flow setup.Restricted-Environment Readiness — 14 / 20
https://install-cli.jfrog.iois hardcoded inrun.sh(curl -fL https://install-cli.jfrog.io | sudo sh). No module input variable overrides this URL.jfrog_urlis the Artifactory instance URL, not the CLI installer URL. No variable exists to point the download at an internal mirror.install_jfrog_cli = falseis documented in the README ("Ifjfis already on thePATH… setinstall_jfrog_cli = falseto disable the download explicitly").run.shcheckscommand -v jfand skips installation when disabled. AREQUIRE_CLIguard fails with a clear error if the CLI is needed but absent.https://install-cli.jfrog.io(conditional) and the user'sjfrog_url(runtime). Includes guidance for air-gapped use.run.shinvokessudo shandsudo chmod 755during CLI installation. However, this is gated behindinstall_jfrog_cli = true(an optional feature) and the README documents the no-sudo path: "pre-installjfin your workspace image to avoid both the external download and thesudostep." Core functionality (package-manager config) writes only to$HOMEand needs no root. Sudo for optional feature with working fallback → half.Engineering Quality — 10 / 10
descriptionblocks.jfrog_urlhas regex validation (must start with http/https).username_fieldhas regex validation (email|username).package_managershas a multi-line description with examples and a cross-field validation ensuring npm/pnpm repo lists match. Sensible defaults throughout.jfrog-oauth.tftest.hclcontains 16 test runs covering: required vars, empty-token edge case, URL/username validation failures, all 7 package managers (npm, pnpm, go, pypi, docker, conda, maven), combined npm+pnpm, mismatched-repo validation, code-server mode, and access-token-only mode. Tests assert on script content, env resources, and resource counts.Overall — 91 / 100
Raw 61 / 67 → round(61 / 67 × 100) = 91
Utility module: Raw 61 / 75 → round(61 / 75 × 100) = 81
Scored against SCORECARD.md on 2026-10-06 with
solstice-1.All reactions