You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the Portable Desktop module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
12 / 17
16 / 16
11 / 20
7 / 10
73 / 100
Drilldown
Presentation & Onboarding — 12 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
README documents three modes: default (no options), custom url + sha256, and install_dir. The module has only three optional inputs, and each major configuration path is shown with a complete HCL example.
Visual preview
5
0
No image, GIF, or video is embedded in the README. The frontmatter icon field references an SVG file but is not a visual preview of the module in action.
Credential Hygiene — 16 / 16
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
No inputs are secrets. agent_id, url, sha256, and install_dir are all non-sensitive configuration values. README examples contain no inline secrets or placeholder keys.
Non-hardcoded auth path
4
N/A
The module performs no authentication. It downloads a public binary from GitHub releases or a user-supplied URL. No API keys, tokens, or auth mechanisms exist by construction.
Restricted-Environment Readiness — 11 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
5
The url variable (main.tf) directly overrides the download URL used in the install script (ARG_AMD64_URL / ARG_ARM64_URL). README shows a concrete example pointing to https://example.com/portabledesktop-linux-x64.
Bring-your-own binary
10
5
run.sh checks command -v portabledesktop and [ -x "${BINARY_PATH}" ] to skip download if the binary is already present. However, this behavior is not documented in the README—no section or example explains how to pre-bake the binary into an image to skip installation.
Egress transparency
3
0
No dedicated README section enumerates external endpoints (GitHub releases API, custom URL) or provides guidance for restricted/air-gapped environments. Endpoint URLs appear only inline in examples.
Runs without sudo
2
1
Core install (download to CODER_SCRIPT_DATA_DIR, symlink to CODER_SCRIPT_BIN_DIR) requires no root. sudo is invoked only in the optional install_dir copy block (sudo mkdir -p, sudo cp), with a working non-root fallback (binary remains available via the symlink). Sudo for an optional feature with a functional fallback earns half.
Engineering Quality — 7 / 10
Criterion
Max
Score
Notes
Input quality
6
3
All four variables have clear descriptions and sensible null defaults. However, no validation blocks are present: sha256 could validate a 64-char hex string, url could validate a URL format, and install_dir could enforce an absolute path.
Test coverage
4
4
portabledesktop.tftest.hcl provides basic plan-level assertions (3 runs). main.test.ts delivers thorough end-to-end coverage: successful install, checksum pass/fail, skip-when-already-installed, sudo fallback, directory creation, and wget fallback—each executed in a real container against a fake HTTP server. Clear testing story with appropriate separation of concerns.
Overall — 73 / 100
Raw 46 / 63 → round(46 / 63 × 100) = 73
Track: Utility (desktop session binary installer; not an AI coding agent or IDE)
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the Portable Desktop module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 12 / 17
url+sha256, andinstall_dir. The module has only three optional inputs, and each major configuration path is shown with a complete HCL example.iconfield references an SVG file but is not a visual preview of the module in action.Credential Hygiene — 16 / 16
agent_id,url,sha256, andinstall_dirare all non-sensitive configuration values. README examples contain no inline secrets or placeholder keys.Restricted-Environment Readiness — 11 / 20
urlvariable (main.tf) directly overrides the download URL used in the install script (ARG_AMD64_URL/ARG_ARM64_URL). README shows a concrete example pointing tohttps://example.com/portabledesktop-linux-x64.run.shcheckscommand -v portabledesktopand[ -x "${BINARY_PATH}" ]to skip download if the binary is already present. However, this behavior is not documented in the README—no section or example explains how to pre-bake the binary into an image to skip installation.CODER_SCRIPT_DATA_DIR, symlink toCODER_SCRIPT_BIN_DIR) requires no root.sudois invoked only in the optionalinstall_dircopy block (sudo mkdir -p,sudo cp), with a working non-root fallback (binary remains available via the symlink). Sudo for an optional feature with a functional fallback earns half.Engineering Quality — 7 / 10
nulldefaults. However, novalidationblocks are present:sha256could validate a 64-char hex string,urlcould validate a URL format, andinstall_dircould enforce an absolute path.portabledesktop.tftest.hclprovides basic plan-level assertions (3 runs).main.test.tsdelivers thorough end-to-end coverage: successful install, checksum pass/fail, skip-when-already-installed, sudo fallback, directory creation, and wget fallback—each executed in a real container against a fake HTTP server. Clear testing story with appropriate separation of concerns.Overall — 73 / 100
Raw 46 / 63 → round(46 / 63 × 100) = 73
Track: Utility (desktop session binary installer; not an AI coding agent or IDE)
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions