Code Server
Deploy Code Server (linuxserver.io VS Code in the browser).
Ansible hosts group: code_server
Variables
| Option | Type | Description | Default |
|---|---|---|---|
cs_code_server_docker_image | string | Code Server docker image | {{ cs_vm_artifact_registry_containers_home }}/code-server |
cs_code_server_docker_tag | string | Code Server docker tag | 4.141.0 |
cs_code_server_container_name | string | Container name | code-server |
cs_code_server_group | string | Dedicated group | code-server |
cs_code_server_user | string | Dedicated user (no home, no login) | code-server |
cs_code_server_server_dns | list | DNS servers | The cluster's DNS servers (from Vault) |
cs_code_server_container_root | string | Container root directory | /app/code-server |
cs_code_server_cluster | string | Cluster name | {{ cs_cluster_name }} |
cs_code_server_public_domain | string | Public domain passed as PROXY_DOMAIN | code-server.<cluster domain> |
cs_code_server_restic_cluster_name | string | Restic cluster name | {{ cs_code_server_cluster }} |
cs_code_server_restic_node_name | string | Restic backup node name | {{ inventory_hostname }} |
cs_code_server_restic_repo_name | string | Restic repository name | code-server |
Hardware acceleration
The play attaches NVIDIA GPUs automatically: it runs nvidia-smi on the host and, when that succeeds (driver installed and loaded, see the patch_nvidia stage), starts the container with the NVIDIA runtime and all GPUs (device_requests), plus NVIDIA_VISIBLE_DEVICES=all and NVIDIA_DRIVER_CAPABILITIES=compute,video,utility. Hosts without a working NVIDIA driver skip these options, and Code Server runs unchanged.
FUSE filesystem mounts
The container starts with the /dev/fuse device, the SYS_ADMIN capability, and the apparmor:unconfined security option, so FUSE-based filesystems (e.g. rclone, sshfs) can be mounted from inside the container:
docker run \
--device /dev/fuse \
--cap-add SYS_ADMIN \
--security-opt apparmor:unconfined \
...
Vault configurations
- key:
{{ cs_project_code }}/application-deployer/clusters/{{ cs_code_server_cluster }}/hosts/{{ inventory_hostname }}/apps/code-server/config
{
"web-gui-port": "Web GUI port",
"password": "Code Server login password",
"sudo_password": "Code Server sudo password"
}
Backup
Restic backs up the whole cs_code_server_container_root directory, including the workspace directory it
holds. The {{ cs_code_server_container_name }} container is stopped for the duration of the backup and started
again afterwards, even if the backup itself fails.
Cleanup (dangerously_cleanup_code_server)
Destructive. Only runs when this exact tag is passed explicitly (it is intentionally excluded from the
plain code_server tag) and permanently deletes Code Server's own data on the host:
- Removes the
{{ cs_code_server_container_name }}Docker container. - Deletes the UFW allow rule opened for the web GUI port.
- Deletes
cs_code_server_container_root, including theworkspacedirectory it holds. - Deletes the
{{ cs_code_server_user }}user, its home directory, and the{{ cs_code_server_group }}group.
Tags
code_server: Deploy Code Server.code_server_install: Install Code Server.code_server_restic_backup: Run Restic backup for Code Server.code_server_restic_restore: Restore Code Server's data from the latest Restic snapshot.dangerously_cleanup_code_server: Destructive. Removes the Code Server Docker container, closes its UFW port, and deletescs_code_server_container_root. Never included by the plaincode_servertag.
Deployment
uv sync --all-extras --all-packages --no-progress
uv --offline run --no-sync --no-progress ansible-galaxy install -r requirements.yml
uv --offline run --no-sync --no-progress ansible-playbook playbook.yml --tags code_server