Current Behavior
The claude-code module creates configuration files when managed_settings or api_key_helper is configured, but leaves those files behind when the corresponding input is later set to null.
On workspaces where these files survive a restart, Claude Code can therefore continue using settings or an authentication helper that was removed from the template. Users have to manually delete the generated files for the change to take effect.
Affected files:
/etc/claude-code/managed-settings.d/10-coder.json
/etc/claude-code/managed-settings.d/20-coder-apikeyhelper.json
~/.claude/coder-api-key-helper.sh
Steps to Reproduce
- Start a workspace with
managed_settings configured.
- Update the template to set
managed_settings = null.
- Apply the updated template and restart the workspace, preserving
/etc/claude-code.
- Check
managed-settings.d/10-coder.json: it still contains the previous settings.
The same issue occurs when configuring api_key_helper and subsequently setting it to null, preserving both /etc/claude-code and the user's home directory.
Expected Behavior
Disabling either input should remove the corresponding files created by the module, while preserving unrelated Claude Code configuration.
Currently, write_managed_settings() and setup_api_key_helper() return immediately when their input is empty, without cleaning up files from a previous run.
Current Behavior
The
claude-codemodule creates configuration files whenmanaged_settingsorapi_key_helperis configured, but leaves those files behind when the corresponding input is later set tonull.On workspaces where these files survive a restart, Claude Code can therefore continue using settings or an authentication helper that was removed from the template. Users have to manually delete the generated files for the change to take effect.
Affected files:
/etc/claude-code/managed-settings.d/10-coder.json/etc/claude-code/managed-settings.d/20-coder-apikeyhelper.json~/.claude/coder-api-key-helper.shSteps to Reproduce
managed_settingsconfigured.managed_settings = null./etc/claude-code.managed-settings.d/10-coder.json: it still contains the previous settings.The same issue occurs when configuring
api_key_helperand subsequently setting it tonull, preserving both/etc/claude-codeand the user's home directory.Expected Behavior
Disabling either input should remove the corresponding files created by the module, while preserving unrelated Claude Code configuration.
Currently,
write_managed_settings()andsetup_api_key_helper()return immediately when their input is empty, without cleaning up files from a previous run.