Skip to content

refactor(registry/coder-labs/modules/sourcegraph-amp)!: remove agentapi, tasks and start logic - #1160

Draft
35C4n0r wants to merge 1 commit into
mainfrom
35C4n0r/migrate-sourcegraph-amp
Draft

35C4n0r wants to merge 1 commit into
mainfrom
35C4n0r/migrate-sourcegraph-amp

Conversation

@35C4n0r

@35C4n0r 35C4n0r commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator

Refactor coder-labs/sourcegraph-amp to install and configure Amp only, matching the claude-code, codex, copilot, and cursor-cli (#1152) migrations.

  • Replace the agentapi module with coder-utils; drop Tasks/web-app inputs (order, group, cli_app, web_app_display_name, cli_app_display_name, install_agentapi, agentapi_version, report_tasks, ai_prompt), the start script, the task_app_id output, and the task-reporting coder MCP server (which also rendered CODER_AGENT_TOKEN into settings).
  • Install via the official installer (https://ampcode.com/install.sh, temp file + bash -n validation, retrying curl) with amp_version passed as AMP_VERSION. The installer is skipped when amp is on PATH and matches the pin, and the install fails clearly when install_amp = false and no binary exists. install_via_npm is removed.
  • Make workdir optional (created if missing).
  • Rename base_amp_config to amp_settings. Its keys are now merged into ~/.config/amp/settings.json instead of overwriting the whole file, and it no longer writes stale defaults (amp.anthropic.thinking.enabled, amp.todos.enabled, amp.terminal.animation).
  • Merge mcp into amp.mcpServers. Existing on-disk servers win on duplicate names, which matches how amp mcp add handles duplicates. A JSONC settings file is left untouched and a warning is logged.
  • Add managed_settings, written as root to /etc/ampcode/managed-settings.json.
  • instruction_prompt now writes ~/.config/amp/AGENTS.md. amp_api_key is exported as AMP_API_KEY only when set and is never rendered into the script.
  • Remove mode: its values are now low|medium|high|ultra and it can only be set with --mode in the user's coder_app.
  • Add the scripts output. Rewrite the README (v4 warning, launcher example) and the tests. Bump to 4.0.0.

Important

Not verified end to end without an Amp access token: that a running agent session loads ~/.config/amp/AGENTS.md, and that MCP servers written by the module start in a session. What was verified with the real binary: amp mcp list reads the merged settings, and amp config keymap reflects /etc/ampcode/managed-settings.json over user settings.

Decision log

Verified against the installed CLI (0.0.1790769659-g954f35) and https://ampcode.com/docs:

Skill pattern Amp reality Decision
Official installer, pass version through install.sh honors AMP_VERSION (exact release, empty = latest; latest or v prefix 404s). Installs to ~/.amp/bin and symlinks ~/.local/bin/amp Pass amp_version as AMP_VERSION, default ""; validate charset
Drop Node/npm npm @sourcegraph/amp now wraps the same native binaries (@ampcode/cli-*), with no musl build Remove install_via_npm; document the npx MCP caveat
Pinned version Amp auto-updates in the background (amp.updates.mode, AMP_SKIP_UPDATE_CHECK) Document pairing the pin with amp.updates.mode = "disabled"
Workdir trust No folder-trust prompt; only workspace .amp/settings.json MCP servers need amp mcp approve Only create workdir
Model via env var No model or mode env var or setting; --mode low|medium|high|ultra flag only (old free|rush|smart is gone) Drop mode, document the flag
Single auth env var AMP_API_KEY (sgamp_ access token) takes precedence over saved accounts coder_env gated on non-empty
MCP duplicate semantics amp mcp add errors with "already exists" and keeps the current entry jq merge, existing wins
Fall back to {} on invalid JSON Amp officially accepts JSONC in settings.json (and settings.json wins over settings.jsonc) Leave non-strict-JSON files untouched and warn, so user settings are never discarded
managed_settings root-owned policy /etc/ampcode/managed-settings.json is read and wins over user settings (verified). Amp does not reject non-root or world-writable files Write as root with mode 0644
Generic user-settings dump Existing base_amp_config feature; the old default wrote keys no longer in the settings reference Keep as amp_settings, key-merge (module owns only its keys), no defaults, reject amp.mcpServers
Settings file location AMP_SETTINGS_FILE overrides the default path Honor it when set
Instruction prompt path Both ~/.config/amp/AGENTS.md and ~/.config/AGENTS.md are loaded Write the Amp-scoped ~/.config/amp/AGENTS.md
AI Gateway port Not present before the migration Out of scope

Testing

  • terraform fmt, terraform validate, terraform test (11 passed)
  • bun test main.test.ts (16 passed, container-based)
  • Ran the rendered install script with the real installer in codercom/enterprise-node:latest: installed, re-run skipped the install, PATH was updated, settings merged with the existing MCP server kept, AGENTS.md and managed settings written, and amp mcp list read the result
  • shellcheck on the rendered install script, prettier, readmevalidation, version-bump.sh --ci major

Generated with Coder Agents.

…pi, tasks and start logic

- Replace the agentapi module with coder-utils; drop Tasks/web-app inputs, start script, and the task-reporting MCP server.
- Install via the official installer (AMP_VERSION pin, temp file + bash -n, retrying curl); drop npm install.
- Make workdir optional; merge amp_settings (was base_amp_config) and mcp into ~/.config/amp/settings.json, existing MCP servers win.
- Add managed_settings (/etc/ampcode/managed-settings.json); write instruction_prompt to ~/.config/amp/AGENTS.md.
- Drop mode (use --mode in the launcher); add scripts output, main.tftest.hcl, container tests; bump to 4.0.0.
@github-actions

Copy link
Copy Markdown
Contributor

Module Scorecard Check

coder-labs/sourcegraph-amp: first scorecard, 68 / 100

No specific score is required to contribute, but modules with higher scores are more likely to be approved by the Coder team and widely used.

Full scorecard for this PR
Presentation & Onboarding Agent Integration Credential Hygiene Restricted-Environment Readiness Engineering Quality Overall
12 / 17 10 / 25 20 / 20 11 / 20 10 / 10 68 / 100
Drilldown

Presentation & Onboarding — 12 / 17

Criterion Max Score Notes
Configuration-mode examples 12 12 README documents five distinct examples: basic install, standalone with coder_app launcher, settings + MCP + instruction_prompt, managed settings with version pinning, and coder_script serialization. Each major option (install_amp, amp_version, workdir, amp_settings, mcp, managed_settings, instruction_prompt) is shown with sensible defaults and usage context.
Visual preview 5 0 No embedded image, GIF, or video in the README. The frontmatter references an SVG icon file, but no visual of the module in action is present.

Credential Hygiene — 20 / 20

Criterion Max Score Notes
Secrets marked sensitive 16 16 amp_api_key is declared with sensitive = true in main.tf. All README examples reference var.amp_api_key (a variable), never an inline literal key. The install script receives the key via coder_env (base64-encoded in the template), and the test api-key-env-var-not-in-script verifies the key is absent from rendered scripts.
Non-hardcoded auth path 4 4 README Configuration section documents: "Without a key, run amp login in the workspace." This is a clear alternative auth path that avoids pasting a raw API key into any template.

Restricted-Environment Readiness — 11 / 20

Criterion Max Score Notes
Mirrorable artifact source 5 0 The installer URL https://ampcode.com/install.sh is hardcoded in scripts/install.sh.tftpl (line: --output "$${installer_file}" https://ampcode.com/install.sh). No module input variable overrides this URL. amp_version controls which version the installer fetches, not where it fetches from. No variable names a mirror or artifact-store URL.
Bring-your-own binary 10 10 install_amp (default true) can be set to false to skip the download entirely. README states: "If install_amp = false, a working amp must already be available on PATH, or workspace startup fails." The install script validates the existing binary and exits cleanly.
Egress transparency 3 0 No dedicated README section enumerates external endpoints or provides air-gapped/restricted-environment guidance. The ampcode.com/install.sh URL appears only inline in the Configuration paragraph, not in a standalone network/egress section.
Runs without sudo 2 1 The core install path (curl + bash installer, workdir creation, settings writes) never invokes sudo. However, write_managed_settings uses sudo mkdir/tee/chmod when writing to /etc/ampcode/managed-settings.json. An else branch exists that attempts the same operations without sudo, but writing to /etc/ as a non-root user will fail in practice. Managed settings is optional (default null), so this is an optional feature with a code-level fallback → half.

Engineering Quality — 10 / 10

Criterion Max Score Notes
Input quality 6 6 All 12 variables have clear description fields. amp_version has a regex validation (^[A-Za-z0-9._-]*$). amp_settings and mcp have JSON-object validations plus a cross-field check preventing amp.mcpServers inside amp_settings. Defaults are sensible (install_amp = true, amp_version = "" for latest, workdir = null).
Test coverage 4 4 main.tftest.hcl (10 test runs) covers defaults, trailing-slash trimming, env-var creation, version pass-through, validation failures, base64 encoding, and scripts output ordering. main.test.ts (15 tests) exercises end-to-end script execution in a container: installer invocation, version-mismatch re-install, download failure, workdir creation, settings merge semantics, MCP merge (existing-wins), JSONC detection, managed-settings root write, API-key leakage, and pre/post scripts.

Agent Integration — 10 / 25

Criterion Max Score Notes
AI governance 10 0 No mention of Coder AI Gateway or Agent Firewall anywhere in the README. The v4 WARNING explicitly states the module "drops support for Coder Tasks and AgentAPI." Per calibration, dropped/removed support counts as absent.
Dashboard entry point 5 5 The "Standalone mode with a launcher app" example documents a complete coder_app resource with slug, display_name, icon, open_in = "slim-window", and a bash command that cds into the workdir and exec amp --mode medium.
Session continuity 5 0 A brief NOTE mentions that coder_app re-executes on reconnect and suggests "a coder_app that attaches to the existing session (for example, with tmux)." This is a user-side workaround suggestion, not a documented module feature. The module implements no session-ID, resume, or persistent-session-manager support.
Managed configuration 5 5 Three documented mechanisms: amp_settings merged into ~/.config/amp/settings.json (with merge semantics and JSONC guard), mcp servers merged into amp.mcpServers (existing-on-disk wins), and managed_settings written to /etc/ampcode/managed-settings.json with enterprise precedence. instruction_prompt writes to ~/.config/amp/AGENTS.md. All have README examples and link to upstream docs.

Overall — 68 / 100

Raw 63 / 92 → round(63 / 92 × 100) = 68

Tip

You can run this locally by telling your agent: "review this module against .github/scorecard/SCORECARD.md".


Scored against SCORECARD.md with solstice-1. Language-model scores are advisory.

@matifali

Copy link
Copy Markdown
Member

Maybe we can repurpose this module to use Coder workspaces as Amp runners?
https://ampcode.com/docs/cli/runners

35C4n0r commented Sep 30, 2026

Copy link
Copy Markdown
Collaborator Author

Ack, will check this out.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants