You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the JFrog (OAuth) module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
17 / 17
20 / 20
14 / 20
10 / 10
91 / 100
Drilldown
Presentation & Onboarding — 17 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
Multiple major modes each have a dedicated documented example: full package-manager config (main example), access-token-only mode (dedicated section with install_jfrog_cli = false / configure_jfrog_cli = false), code-server configuration (configure_code_server = true), username-field choice (username vs email), and reusing the token in other Terraform resources. All examples use sensible defaults.
Visual preview
5
5
README embeds ; file verified to exist at 47.9 KB.
Credential Hygiene — 20 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
output "access_token" is marked sensitive = true. The token is sourced from data.coder_external_auth.jfrog (Coder-managed OAuth), so no secret is a module input. README module examples contain no inline keys or tokens; the only placeholder (CODER_EXTERNAL_AUTH_1_CLIENT_SECRET="XXXXXXXXXXXXXXXXXXX") appears in the admin-level Coder deployment setup, not in a module usage example.
Non-hardcoded auth path
4
4
README explicitly documents Coder external-auth OAuth flow: "Each user authenticates through an OAuth flow and receives a user-scoped access token, so no API keys or passwords are stored in the template or the workspace." No raw keys are pasted into templates.
Restricted-Environment Readiness — 14 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
The JFrog CLI is downloaded from the hardcoded URL https://install-cli.jfrog.io in run.sh (curl -fL https://install-cli.jfrog.io | sudo sh). No module input variable overrides this download URL. jfrog_url is the Artifactory instance URL, not the CLI installer URL. No variable exists to point the installer at an internal mirror.
Bring-your-own binary
10
10
README documents: "If jf is already on the PATH … set install_jfrog_cli = false to disable the download explicitly." run.sh checks command -v jf and skips installation when the flag is false or the binary is present. Fully documented and functional.
Egress transparency
3
3
Dedicated "### External endpoints" subsection under "Offline and air-gapped environments" enumerates both contacted endpoints: https://install-cli.jfrog.io (CLI install, conditional) and the user's jfrog_url (package-manager config / token exchange).
Runs without sudo
2
1
run.sh invokes sudo sh and sudo chmod 755 during CLI installation. This is an optional feature (disabled via install_jfrog_cli = false), and the README documents the no-sudo path ("pre-install jf in your workspace image to avoid both the external download and the sudo step"). Sudo is needed only for the optional install with a working fallback → half.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All 9 variables have clear description fields. jfrog_url has a regex validation (must start with http/https). username_field has a regex validation (must be email or username). package_managers has a multi-line description with a concrete example. Sensible defaults throughout (install_jfrog_cli = true, configure_jfrog_cli = true, username_field = "username", external_auth_id = "jfrog").
Test coverage
4
4
jfrog-oauth.tftest.hcl contains 13 test runs covering: required vars, empty-token edge case (template import), valid token, URL validation, username-field validation, each package manager (npm, go, pypi, docker, conda, maven), code-server env vars, and access-token-only mode. Tests use override_data to mock external auth and assert on script content, env values, and resource counts. Clear business-logic coverage.
Overall — 91 / 100
Raw 61 / 67 → round(61 / 67 × 100) = 91
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the JFrog (OAuth) module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 17 / 17
install_jfrog_cli = false/configure_jfrog_cli = false), code-server configuration (configure_code_server = true), username-field choice (usernamevsemail), and reusing the token in other Terraform resources. All examples use sensible defaults.; file verified to exist at 47.9 KB.Credential Hygiene — 20 / 20
output "access_token"is markedsensitive = true. The token is sourced fromdata.coder_external_auth.jfrog(Coder-managed OAuth), so no secret is a module input. README module examples contain no inline keys or tokens; the only placeholder (CODER_EXTERNAL_AUTH_1_CLIENT_SECRET="XXXXXXXXXXXXXXXXXXX") appears in the admin-level Coder deployment setup, not in a module usage example.external-authOAuth flow: "Each user authenticates through an OAuth flow and receives a user-scoped access token, so no API keys or passwords are stored in the template or the workspace." No raw keys are pasted into templates.Restricted-Environment Readiness — 14 / 20
https://install-cli.jfrog.ioinrun.sh(curl -fL https://install-cli.jfrog.io | sudo sh). No module input variable overrides this download URL.jfrog_urlis the Artifactory instance URL, not the CLI installer URL. No variable exists to point the installer at an internal mirror.jfis already on thePATH… setinstall_jfrog_cli = falseto disable the download explicitly."run.shcheckscommand -v jfand skips installation when the flag is false or the binary is present. Fully documented and functional.https://install-cli.jfrog.io(CLI install, conditional) and the user'sjfrog_url(package-manager config / token exchange).run.shinvokessudo shandsudo chmod 755during CLI installation. This is an optional feature (disabled viainstall_jfrog_cli = false), and the README documents the no-sudo path ("pre-installjfin your workspace image to avoid both the external download and thesudostep"). Sudo is needed only for the optional install with a working fallback → half.Engineering Quality — 10 / 10
descriptionfields.jfrog_urlhas a regex validation (must start with http/https).username_fieldhas a regex validation (must beemailorusername).package_managershas a multi-line description with a concrete example. Sensible defaults throughout (install_jfrog_cli = true,configure_jfrog_cli = true,username_field = "username",external_auth_id = "jfrog").jfrog-oauth.tftest.hclcontains 13 test runs covering: required vars, empty-token edge case (template import), valid token, URL validation, username-field validation, each package manager (npm, go, pypi, docker, conda, maven), code-server env vars, and access-token-only mode. Tests useoverride_datato mock external auth and assert on script content, env values, and resource counts. Clear business-logic coverage.Overall — 91 / 100
Raw 61 / 67 → round(61 / 67 × 100) = 91
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions