vscode-web
VS Code in your browser, running on the workstation: code-server installed, started for you, reachable only from your laptop.
Installs code-server, which is VS Code in a browser tab, running on the workstation. It starts on boot as the login user and listens on port 8080 on the workstation’s own loopback address.
To use it, install it, forward its port, and tell it not to ask for a password (safe, because only the forward can reach it):
spec:
devtools:
- name: vscode-web
toolconfigs:
- id: vscode-web
name: vscode-web
config:
auth: none
ports:
- 8080
defaultLocalBinding:
enabled: true
autoForward:
forwardAll: trueThen open http://127.0.0.1:8080 on your laptop.
That is the whole setup. version pins the code-server release; omit it for the pinned
default. Everything else on this page is optional: extensions,
a password or a different port, and how it behaves.
Extensions
The default set is one extension, Claude Code. To choose your own, list
Open VSX ids on the devtool’s config, optionally pinned as
<namespace>.<name>@<version>:
devtools:
- name: vscode-web
config:
extensions:
- anthropic.claude-code
- golang.go
- ms-python.python@2024.14.0| You declare | You get |
|---|---|
| nothing | anthropic.claude-code |
extensions: [] | no extensions; an empty list is taken literally |
| a list | those, up to 32 |
| a malformed id | refused at apply, so the typo surfaces while you are looking at it |
If one extension fails to install, only that extension is lost; the rest, and the IDE itself, are unaffected.
Configuring it
The devtool installs; the
vscode-web toolconfig configures.
Use it to require a password, move the IDE off port 8080, or set editor settings for
everyone.
What it does
- Installs the
code-serverbinary from the official release for the workstation’s architecture. - Installs the declared extensions for the login user.
- Registers a Ringleader-managed service that starts
code-serveras the login user on boot, carrying the workstation’s declaredenvironment. When that environment changes, the service restarts, so a variable declared in a config layer reaches the editor and its terminals without anyone restarting anything.
The browser IDE is served under Ringleader’s mark: the tab icon and the app-install icons are the Ringleader ring, and the install prompt reads “Install Ringleader app”. Nothing else about the editor is changed.
Example
A browser IDE with Claude Code and Codex in the terminal and the editor, reachable only from your laptop:
apiVersion: workstations.ringleader.dev/v1
kind: WorkstationConfig
metadata:
name: ide
namespace: local
spec:
selector:
matchLabels:
tier: dev
identity:
shell: /bin/bash
packages:
- git
- curl
devtools:
- name: nodejs
- name: claude-code
- name: codex
- name: vscode-web
toolconfigs:
- id: vscode-web
name: vscode-web
config:
auth: none
ports:
- 8080
defaultLocalBinding:
enabled: true
autoForward:
forwardAll: trueNotes
- code-server listens only on the workstation’s loopback address, so it is never exposed on a network; the forward is the only way in.
- If you also run a service on 8080, move code-server with the toolconfig’s
port. Tool configuration is applied before your provisioning scripts run, so code-server has already moved by the time a script tries to bind 8080. - To attach desktop VS Code over SSH instead, no devtool is needed; see the
vscode-servertoolconfig. - Debian and Ubuntu only. code-server publishes no musl build, so on an Alpine workstation this devtool fails with a message saying so.