vscode-web
VS Code in your browser, running on the workstation: the few lines that make it work, and the settings for when you need more.
This toolconfig tells code-server, VS Code in a browser tab, how to run on your
workstation. The vscode-web devtool
installs it; this configures it.
Set it up
For most people this is the whole configuration. Add it to a WorkstationConfig that selects your workstations:
spec:
devtools:
- name: vscode-web
toolconfigs:
- id: vscode-web
name: vscode-web
config:
auth: none
ports:
- 8080
defaultLocalBinding:
enabled: true
autoForward:
forwardAll: trueThen open http://127.0.0.1:8080 on your laptop. That is your workstation’s VS Code.
auth: none is safe here because code-server listens only on the workstation’s own
loopback address, and the only way to reach it is the port forward Ringleader sets up
to your laptop. Nobody else can connect to it.
If that is all you need, you are done. The rest of this page is for when you want something different: a password, a different port, editor settings, or the full list of fields.
Requiring a password
Store the password as a Secret, then point the toolconfig at it:
rl secret create vscode-web-password -n local \
--from-string vscode-web-password=<choose-a-password>toolconfigs:
- id: vscode-web
name: vscode-web
config:
auth: password
password: "${secret:vscode-web-password}"Changing the password later restarts code-server for you, since it reads the password only when it starts.
Changing the port
If something else on the workstation already uses 8080, move code-server. Set port
and auth together, and forward the new port:
toolconfigs:
- id: vscode-web
name: vscode-web
config:
port: 8081
auth: none
ports:
- 8080 # your app
- 8081 # the IDESetting the port alone leaves nobody able to log in
port, bindAddr or cert, set auth in the same block. A field
you leave out takes its default, and the default for auth is password, so port: 8081 on its own gives you password authentication with no password. Set auth: none
(safe on the default loopback bind) or auth: password with a password.Tool configuration is applied before your provisioning scripts run, so code-server has already moved by the time a script starts your app on 8080.
Editor settings
You do not need this section to use the editor. code-server has the same settings as
desktop VS Code. To set editor settings for everyone who uses the workstation, put them
under settings.
Ringleader also writes three settings for the Claude Code extension, so that if you use it, its panel opens without permission prompts or onboarding. They have no effect on any other tool:
{
"claudeCode.allowDangerouslySkipPermissions": true,
"claudeCode.initialPermissionMode": "bypassPermissions",
"claudeCode.hideOnboarding": true
}Anything you set wins over Ringleader’s three, and any setting you do not name is left exactly as it is, so a preference someone changes in the editor itself is not undone the next time the workstation applies its configuration:
config:
auth: none
settings:
workbench.colorTheme: Default Dark Modern
editor.fontSize: 14When the workstation declares trusted folders, the workspace-trust prompt is turned off as well, again unless you set that key yourself.
config fields
| Field | Type | Default | Description |
|---|---|---|---|
auth | string | password | none or password. |
password | string | none | The password, as a ${secret:NAME} reference. |
port | int | 8080 | The port code-server listens on. |
bindAddr | string | 127.0.0.1 | The address code-server listens on: a bare IP or localhost, with no port. Leave it alone unless you know why you are changing it. |
cert | bool or string | none | true for a self-signed certificate, or a path to one. |
settings | object | none | Editor settings, as described above. |
Ringleader refuses auth: none on any bindAddr other than loopback, and the
workstation stops setting up. An unauthenticated browser IDE has a terminal in it, and
on a public interface that is remote code execution for anyone who can reach the port.
How the files are written
Ringleader writes code-server’s own configuration file
(~/.config/code-server/config.yaml) only when you set at least one of auth,
password, port, bindAddr or cert. With none of those, code-server keeps the file
it generates for itself, with its own random password, and Ringleader touches only the
editor settings.
Both files (config.yaml and ~/.local/share/code-server/User/settings.json) belong to
the login user and are readable by nobody else on the workstation, so a password or a
resolved secret in them is not exposed.
The port you declare is checked every time the workstation applies its configuration, not only the first time. If code-server is not serving it, because it started before the configuration landed, crashed, or was restarted by hand, Ringleader restarts the service so it comes back on the declared port. A workstation already serving the right port is left alone.
Tool entries merge last-wins by id: a higher-priority config layer that sets auth
replaces the whole vscode-web entry, so re-declare port there too if you moved it.