Skip to content

feat(registry/coder-labs): add pi module for the Pi coding agent CLI - #1140

Merged
nickvigilante merged 4 commits into
mainfrom
add-pi-module
Oct 1, 2026
Merged

nickvigilante merged 4 commits into
mainfrom
add-pi-module

Conversation

@nickvigilante

@nickvigilante nickvigilante commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Adds a new coder-labs/pi module that installs and configures the Pi coding agent CLI in a Coder workspace, following the same install-only pattern as the codex and claude-code modules (install/auth via coder-utils, starting the CLI is left to the caller).

Changes

  • New module registry/coder-labs/modules/pi: installs Pi via npm install -g @earendil-works/pi-coding-agent into a user-owned prefix (with version pinning), wires ANTHROPIC_API_KEY / OPENAI_API_KEY / GEMINI_API_KEY plus an extra_env map for other supported providers, writes defaultProjectTrust into ~/.pi/agent/settings.json, and supports optional workdir pre-creation and pre_install_script/post_install_script hooks.
  • enable_ai_gateway routes Pi's anthropic and openai providers through Coder AI Gateway with the owner's session token.
    Pi ignores ANTHROPIC_BASE_URL, so the gateway endpoints are written as baseUrl overrides in ~/.pi/agent/models.json (other keys preserved).
  • npm_registry_url installs from an internal npm mirror; pi_binary_path points install_pi = false at a preinstalled binary outside PATH.
  • README covers auth paths (AI Gateway, /login, sensitive variables), Agent Firewall, session continuity (pi --continue + tmux), managed configuration, and a network access / air-gapped section; adds a preview image (registry/coder-labs/.images/pi.png, from Pi's MIT-licensed docs).
  • Adds the official Pi logo at .icons/pi.svg (sourced from pi.dev/logo-auto.svg).
  • Ignores the local .worktrees/ directory used for isolated branch work.

Testing

  • terraform test: 18/18 passing
  • bun test registry/coder-labs/modules/pi (Docker): 16/16 passing, including real npm installs with and without npm_registry_url
  • shellcheck on the rendered install script, bun x prettier --check, terraform fmt -check, go run ./cmd/readmevalidation: clean
  • Verified manually against Pi 0.87.1 and a mock HTTP server that a models.json baseUrl override sends Anthropic requests to <base>/v1/messages with X-Api-Key and OpenAI requests to <base>/v1/responses with a bearer token, both of which AI Gateway accepts.

Notes


🤖 Generated by Coder Agents on behalf of @nickvigilante.

@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Module Scorecard Check

coder-labs/pi: first scorecard, 100 / 100

No specific score is required to contribute, but modules with higher scores are more likely to be approved by the Coder team and widely used.

Full scorecard for this PR
Presentation & Onboarding Agent Integration Credential Hygiene Restricted-Environment Readiness Engineering Quality Overall
17 / 17 25 / 25 20 / 20 20 / 20 10 / 10 100 / 100
Drilldown

Presentation & Onboarding — 17 / 17

Criterion Max Score Notes
Configuration-mode examples 12 12 README documents interactive /login, provider API keys, AI Gateway, Agent Firewall, dashboard coder_app, tmux session continuity, bring-your-own-binary, and multi-provider extra_env — each with a complete module "pi" {...} example and sensible defaults.
Visual preview 5 5 ![Pi interactive mode in a terminal](../../.images/pi.png) embedded near the top; file verified to exist (506.9 KB).

Credential Hygiene — 20 / 20

Criterion Max Score Notes
Secrets marked sensitive 16 16 anthropic_api_key, openai_api_key, gemini_api_key, extra_env are all sensitive = true in main.tf. README examples reference var.anthropic_api_key (a declared sensitive variable) rather than inline literals; tests assert API keys never land in the rendered install script.
Non-hardcoded auth path 4 4 README's "Authentication" table ranks AI Gateway and interactive /login above raw provider keys, with dedicated sections explaining each.

Restricted-Environment Readiness — 20 / 20

Criterion Max Score Notes
Mirrorable artifact source 5 5 The npm_registry_url variable overrides the registry npm install -g --registry "$ARG_NPM_REGISTRY_URL" pulls @earendil-works/pi-coding-agent from (see install.sh.tftpl); README documents pointing it at Artifactory/Nexus.
Bring-your-own binary 10 10 install_pi = false + pi_binary_path fully skips npm; "Bring your own Pi binary" section documents this with a working example and notes the script only validates pi --version.
Egress transparency 3 3 Dedicated "Network access and air-gapped environments" section with a table enumerating exact endpoints (npm registry, AI Gateway path, provider APIs, pi.dev, github.com for fd/ripgrep) plus air-gapped mitigation notes (mirror, PI_OFFLINE=1, Agent Firewall).
Runs without sudo 2 2 install.sh.tftpl never invokes sudo; npm install deliberately uses a user-owned prefix (~/.coder-modules/.../npm-global) specifically to avoid needing a writable global npm prefix, confirmed by code and by the "Prerequisites" section and a dedicated test (install-does-not-require-writable-global-npm-prefix).

Engineering Quality — 10 / 10

Criterion Max Score Notes
Input quality 6 6 All variables have descriptions and defaults; validation blocks enforce npm_registry_url format, pi_binary_path absolute path + mutual exclusivity with install_pi, default_project_trust enum, and AI Gateway/API-key mutual exclusivity.
Test coverage 4 4 main.tftest.hcl covers business logic (defaults, env-var creation, mutual exclusivity, script ordering, AI Gateway URL derivation). main.test.ts runs real containerized end-to-end checks (npm install without root prefix, models.json/settings.json merging, workdir creation, binary-path fallback, pre/post scripts).

Agent Integration — 25 / 25

Criterion Max Score Notes
AI governance 10 10 Both AI Gateway (enable_ai_gateway, routes to <access_url>/api/v2/ai-gateway/..., session-token auth) and Agent Firewall (wrapper example with agent_firewall_wrapper_path/agent_firewall_config_path) are documented with specifics on auth, routing, and policy enforcement.
Dashboard entry point 5 5 "Dashboard entry point" section gives a full resource "coder_app" "pi" example with open_in = "slim-window" and a launch command.
Session continuity 5 5 Documents native pi --continue/pi --resume session persistence under ~/.pi/agent/sessions/, plus a tmux-wrapped coder_app example (tmux new-session -A -s pi 'pi --continue') for surviving reconnects.
Managed configuration 5 5 "Managed configuration" section documents module-managed settings.json (defaultProjectTrust) and models.json (providers.*.baseUrl) keys, plus workdir pre-creation, with a table of what's controlled by which variable.

Overall — 100 / 100

Raw 92 / 92 → round(92 / 92 × 100) = 100

Tip

You can run this locally by telling your agent: "review this module against .github/scorecard/SCORECARD.md".


Scored against SCORECARD.md with solstice-1. Language-model scores are advisory.

Installs and configures the Pi (pi.dev) coding agent CLI, following the
same install-only pattern as the codex and claude-code modules: the
module installs and authenticates the CLI via coder-utils, and leaves
starting it to the caller (template command, IDE launcher, or a
custom coder_script).

Also ignores the local .worktrees/ directory used for isolated
branch work.

Assisted-by: AI
CI failed because codercom/enterprise-node:latest sets npm's default
global prefix to /usr, which is root-owned, so `npm install -g` fails
with EACCES for the unprivileged workspace user. Install into a
prefix under the module's own coder-modules data directory instead,
so the install never depends on npm's default global prefix being
writable.

Also fixes the "npm missing" test, which silently no-op'd (mv lacked
permission on the root-owned npm binary) and masked this failure, and
adds a regression test for the EACCES scenario.

Assisted-by: AI
…port to pi

Address the module scorecard gaps on the pi module:

- enable_ai_gateway routes Pi's anthropic and openai providers through
  Coder AI Gateway. Pi ignores ANTHROPIC_BASE_URL, so the gateway
  endpoints are written as baseUrl overrides in ~/.pi/agent/models.json.
- npm_registry_url installs from an internal npm mirror.
- pi_binary_path points at a preinstalled binary outside PATH.
- README documents AI governance, session continuity with
  pi --continue and tmux, managed configuration, egress endpoints, and
  uses sensitive variables instead of inline secrets.

@Katarinya Katarinya left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LTGM. Had Coder agents review it additionally last week, but dogfood died.
Either way, still good!

@nickvigilante
nickvigilante merged commit c91a9a0 into main Oct 1, 2026
5 checks passed
@nickvigilante
nickvigilante deleted the add-pi-module branch October 1, 2026 20:09
nickvigilante added a commit to coder/coder that referenced this pull request Oct 1, 2026
## Summary

Adds the official [Pi](https://pi.dev/) coding agent logo as a static
icon, served at `/icon/pi.svg`, for use by the new `coder-labs/pi` Coder
Registry module (coder/registry#1140).

## Changes

- Adds `site/static/icon/pi.svg`, sourced from `pi.dev/logo-auto.svg`.

## Testing

- Visual diff of the SVG only; no application code paths changed.

---
🤖 Built with AI assistance.

---------

Co-authored-by: Coder Agents <noreply@coder.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants