vscode-web

VS Code in your browser, running on the workstation: the few lines that make it work, and the settings for when you need more.

This toolconfig tells code-server, VS Code in a browser tab, how to run on your workstation. The vscode-web devtool installs it; this configures it.

Set it up

For most people this is the whole configuration. Add it to a WorkstationConfig that selects your workstations:

spec:
  devtools:
    - name: vscode-web
  toolconfigs:
    - id: vscode-web
      name: vscode-web
      config:
        auth: none
  ports:
    - 8080
  defaultLocalBinding:
    enabled: true
    autoForward:
      forwardAll: true

Then open http://127.0.0.1:8080 on your laptop. That is your workstation’s VS Code.

auth: none is safe here because code-server listens only on the workstation’s own loopback address, and the only way to reach it is the port forward Ringleader sets up to your laptop. Nobody else can connect to it.

If that is all you need, you are done. The rest of this page is for when you want something different: a password, a different port, editor settings, or the full list of fields.

Requiring a password

Store the password as a Secret, then point the toolconfig at it:

rl secret create vscode-web-password -n local \
  --from-string vscode-web-password=<choose-a-password>
toolconfigs:
  - id: vscode-web
    name: vscode-web
    config:
      auth: password
      password: "${secret:vscode-web-password}"

Changing the password later restarts code-server for you, since it reads the password only when it starts.

Changing the port

If something else on the workstation already uses 8080, move code-server. Set port and auth together, and forward the new port:

toolconfigs:
  - id: vscode-web
    name: vscode-web
    config:
      port: 8081
      auth: none
ports:
  - 8080          # your app
  - 8081          # the IDE

Setting the port alone leaves nobody able to log in

Whenever you set port, bindAddr or cert, set auth in the same block. A field you leave out takes its default, and the default for auth is password, so port: 8081 on its own gives you password authentication with no password. Set auth: none (safe on the default loopback bind) or auth: password with a password.

Tool configuration is applied before your provisioning scripts run, so code-server has already moved by the time a script starts your app on 8080.

Editor settings

You do not need this section to use the editor. code-server has the same settings as desktop VS Code. To set editor settings for everyone who uses the workstation, put them under settings.

Ringleader also writes three settings for the Claude Code extension, so that if you use it, its panel opens without permission prompts or onboarding. They have no effect on any other tool:

{
  "claudeCode.allowDangerouslySkipPermissions": true,
  "claudeCode.initialPermissionMode": "bypassPermissions",
  "claudeCode.hideOnboarding": true
}

Anything you set wins over Ringleader’s three, and any setting you do not name is left exactly as it is, so a preference someone changes in the editor itself is not undone the next time the workstation applies its configuration:

config:
  auth: none
  settings:
    workbench.colorTheme: Default Dark Modern
    editor.fontSize: 14

When the workstation declares trusted folders, the workspace-trust prompt is turned off as well, again unless you set that key yourself.

config fields

FieldTypeDefaultDescription
authstringpasswordnone or password.
passwordstringnoneThe password, as a ${secret:NAME} reference.
portint8080The port code-server listens on.
bindAddrstring127.0.0.1The address code-server listens on: a bare IP or localhost, with no port. Leave it alone unless you know why you are changing it.
certbool or stringnonetrue for a self-signed certificate, or a path to one.
settingsobjectnoneEditor settings, as described above.

Ringleader refuses auth: none on any bindAddr other than loopback, and the workstation stops setting up. An unauthenticated browser IDE has a terminal in it, and on a public interface that is remote code execution for anyone who can reach the port.

How the files are written

Ringleader writes code-server’s own configuration file (~/.config/code-server/config.yaml) only when you set at least one of auth, password, port, bindAddr or cert. With none of those, code-server keeps the file it generates for itself, with its own random password, and Ringleader touches only the editor settings.

Both files (config.yaml and ~/.local/share/code-server/User/settings.json) belong to the login user and are readable by nobody else on the workstation, so a password or a resolved secret in them is not exposed.

The port you declare is checked every time the workstation applies its configuration, not only the first time. If code-server is not serving it, because it started before the configuration landed, crashed, or was restarted by hand, Ringleader restarts the service so it comes back on the declared port. A workstation already serving the right port is left alone.

Tool entries merge last-wins by id: a higher-priority config layer that sets auth replaces the whole vscode-web entry, so re-declare port there too if you moved it.