You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the KasmVNC module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
6 / 17
20 / 20
5 / 20
8 / 10
58 / 100
Drilldown
Track: Utility (VNC remote desktop server — not an AI agent, not an IDE/editor)
Presentation & Onboarding — 6 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
6
README shows a single example (desktop_environment = "xfce", subdomain = true). The module has two major access modes (subdomain vs. path-based via subdomain = false, which triggers a different file-patching code path in run.sh) and eight desktop-environment options, but no additional examples or documentation of the non-subdomain mode.
Visual preview
5
0
No image, GIF, or video embedded in the README. The frontmatter references an SVG icon, which does not count.
Credential Hygiene — 20 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
No sensitive inputs exist in this module (no API keys, tokens, or passwords are user-supplied). The VNC password in run.sh is a placeholder explicitly noted as unused ("This password is not used since we start the server without auth"). README examples contain no inline secrets.
Non-hardcoded auth path
4
4
Authentication is handled entirely by Coder's session-token tunnel; the VNC server binds to 127.0.0.1 and is protected by the Coder app proxy. No raw keys are pasted into templates.
Restricted-Environment Readiness — 5 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
The download URL is hardcoded in run.sh as https://github.com/kasmtech/KasmVNC/releases/download/v${KASM_VERSION}. No module input variable overrides this base URL. kasm_version only pins the version, not the source.
Bring-your-own binary
10
5
run.sh includes a check_installed() guard that skips installation if kasmvncserver is already on PATH. However, this behaviour is not documented in the README; a user would have to read the script to discover it.
Egress transparency
3
0
No dedicated README section enumerates external endpoints. The only outbound call (GitHub releases) is visible only in run.sh source.
Runs without sudo
2
0
When KasmVNC is not pre-installed, the script explicitly requires sudo and exits with "ERROR: sudo NOPASSWD access required!". Installation is core functionality, not an optional feature.
Engineering Quality — 8 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All eight variables carry description blocks. desktop_environment and share include validation with clear error messages. Defaults are sensible (port = 6800, kasm_version = "1.4.0", subdomain = true).
Test coverage
4
2
main.test.ts exercises runTerraformApply across five desktop environments and validates required variables. No .tftest.hcl file exists. No tests cover the subdomain vs. path-based mode, share levels, custom ports, or version pinning.
Overall — 58 / 100
Raw 39 / 67 → round(39 / 67 × 100) = 58
Scored against SCORECARD.md on 2026-10-05 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the KasmVNC module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Track: Utility (VNC remote desktop server — not an AI agent, not an IDE/editor)
Presentation & Onboarding — 6 / 17
desktop_environment = "xfce",subdomain = true). The module has two major access modes (subdomain vs. path-based viasubdomain = false, which triggers a different file-patching code path inrun.sh) and eight desktop-environment options, but no additional examples or documentation of the non-subdomain mode.Credential Hygiene — 20 / 20
run.shis a placeholder explicitly noted as unused ("This password is not used since we start the server without auth"). README examples contain no inline secrets.127.0.0.1and is protected by the Coder app proxy. No raw keys are pasted into templates.Restricted-Environment Readiness — 5 / 20
run.shashttps://github.com/kasmtech/KasmVNC/releases/download/v${KASM_VERSION}. No module input variable overrides this base URL.kasm_versiononly pins the version, not the source.run.shincludes acheck_installed()guard that skips installation ifkasmvncserveris already onPATH. However, this behaviour is not documented in the README; a user would have to read the script to discover it.run.shsource.sudoand exits with"ERROR: sudo NOPASSWD access required!". Installation is core functionality, not an optional feature.Engineering Quality — 8 / 10
descriptionblocks.desktop_environmentandshareincludevalidationwith clear error messages. Defaults are sensible (port = 6800,kasm_version = "1.4.0",subdomain = true).main.test.tsexercisesrunTerraformApplyacross five desktop environments and validates required variables. No.tftest.hclfile exists. No tests cover the subdomain vs. path-based mode, share levels, custom ports, or version pinning.Overall — 58 / 100
Raw 39 / 67 → round(39 / 67 × 100) = 58
Scored against SCORECARD.md on 2026-10-05 with
solstice-1.All reactions