Conversation
…ks and start logic - Replace the agentapi module with coder-utils and an install-only scripts/install.sh.tftpl using the official installer. - Drop Tasks/AgentAPI inputs, the start script, the task-reporting MCP server, and the task_app_id output; add the scripts output. - Make workdir optional; merge config_json and the new mcp variable into ~/.config/opencode/opencode.json (existing MCP servers win). - Deliver auth_json via coder_env and merge it into auth.json (0600). - Add managed_settings written as root to /etc/opencode/opencode.json. - Rewrite README and tests; bump to 1.0.0.
Contributor
Module Scorecard Check
|
| Presentation & Onboarding | Agent Integration | Credential Hygiene | Restricted-Environment Readiness | Engineering Quality | Overall |
|---|---|---|---|---|---|
| 12 / 17 | 15 / 25 | 20 / 20 | 11 / 20 | 10 / 10 | 74 / 100 |
Drilldown
Presentation & Onboarding — 12 / 17
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Configuration-mode examples | 12 | 12 | README documents each major mode with a dedicated example: standalone launcher app (workdir, auth_json, config_json), MCP servers, managed settings, and downstream script serialization. The Configuration section covers install_opencode, opencode_version, and the BYO-binary path. Sensible defaults are shown throughout. |
| Visual preview | 5 | 0 | No embedded image, GIF, or video in the README. The icon frontmatter field references an SVG file but does not embed a visual of the module in action. |
Credential Hygiene — 20 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Secrets marked sensitive | 16 | 16 | auth_json is declared sensitive = true in main.tf. README examples use var.opencode_auth_json (no inline literal keys). The install script reads credentials exclusively from the CODER_OPENCODE_AUTH_JSON environment variable; tests verify the secret never appears in the rendered script or logs. |
| Non-hardcoded auth path | 4 | 4 | README explicitly documents: "Alternatively, skip auth_json and set the provider's API key environment variable (for example ANTHROPIC_API_KEY) with a coder_env." This avoids pasting raw keys into module templates. |
Restricted-Environment Readiness — 11 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Mirrorable artifact source | 5 | 0 | The install URL https://opencode.ai/install is hardcoded in scripts/install.sh.tftpl. No module input variable overrides this download URL. opencode_version pins a release tag but does not change the source URL. No variable exists that would allow pointing to an internal mirror. |
| Bring-your-own binary | 10 | 10 | install_opencode = false is documented in the README ("If install_opencode = false, a working opencode must already be available on PATH"). The install script skips the download, validates the existing binary, and adds it to PATH. Fully functional offline path. |
| Egress transparency | 3 | 0 | No dedicated README section enumerates external endpoints or provides notes for restricted/air-gapped environments. The install URL appears in passing in the Configuration section; MCP server URLs appear in examples. No consolidated network-egress documentation exists. |
| Runs without sudo | 2 | 1 | Core install (binary, config, auth, workdir) runs entirely as the unprivileged user. sudo is invoked only inside write_managed_settings (optional feature) and the script degrades gracefully: if sudo -n true fails, it logs a warning and returns. Per rubric, sudo for optional features with a working fallback earns half. |
Engineering Quality — 10 / 10
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Input quality | 6 | 6 | All 11 variables have clear descriptions, sensible defaults, and validation blocks where appropriate (opencode_version regex, auth_json/config_json/mcp JSON-object checks, config_json mcp-key exclusion, managed_settings object check). |
| Test coverage | 4 | 4 | main.tftest.hcl (13 runs) covers plan-level business logic: defaults, workdir trimming, env-var creation, base64 encoding, validation failures, and scripts output ordering. main.test.ts (14 tests) covers end-to-end container behavior: happy path, BYO binary, installer invocation, version pinning, download failure, config/MCP merging, auth file permissions, managed settings, and pre/post scripts. |
Agent Integration — 15 / 25
| Criterion | Max | Score | Notes |
|---|---|---|---|
| AI governance | 10 | 0 | No documentation of Coder AI Gateway or Agent Firewall support. The v1 WARNING explicitly states "drops support for Coder Tasks and AgentAPI." No mention of how Coder governs auth, routing, or policy enforcement for the agent. |
| Dashboard entry point | 5 | 5 | README "Standalone mode with a launcher app" section provides a complete coder_app resource example with slug, display_name, icon, open_in = "slim-window", and a bash command that cds to the workdir and execs opencode --continue. |
| Session continuity | 5 | 5 | README documents --continue and --session CLI flags (WARNING section and example). The NOTE explicitly addresses reconnect behavior: "use a coder_script (runs once at startup) and a coder_app that attaches to the existing session (for example, with tmux or opencode attach)." |
| Managed configuration | 5 | 5 | "Managed settings" section documents managed_settings written to /etc/opencode/opencode.json with highest precedence. Example shows share, autoupdate, and permission keys. README links to OpenCode's managed-settings docs. |
Overall — 74 / 100
Raw 68 / 92 → round(68 / 92 × 100) = 74
Tip
You can run this locally by telling your agent: "review this module against .github/scorecard/SCORECARD.md".
Scored against SCORECARD.md with solstice-1. Language-model scores are advisory.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Refactor
coder-labs/opencodeto install and configure OpenCode only, matching the codex, copilot, and cursor-cli (#1152) migrations.order,group,report_tasks,cli_app,web_app_display_name,cli_app_display_name,subdomain,install_agentapi,agentapi_version,ai_prompt), the start script, the task-reportingcoderMCP server, and thetask_app_idoutput.https://opencode.ai/install, temp file +bash -nvalidation, retrying curl,--no-modify-path).latestis passed as an emptyVERSIONbecause the installer otherwise looks up avlatesttag and fails. Skipped whenopencodeis onPATHand matches the requested version; fails clearly wheninstall_opencode = falseand no binary exists.opencode_versionis validated since it is rendered into the script.workdiroptional (created if missing). OpenCode has no trust prompt, so nothing else is written.config_jsonis now deep-merged into~/.config/opencode/opencode.jsoninstead of overwriting it (module keys win, other keys preserved, invalid JSON backed up to.bak). It rejects anmcpkey at plan time.mcpvariable (value of opencode.json'smcpkey) merged into the same file; servers already on disk win on duplicate names.auth_jsonis delivered throughcoder_envCODER_OPENCODE_AUTH_JSON(never rendered into the script, read by jq viaenv) and merged into~/.local/share/opencode/auth.jsonwith mode0600; module provider IDs win, other credentials are preserved.managed_settingswritten as root to/etc/opencode/opencode.json(OpenCode's Linux managed config, highest precedence).continueandsession_id: they only fed the launch command, so they become--continue/--sessionflags in the user'scoder_app.scriptsoutput; rewrite README (v1 warning, launcher example) and tests. Bump to1.0.0.Important
Two choices worth a reviewer check:
opencode mcp addis an upsert (verified: it overwrites an existing name), so "existing servers win" deviates from native semantics. It was kept for consistency with the sibling modules and to avoid clobbering in-workspace edits; the trade-off is that template changes to an existing server name do not propagate.auth_jsonis exported workspace-wide asCODER_OPENCODE_AUTH_JSON. This keeps it out of the rendered script but makes it visible to every workspace process (equivalent exposure to theauth.jsonfile itself and to provider API key env vars). OpenCode's ownOPENCODE_AUTH_CONTENTwas not used because it is undocumented and makes OpenCode ignoreauth.json, silently dropping interactive logins.Real provider auth (a live model call) was not exercised; credentials were verified via
opencode providers listonly.Decision log
Verified against the installed CLI (
1.18.33, also1.18.30) and OpenCode docs:VERSION(stripsv);VERSION=latestfails withRelease vlatest not foundlatestto emptyVERSION; validate version format$SHELL; binary in~/.opencode/bin--no-modify-path; module links intoCODER_SCRIPT_BIN_DIRand updates all profilesmodelkey in config or--modelflagmodelvariable; useconfig_jsonor the flagauth.jsonor provider env vars likeANTHROPIC_API_KEY)auth_json, delivered viacoder_env, merged intoauth.jsonmanaged_settingsroot-owned policy/etc/opencode/opencode.json(confirmed in binary and viaopencode debug config)0644mcpinopencode.json;opencode mcp addoverwritesmcpvariable, existing wins (see IMPORTANT)config_jsonoverwrote the whole fileconfig_json, now a deep merge that preserves other keyscontinue,session_id)--continue,--sessionCLI flagscoder_appTesting
terraform fmt,terraform validate,terraform test(14 passed)bun test main.test.ts(15 passed, container-based)codercom/enterprise-node:latest: installed1.18.33,opencode debug configshowed the merged model, MCP server, and managedshare;opencode providers listshowed the credential;auth.jsonis0600, managed file root0644; rerun skipped install; switching tov1.18.30reinstalled that versionvalidate_set_u_order.sh, prettier, typos,readmevalidationGenerated with Coder Agents.