vscode-web

VS Code in your browser, running on the workstation: code-server installed, started for you, reachable only from your laptop.

Installs code-server, which is VS Code in a browser tab, running on the workstation. It starts on boot as the login user and listens on port 8080 on the workstation’s own loopback address.

To use it, install it, forward its port, and tell it not to ask for a password (safe, because only the forward can reach it):

spec:
  devtools:
    - name: vscode-web
  toolconfigs:
    - id: vscode-web
      name: vscode-web
      config:
        auth: none
  ports:
    - 8080
  defaultLocalBinding:
    enabled: true
    autoForward:
      forwardAll: true

Then open http://127.0.0.1:8080 on your laptop.

That is the whole setup. version pins the code-server release; omit it for the pinned default. Everything else on this page is optional: extensions, a password or a different port, and how it behaves.

Extensions

The default set is one extension, Claude Code. To choose your own, list Open VSX ids on the devtool’s config, optionally pinned as <namespace>.<name>@<version>:

devtools:
  - name: vscode-web
    config:
      extensions:
        - anthropic.claude-code
        - golang.go
        - ms-python.python@2024.14.0
You declareYou get
nothinganthropic.claude-code
extensions: []no extensions; an empty list is taken literally
a listthose, up to 32
a malformed idrefused at apply, so the typo surfaces while you are looking at it

If one extension fails to install, only that extension is lost; the rest, and the IDE itself, are unaffected.

Configuring it

The devtool installs; the vscode-web toolconfig configures. Use it to require a password, move the IDE off port 8080, or set editor settings for everyone.

What it does

  1. Installs the code-server binary from the official release for the workstation’s architecture.
  2. Installs the declared extensions for the login user.
  3. Registers a Ringleader-managed service that starts code-server as the login user on boot, carrying the workstation’s declared environment. When that environment changes, the service restarts, so a variable declared in a config layer reaches the editor and its terminals without anyone restarting anything.

The browser IDE is served under Ringleader’s mark: the tab icon and the app-install icons are the Ringleader ring, and the install prompt reads “Install Ringleader app”. Nothing else about the editor is changed.

Example

A browser IDE with Claude Code and Codex in the terminal and the editor, reachable only from your laptop:

apiVersion: workstations.ringleader.dev/v1
kind: WorkstationConfig
metadata:
  name: ide
  namespace: local
spec:
  selector:
    matchLabels:
      tier: dev
  identity:
    shell: /bin/bash
  packages:
    - git
    - curl
  devtools:
    - name: nodejs
    - name: claude-code
    - name: codex
    - name: vscode-web
  toolconfigs:
    - id: vscode-web
      name: vscode-web
      config:
        auth: none
  ports:
    - 8080
  defaultLocalBinding:
    enabled: true
    autoForward:
      forwardAll: true

Notes

  • code-server listens only on the workstation’s loopback address, so it is never exposed on a network; the forward is the only way in.
  • If you also run a service on 8080, move code-server with the toolconfig’s port. Tool configuration is applied before your provisioning scripts run, so code-server has already moved by the time a script tries to bind 8080.
  • To attach desktop VS Code over SSH instead, no devtool is needed; see the vscode-server toolconfig.
  • Debian and Ubuntu only. code-server publishes no musl build, so on an Alpine workstation this devtool fails with a message saying so.