You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Four examples cover default usage, custom coder_github_auth_id, custom vault_github_auth_path, and custom vault_cli_version. However, the vault_namespace variable (a major option for Vault Enterprise) has no documented example. Half credit for incomplete option coverage.
Visual preview
5
5
README embeds ; file verified to exist at 116.7 KB.
Credential Hygiene — 20 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
No module input carries a secret value; all variables are configuration (URLs, paths, versions). The actual token is obtained at runtime via coder external-auth access-token. README examples contain no inline secrets or placeholder keys.
Non-hardcoded auth path
4
4
Authentication uses Coder's external auth mechanism (coder external-auth access-token "$GITHUB_EXTERNAL_AUTH_ID"), avoiding any raw key pasting into templates. The coder_github_auth_id variable selects which external auth to use.
Restricted-Environment Readiness — 7 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
The Vault CLI download URL is hardcoded in run.sh as https://releases.hashicorp.com/vault/.... No module input variable overrides this URL. vault_cli_version is a version pin, not a URL override. No variable names the download source.
Bring-your-own binary
10
5
run.sh checks command -v vault and skips installation if the matching version is already present (installation_needed=0). This is implemented in code but not documented in the README—no section tells users they can pre-bake Vault into their image. Half credit for undocumented behavior.
Egress transparency
3
0
No dedicated README section enumerates external endpoints (releases.hashicorp.com, the user-specified vault_addr). Endpoints are only visible in source code. No offline/air-gapped guidance.
Runs without sudo
2
2
run.sh attempts sudo mv vault /usr/local/bin/vault and, on failure, falls back to mkdir -p ~/.local/bin && mv vault ~/.local/bin/vault. The script degrades gracefully when sudo is absent; no root is required for core functionality.
Engineering Quality — 8 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All six variables have description fields. Sensible defaults on all optional variables (github, null, latest). vault_cli_version includes a validation block with a regex and clear error message. Required variables (agent_id, vault_addr) correctly lack defaults.
Test coverage
4
2
main.test.ts only calls testRequiredVariables to confirm agent_id and vault_addr are declared. No .tftest.hcl file exists. No business-logic tests (auth flow, version detection, namespace handling) and no end-to-end behavior tests. Minimal coverage.
Overall — 69 / 100
Raw 46 / 67 → round(46 / 67 × 100) = 69
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the Hashicorp Vault Integration (GitHub) module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 11 / 17
coder_github_auth_id, customvault_github_auth_path, and customvault_cli_version. However, thevault_namespacevariable (a major option for Vault Enterprise) has no documented example. Half credit for incomplete option coverage.; file verified to exist at 116.7 KB.Credential Hygiene — 20 / 20
coder external-auth access-token. README examples contain no inline secrets or placeholder keys.coder external-auth access-token "$GITHUB_EXTERNAL_AUTH_ID"), avoiding any raw key pasting into templates. Thecoder_github_auth_idvariable selects which external auth to use.Restricted-Environment Readiness — 7 / 20
run.shashttps://releases.hashicorp.com/vault/.... No module input variable overrides this URL.vault_cli_versionis a version pin, not a URL override. No variable names the download source.run.shcheckscommand -v vaultand skips installation if the matching version is already present (installation_needed=0). This is implemented in code but not documented in the README—no section tells users they can pre-bake Vault into their image. Half credit for undocumented behavior.vault_addr). Endpoints are only visible in source code. No offline/air-gapped guidance.run.shattemptssudo mv vault /usr/local/bin/vaultand, on failure, falls back tomkdir -p ~/.local/bin && mv vault ~/.local/bin/vault. The script degrades gracefully when sudo is absent; no root is required for core functionality.Engineering Quality — 8 / 10
descriptionfields. Sensible defaults on all optional variables (github,null,latest).vault_cli_versionincludes avalidationblock with a regex and clear error message. Required variables (agent_id,vault_addr) correctly lack defaults.main.test.tsonly callstestRequiredVariablesto confirmagent_idandvault_addrare declared. No.tftest.hclfile exists. No business-logic tests (auth flow, version detection, namespace handling) and no end-to-end behavior tests. Minimal coverage.Overall — 69 / 100
Raw 46 / 67 → round(46 / 67 × 100) = 69
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions