Skip to main content

Code Server

Deploy Code Server (linuxserver.io VS Code in the browser).

Ansible hosts group: code_server​

Variables​

OptionTypeDescriptionDefault
cs_code_server_docker_imagestringCode Server docker image{{ cs_vm_artifact_registry_containers_home }}/code-server
cs_code_server_docker_tagstringCode Server docker tag4.141.0
cs_code_server_container_namestringContainer namecode-server
cs_code_server_groupstringDedicated groupcode-server
cs_code_server_userstringDedicated user (no home, no login)code-server
cs_code_server_server_dnslistDNS serversThe cluster's DNS servers (from Vault)
cs_code_server_container_rootstringContainer root directory/app/code-server
cs_code_server_clusterstringCluster name{{ cs_cluster_name }}
cs_code_server_public_domainstringPublic domain passed as PROXY_DOMAINcode-server.<cluster domain>
cs_code_server_restic_cluster_namestringRestic cluster name{{ cs_code_server_cluster }}
cs_code_server_restic_node_namestringRestic backup node name{{ inventory_hostname }}
cs_code_server_restic_repo_namestringRestic repository namecode-server

Hardware acceleration​

The play attaches NVIDIA GPUs automatically: it runs nvidia-smi on the host and, when that succeeds (driver installed and loaded, see the patch_nvidia stage), starts the container with the NVIDIA runtime and all GPUs (device_requests), plus NVIDIA_VISIBLE_DEVICES=all and NVIDIA_DRIVER_CAPABILITIES=compute,video,utility. Hosts without a working NVIDIA driver skip these options, and Code Server runs unchanged.

FUSE filesystem mounts​

The container starts with the /dev/fuse device, the SYS_ADMIN capability, and the apparmor:unconfined security option, so FUSE-based filesystems (e.g. rclone, sshfs) can be mounted from inside the container:

docker run \
--device /dev/fuse \
--cap-add SYS_ADMIN \
--security-opt apparmor:unconfined \
...

Vault configurations​

  • key: {{ cs_project_code }}/application-deployer/clusters/{{ cs_code_server_cluster }}/hosts/{{ inventory_hostname }}/apps/code-server/config
{
"web-gui-port": "Web GUI port",
"password": "Code Server login password",
"sudo_password": "Code Server sudo password"
}

Backup​

Restic backs up the whole cs_code_server_container_root directory, including the workspace directory it holds. The {{ cs_code_server_container_name }} container is stopped for the duration of the backup and started again afterwards, even if the backup itself fails.

Cleanup (dangerously_cleanup_code_server)​

Destructive. Only runs when this exact tag is passed explicitly (it is intentionally excluded from the plain code_server tag) and permanently deletes Code Server's own data on the host:

  • Removes the {{ cs_code_server_container_name }} Docker container.
  • Deletes the UFW allow rule opened for the web GUI port.
  • Deletes cs_code_server_container_root, including the workspace directory it holds.
  • Deletes the {{ cs_code_server_user }} user, its home directory, and the {{ cs_code_server_group }} group.

Tags​

  • code_server: Deploy Code Server.
  • code_server_install: Install Code Server.
  • code_server_restic_backup: Run Restic backup for Code Server.
  • code_server_restic_restore: Restore Code Server's data from the latest Restic snapshot.
  • dangerously_cleanup_code_server: Destructive. Removes the Code Server Docker container, closes its UFW port, and deletes cs_code_server_container_root. Never included by the plain code_server tag.

Deployment​

uv sync --all-extras --all-packages --no-progress
uv --offline run --no-sync --no-progress ansible-galaxy install -r requirements.yml
uv --offline run --no-sync --no-progress ansible-playbook playbook.yml --tags code_server