You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the Agent Relay Claude Code module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Agent Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
12 / 17
0 / 25
20 / 20
12 / 20
10 / 10
59 / 100
Drilldown
Presentation & Onboarding — 12 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
The module has a single operational mode (run the self-hosted runner) with a minor install_cli toggle. The README's main example shows install_cli = true with a comment explaining the bake-into-image alternative. All 7 input variables are documented in the Parameters section with sensible defaults and descriptions. No separate code example is needed for a module with this configuration surface.
Visual preview
5
0
No image, GIF, or video embedded in the README. The frontmatter references an icon file (claude.svg) but that is not a visual preview of the module in action.
Agent Integration — 0 / 25
Criterion
Max
Score
Notes
AI governance
10
0
No mention of Coder AI Gateway or Agent Firewall anywhere in the README or source. The module relies on Agent Relay's dispatch mechanism for credential delivery, but does not document how Coder governs auth, routing, or policy enforcement at the gateway/firewall level.
Dashboard entry point
5
0
No coder_app resource declared or documented. The module is a headless runner with no UI to open from the dashboard.
Session continuity
5
0
No documentation of resuming a Claude Code session across reconnects or relaunches. No mention of tmux, screen, boo, or native session-ID resume. The agent_relay_session_id parameter supports relay-level deduplication, not agent-session continuity.
Managed configuration
5
0
No documentation of managed MCP servers, settings files, policies, or workdir configuration. base_dir sets the session checkout directory but does not constitute managed agent configuration.
Credential Hygiene — 20 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
agent_relay_credential is styled with mask_input = true and is ephemeral. The README states "the credential is masked." No inline secrets appear in any README example; the only example shows agent_id and install_cli.
Non-hardcoded auth path
4
4
The README documents that the credential is a "Single-use work order JWT" stamped by Agent Relay on dispatch. The user never pastes a raw key; auth flows through the relay's dispatch mechanism into SELF_HOSTED_RUNNER_ENVIRONMENT_SECRET.
Restricted-Environment Readiness — 12 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
The install URL https://claude.ai/install.sh is hardcoded in install.sh.tftpl. No module input variable overrides this download URL. cli_binary overrides the binary path, not the source URL. install_cli is a skip toggle, not a URL override.
Bring-your-own binary
10
10
install_cli = false (documented in README: "Bake the CLI into the image and set this to false for faster workspaces") disables the download entirely. The install script checks command -v and skips when the binary is present. The start script adds ~/.local/bin to PATH unconditionally so a pre-baked CLI is found.
Egress transparency
3
0
No dedicated README section enumerates external endpoints. The install contacts claude.ai/install.sh (→ downloads.claude.ai) and the runner contacts Anthropic's API, but these are only visible in source code, not in a dedicated network/offline/air-gapped section.
Runs without sudo
2
2
All three scripts (install.sh.tftpl, start.sh.tftpl, status.sh.tftpl) never invoke sudo. The installer writes to ~/.local/bin; the start script creates directories under $HOME. No root required for core functionality.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All 7 variables have clear descriptions and sensible defaults. cli_binary has a regex validation rejecting shell metacharacters; exit_if_unused_min validates whole-number ≥ 0. Descriptions explain the "why" (e.g., why base_dir defaults to $HOME/workspace rather than the CLI's /workspace).
Test coverage
4
4
main.tftest.hcl covers the parameter contract (names, ephemeral flags, styling), runner wiring (env var names, script ordering, state-file consistency), install behavior, and injection safety. main.test.ts runs the actual install/start scripts in a container with a stub claude binary, verifying lifecycle states (idle, working, done, failed), wrapper behavior, exit codes, path overrides, and serving_log_pattern as fixed-string data.
Overall — 59 / 100
Raw 54 / 92 → round(54 / 92 × 100) = 59
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the Agent Relay Claude Code module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 12 / 17
install_clitoggle. The README's main example showsinstall_cli = truewith a comment explaining the bake-into-image alternative. All 7 input variables are documented in the Parameters section with sensible defaults and descriptions. No separate code example is needed for a module with this configuration surface.claude.svg) but that is not a visual preview of the module in action.Agent Integration — 0 / 25
coder_appresource declared or documented. The module is a headless runner with no UI to open from the dashboard.agent_relay_session_idparameter supports relay-level deduplication, not agent-session continuity.base_dirsets the session checkout directory but does not constitute managed agent configuration.Credential Hygiene — 20 / 20
agent_relay_credentialis styled withmask_input = trueand is ephemeral. The README states "the credential is masked." No inline secrets appear in any README example; the only example showsagent_idandinstall_cli.SELF_HOSTED_RUNNER_ENVIRONMENT_SECRET.Restricted-Environment Readiness — 12 / 20
https://claude.ai/install.shis hardcoded ininstall.sh.tftpl. No module input variable overrides this download URL.cli_binaryoverrides the binary path, not the source URL.install_cliis a skip toggle, not a URL override.install_cli = false(documented in README: "Bake the CLI into the image and set this to false for faster workspaces") disables the download entirely. The install script checkscommand -vand skips when the binary is present. The start script adds~/.local/binto PATH unconditionally so a pre-baked CLI is found.claude.ai/install.sh(→downloads.claude.ai) and the runner contacts Anthropic's API, but these are only visible in source code, not in a dedicated network/offline/air-gapped section.install.sh.tftpl,start.sh.tftpl,status.sh.tftpl) never invokesudo. The installer writes to~/.local/bin; the start script creates directories under$HOME. No root required for core functionality.Engineering Quality — 10 / 10
cli_binaryhas a regex validation rejecting shell metacharacters;exit_if_unused_minvalidates whole-number ≥ 0. Descriptions explain the "why" (e.g., whybase_dirdefaults to$HOME/workspacerather than the CLI's/workspace).main.tftest.hclcovers the parameter contract (names, ephemeral flags, styling), runner wiring (env var names, script ordering, state-file consistency), install behavior, and injection safety.main.test.tsruns the actual install/start scripts in a container with a stubclaudebinary, verifying lifecycle states (idle, working, done, failed), wrapper behavior, exit codes, path overrides, andserving_log_patternas fixed-string data.Overall — 59 / 100
Raw 54 / 92 → round(54 / 92 × 100) = 59
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions