feat(registry/coder-labs): add pi module for the Pi coding agent CLI - #1140
Merged
Merged
Conversation
Contributor
Module Scorecard Check
|
| Presentation & Onboarding | Agent Integration | Credential Hygiene | Restricted-Environment Readiness | Engineering Quality | Overall |
|---|---|---|---|---|---|
| 17 / 17 | 25 / 25 | 20 / 20 | 20 / 20 | 10 / 10 | 100 / 100 |
Drilldown
Presentation & Onboarding — 17 / 17
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Configuration-mode examples | 12 | 12 | README documents interactive /login, provider API keys, AI Gateway, Agent Firewall, dashboard coder_app, tmux session continuity, bring-your-own-binary, and multi-provider extra_env — each with a complete module "pi" {...} example and sensible defaults. |
| Visual preview | 5 | 5 |  embedded near the top; file verified to exist (506.9 KB). |
Credential Hygiene — 20 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Secrets marked sensitive | 16 | 16 | anthropic_api_key, openai_api_key, gemini_api_key, extra_env are all sensitive = true in main.tf. README examples reference var.anthropic_api_key (a declared sensitive variable) rather than inline literals; tests assert API keys never land in the rendered install script. |
| Non-hardcoded auth path | 4 | 4 | README's "Authentication" table ranks AI Gateway and interactive /login above raw provider keys, with dedicated sections explaining each. |
Restricted-Environment Readiness — 20 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Mirrorable artifact source | 5 | 5 | The npm_registry_url variable overrides the registry npm install -g --registry "$ARG_NPM_REGISTRY_URL" pulls @earendil-works/pi-coding-agent from (see install.sh.tftpl); README documents pointing it at Artifactory/Nexus. |
| Bring-your-own binary | 10 | 10 | install_pi = false + pi_binary_path fully skips npm; "Bring your own Pi binary" section documents this with a working example and notes the script only validates pi --version. |
| Egress transparency | 3 | 3 | Dedicated "Network access and air-gapped environments" section with a table enumerating exact endpoints (npm registry, AI Gateway path, provider APIs, pi.dev, github.com for fd/ripgrep) plus air-gapped mitigation notes (mirror, PI_OFFLINE=1, Agent Firewall). |
| Runs without sudo | 2 | 2 | install.sh.tftpl never invokes sudo; npm install deliberately uses a user-owned prefix (~/.coder-modules/.../npm-global) specifically to avoid needing a writable global npm prefix, confirmed by code and by the "Prerequisites" section and a dedicated test (install-does-not-require-writable-global-npm-prefix). |
Engineering Quality — 10 / 10
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Input quality | 6 | 6 | All variables have descriptions and defaults; validation blocks enforce npm_registry_url format, pi_binary_path absolute path + mutual exclusivity with install_pi, default_project_trust enum, and AI Gateway/API-key mutual exclusivity. |
| Test coverage | 4 | 4 | main.tftest.hcl covers business logic (defaults, env-var creation, mutual exclusivity, script ordering, AI Gateway URL derivation). main.test.ts runs real containerized end-to-end checks (npm install without root prefix, models.json/settings.json merging, workdir creation, binary-path fallback, pre/post scripts). |
Agent Integration — 25 / 25
| Criterion | Max | Score | Notes |
|---|---|---|---|
| AI governance | 10 | 10 | Both AI Gateway (enable_ai_gateway, routes to <access_url>/api/v2/ai-gateway/..., session-token auth) and Agent Firewall (wrapper example with agent_firewall_wrapper_path/agent_firewall_config_path) are documented with specifics on auth, routing, and policy enforcement. |
| Dashboard entry point | 5 | 5 | "Dashboard entry point" section gives a full resource "coder_app" "pi" example with open_in = "slim-window" and a launch command. |
| Session continuity | 5 | 5 | Documents native pi --continue/pi --resume session persistence under ~/.pi/agent/sessions/, plus a tmux-wrapped coder_app example (tmux new-session -A -s pi 'pi --continue') for surviving reconnects. |
| Managed configuration | 5 | 5 | "Managed configuration" section documents module-managed settings.json (defaultProjectTrust) and models.json (providers.*.baseUrl) keys, plus workdir pre-creation, with a table of what's controlled by which variable. |
Overall — 100 / 100
Raw 92 / 92 → round(92 / 92 × 100) = 100
Tip
You can run this locally by telling your agent: "review this module against .github/scorecard/SCORECARD.md".
Scored against SCORECARD.md with solstice-1. Language-model scores are advisory.
nickvigilante
requested review from
DevelopmentCats,
Katarinya and
phorcys420
September 28, 2026 23:23
Installs and configures the Pi (pi.dev) coding agent CLI, following the same install-only pattern as the codex and claude-code modules: the module installs and authenticates the CLI via coder-utils, and leaves starting it to the caller (template command, IDE launcher, or a custom coder_script). Also ignores the local .worktrees/ directory used for isolated branch work. Assisted-by: AI
CI failed because codercom/enterprise-node:latest sets npm's default global prefix to /usr, which is root-owned, so `npm install -g` fails with EACCES for the unprivileged workspace user. Install into a prefix under the module's own coder-modules data directory instead, so the install never depends on npm's default global prefix being writable. Also fixes the "npm missing" test, which silently no-op'd (mv lacked permission on the root-owned npm binary) and masked this failure, and adds a regression test for the EACCES scenario. Assisted-by: AI
…port to pi Address the module scorecard gaps on the pi module: - enable_ai_gateway routes Pi's anthropic and openai providers through Coder AI Gateway. Pi ignores ANTHROPIC_BASE_URL, so the gateway endpoints are written as baseUrl overrides in ~/.pi/agent/models.json. - npm_registry_url installs from an internal npm mirror. - pi_binary_path points at a preinstalled binary outside PATH. - README documents AI governance, session continuity with pi --continue and tmux, managed configuration, egress endpoints, and uses sensitive variables instead of inline secrets.
… container removal
nickvigilante
force-pushed
the
add-pi-module
branch
from
October 1, 2026 16:49
f9981ef to
558d249
Compare
Katarinya
approved these changes
Oct 1, 2026
Katarinya
left a comment
There was a problem hiding this comment.
LTGM. Had Coder agents review it additionally last week, but dogfood died.
Either way, still good!
nickvigilante
added a commit
to coder/coder
that referenced
this pull request
Oct 1, 2026
## Summary Adds the official [Pi](https://pi.dev/) coding agent logo as a static icon, served at `/icon/pi.svg`, for use by the new `coder-labs/pi` Coder Registry module (coder/registry#1140). ## Changes - Adds `site/static/icon/pi.svg`, sourced from `pi.dev/logo-auto.svg`. ## Testing - Visual diff of the SVG only; no application code paths changed. --- 🤖 Built with AI assistance. --------- Co-authored-by: Coder Agents <noreply@coder.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a new
coder-labs/pimodule that installs and configures the Pi coding agent CLI in a Coder workspace, following the same install-only pattern as thecodexandclaude-codemodules (install/auth viacoder-utils, starting the CLI is left to the caller).Changes
registry/coder-labs/modules/pi: installs Pi vianpm install -g @earendil-works/pi-coding-agentinto a user-owned prefix (with version pinning), wiresANTHROPIC_API_KEY/OPENAI_API_KEY/GEMINI_API_KEYplus anextra_envmap for other supported providers, writesdefaultProjectTrustinto~/.pi/agent/settings.json, and supports optionalworkdirpre-creation andpre_install_script/post_install_scripthooks.enable_ai_gatewayroutes Pi'santhropicandopenaiproviders through Coder AI Gateway with the owner's session token.Pi ignores
ANTHROPIC_BASE_URL, so the gateway endpoints are written asbaseUrloverrides in~/.pi/agent/models.json(other keys preserved).npm_registry_urlinstalls from an internal npm mirror;pi_binary_pathpointsinstall_pi = falseat a preinstalled binary outsidePATH./login, sensitive variables), Agent Firewall, session continuity (pi --continue+ tmux), managed configuration, and a network access / air-gapped section; adds a preview image (registry/coder-labs/.images/pi.png, from Pi's MIT-licensed docs)..icons/pi.svg(sourced frompi.dev/logo-auto.svg)..worktrees/directory used for isolated branch work.Testing
terraform test: 18/18 passingbun test registry/coder-labs/modules/pi(Docker): 16/16 passing, including real npm installs with and withoutnpm_registry_urlshellcheckon the rendered install script,bun x prettier --check,terraform fmt -check,go run ./cmd/readmevalidation: cleanmodels.jsonbaseUrloverride sends Anthropic requests to<base>/v1/messageswithX-Api-Keyand OpenAI requests to<base>/v1/responseswith a bearer token, both of which AI Gateway accepts.Notes
/icon/pi.svgicon referenced by the module'scoder_script/coder_appresources does not yet exist incoder/coder'ssite/static/icon/. A companion PR adds it there: feat(site): add Pi coding agent icon coder#29687🤖 Generated by Coder Agents on behalf of @nickvigilante.