Skip to content

refactor(registry/coder-labs/modules/opencode)!: remove agentapi, tasks and start logic - #1159

Draft
35C4n0r wants to merge 1 commit into
mainfrom
35C4n0r/migrate-opencode
Draft

35C4n0r wants to merge 1 commit into
mainfrom
35C4n0r/migrate-opencode

Conversation

@35C4n0r

@35C4n0r 35C4n0r commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Refactor coder-labs/opencode to install and configure OpenCode only, matching the codex, copilot, and cursor-cli (#1152) migrations.

  • Replace the agentapi module with coder-utils; drop Tasks inputs (order, group, report_tasks, cli_app, web_app_display_name, cli_app_display_name, subdomain, install_agentapi, agentapi_version, ai_prompt), the start script, the task-reporting coder MCP server, and the task_app_id output.
  • Install via the official installer (https://opencode.ai/install, temp file + bash -n validation, retrying curl, --no-modify-path). latest is passed as an empty VERSION because the installer otherwise looks up a vlatest tag and fails. Skipped when opencode is on PATH and matches the requested version; fails clearly when install_opencode = false and no binary exists. opencode_version is validated since it is rendered into the script.
  • Make workdir optional (created if missing). OpenCode has no trust prompt, so nothing else is written.
  • config_json is now deep-merged into ~/.config/opencode/opencode.json instead of overwriting it (module keys win, other keys preserved, invalid JSON backed up to .bak). It rejects an mcp key at plan time.
  • New mcp variable (value of opencode.json's mcp key) merged into the same file; servers already on disk win on duplicate names.
  • auth_json is delivered through coder_env CODER_OPENCODE_AUTH_JSON (never rendered into the script, read by jq via env) and merged into ~/.local/share/opencode/auth.json with mode 0600; module provider IDs win, other credentials are preserved.
  • New managed_settings written as root to /etc/opencode/opencode.json (OpenCode's Linux managed config, highest precedence).
  • Remove continue and session_id: they only fed the launch command, so they become --continue / --session flags in the user's coder_app.
  • Add scripts output; rewrite README (v1 warning, launcher example) and tests. Bump to 1.0.0.

Important

Two choices worth a reviewer check:

  • opencode mcp add is an upsert (verified: it overwrites an existing name), so "existing servers win" deviates from native semantics. It was kept for consistency with the sibling modules and to avoid clobbering in-workspace edits; the trade-off is that template changes to an existing server name do not propagate.
  • auth_json is exported workspace-wide as CODER_OPENCODE_AUTH_JSON. This keeps it out of the rendered script but makes it visible to every workspace process (equivalent exposure to the auth.json file itself and to provider API key env vars). OpenCode's own OPENCODE_AUTH_CONTENT was not used because it is undocumented and makes OpenCode ignore auth.json, silently dropping interactive logins.

Real provider auth (a live model call) was not exercised; credentials were verified via opencode providers list only.

Decision log

Verified against the installed CLI (1.18.33, also 1.18.30) and OpenCode docs:

Skill pattern OpenCode reality Decision
Pass version straight to official installer Installer reads VERSION (strips v); VERSION=latest fails with Release vlatest not found Map latest to empty VERSION; validate version format
Installer handles PATH Installer edits one rc file based on $SHELL; binary in ~/.opencode/bin --no-modify-path; module links into CODER_SCRIPT_BIN_DIR and updates all profiles
Model via documented env var No model env var; model key in config or --model flag No model variable; use config_json or the flag
Single tool-specific token env var Credentials are per provider (auth.json or provider env vars like ANTHROPIC_API_KEY) Keep auth_json, delivered via coder_env, merged into auth.json
managed_settings root-owned policy Linux managed config /etc/opencode/opencode.json (confirmed in binary and via opencode debug config) Added, written with sudo, 0644
MCP merge, existing wins MCP lives under mcp in opencode.json; opencode mcp add overwrites Separate mcp variable, existing wins (see IMPORTANT)
Generic config dump discouraged Pre-migration config_json overwrote the whole file Keep config_json, now a deep merge that preserves other keys
Workdir trust key No trust concept in docs or binary Only create the workdir
AI Gateway port Not present pre-migration Out of scope
Launch-only flags (continue, session_id) --continue, --session CLI flags Removed; documented for the coder_app

Testing

  • terraform fmt, terraform validate, terraform test (14 passed)
  • bun test main.test.ts (15 passed, container-based)
  • Real installer run of the rendered install script in codercom/enterprise-node:latest: installed 1.18.33, opencode debug config showed the merged model, MCP server, and managed share; opencode providers list showed the credential; auth.json is 0600, managed file root 0644; rerun skipped install; switching to v1.18.30 reinstalled that version
  • shellcheck on rendered install script, validate_set_u_order.sh, prettier, typos, readmevalidation

Generated with Coder Agents.

…ks and start logic

- Replace the agentapi module with coder-utils and an install-only
  scripts/install.sh.tftpl using the official installer.
- Drop Tasks/AgentAPI inputs, the start script, the task-reporting MCP
  server, and the task_app_id output; add the scripts output.
- Make workdir optional; merge config_json and the new mcp variable into
  ~/.config/opencode/opencode.json (existing MCP servers win).
- Deliver auth_json via coder_env and merge it into auth.json (0600).
- Add managed_settings written as root to /etc/opencode/opencode.json.
- Rewrite README and tests; bump to 1.0.0.
@github-actions

Copy link
Copy Markdown
Contributor

Module Scorecard Check

coder-labs/opencode: first scorecard, 74 / 100

No specific score is required to contribute, but modules with higher scores are more likely to be approved by the Coder team and widely used.

Full scorecard for this PR
Presentation & Onboarding Agent Integration Credential Hygiene Restricted-Environment Readiness Engineering Quality Overall
12 / 17 15 / 25 20 / 20 11 / 20 10 / 10 74 / 100
Drilldown

Presentation & Onboarding — 12 / 17

Criterion Max Score Notes
Configuration-mode examples 12 12 README documents each major mode with a dedicated example: standalone launcher app (workdir, auth_json, config_json), MCP servers, managed settings, and downstream script serialization. The Configuration section covers install_opencode, opencode_version, and the BYO-binary path. Sensible defaults are shown throughout.
Visual preview 5 0 No embedded image, GIF, or video in the README. The icon frontmatter field references an SVG file but does not embed a visual of the module in action.

Credential Hygiene — 20 / 20

Criterion Max Score Notes
Secrets marked sensitive 16 16 auth_json is declared sensitive = true in main.tf. README examples use var.opencode_auth_json (no inline literal keys). The install script reads credentials exclusively from the CODER_OPENCODE_AUTH_JSON environment variable; tests verify the secret never appears in the rendered script or logs.
Non-hardcoded auth path 4 4 README explicitly documents: "Alternatively, skip auth_json and set the provider's API key environment variable (for example ANTHROPIC_API_KEY) with a coder_env." This avoids pasting raw keys into module templates.

Restricted-Environment Readiness — 11 / 20

Criterion Max Score Notes
Mirrorable artifact source 5 0 The install URL https://opencode.ai/install is hardcoded in scripts/install.sh.tftpl. No module input variable overrides this download URL. opencode_version pins a release tag but does not change the source URL. No variable exists that would allow pointing to an internal mirror.
Bring-your-own binary 10 10 install_opencode = false is documented in the README ("If install_opencode = false, a working opencode must already be available on PATH"). The install script skips the download, validates the existing binary, and adds it to PATH. Fully functional offline path.
Egress transparency 3 0 No dedicated README section enumerates external endpoints or provides notes for restricted/air-gapped environments. The install URL appears in passing in the Configuration section; MCP server URLs appear in examples. No consolidated network-egress documentation exists.
Runs without sudo 2 1 Core install (binary, config, auth, workdir) runs entirely as the unprivileged user. sudo is invoked only inside write_managed_settings (optional feature) and the script degrades gracefully: if sudo -n true fails, it logs a warning and returns. Per rubric, sudo for optional features with a working fallback earns half.

Engineering Quality — 10 / 10

Criterion Max Score Notes
Input quality 6 6 All 11 variables have clear descriptions, sensible defaults, and validation blocks where appropriate (opencode_version regex, auth_json/config_json/mcp JSON-object checks, config_json mcp-key exclusion, managed_settings object check).
Test coverage 4 4 main.tftest.hcl (13 runs) covers plan-level business logic: defaults, workdir trimming, env-var creation, base64 encoding, validation failures, and scripts output ordering. main.test.ts (14 tests) covers end-to-end container behavior: happy path, BYO binary, installer invocation, version pinning, download failure, config/MCP merging, auth file permissions, managed settings, and pre/post scripts.

Agent Integration — 15 / 25

Criterion Max Score Notes
AI governance 10 0 No documentation of Coder AI Gateway or Agent Firewall support. The v1 WARNING explicitly states "drops support for Coder Tasks and AgentAPI." No mention of how Coder governs auth, routing, or policy enforcement for the agent.
Dashboard entry point 5 5 README "Standalone mode with a launcher app" section provides a complete coder_app resource example with slug, display_name, icon, open_in = "slim-window", and a bash command that cds to the workdir and execs opencode --continue.
Session continuity 5 5 README documents --continue and --session CLI flags (WARNING section and example). The NOTE explicitly addresses reconnect behavior: "use a coder_script (runs once at startup) and a coder_app that attaches to the existing session (for example, with tmux or opencode attach)."
Managed configuration 5 5 "Managed settings" section documents managed_settings written to /etc/opencode/opencode.json with highest precedence. Example shows share, autoupdate, and permission keys. README links to OpenCode's managed-settings docs.

Overall — 74 / 100

Raw 68 / 92 → round(68 / 92 × 100) = 74

Tip

You can run this locally by telling your agent: "review this module against .github/scorecard/SCORECARD.md".


Scored against SCORECARD.md with solstice-1. Language-model scores are advisory.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant