You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the KasmVNC module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
6 / 17
18 / 20
5 / 20
8 / 10
55 / 100
Drilldown
Presentation & Onboarding — 6 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
6
README shows a single example (desktop_environment = "xfce", subdomain = true). The module supports 8 desktop environments, subdomain on/off (path-based sharing), and 3 share levels, but no additional examples or mode documentation are provided.
Visual preview
5
0
No image, GIF, or video embedded in the README. The frontmatter references an SVG icon, which does not count.
Credential Hygiene — 18 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
No sensitive inputs exist in this module (no API keys, tokens, or passwords are user-supplied). The VNC password in run.sh is a placeholder explicitly noted as unused ("The server is protected via the Coder session token / tunnel"). README example contains no inline secrets.
Non-hardcoded auth path
4
2
The module inherently uses Coder's session-based auth (app tunnel, no public listener), but the README does not document this auth mechanism or explain how access is governed. The note exists only as a comment in run.sh.
Restricted-Environment Readiness — 5 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
The download URL is hardcoded in run.sh as https://github.com/kasmtech/KasmVNC/releases/download/v${KASM_VERSION}. No module input variable overrides this base URL. kasm_version only pins the version, not the source.
Bring-your-own binary
10
5
run.sh contains a check_installed() function that skips installation if kasmvncserver is already on PATH. However, this behavior is not documented in the README.
Egress transparency
3
0
No dedicated README section enumerates external endpoints (GitHub releases, apt/dnf repos). No air-gapped or restricted-network guidance is provided.
Runs without sudo
2
0
run.sh explicitly requires sudo -n true for the install step and exits with an error if unavailable. Package installation (apt-get, dnf, zypper) is core functionality and cannot proceed without root. A user-config fallback exists for the config file, but not for installation.
Engineering Quality — 8 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All 8 variables have clear descriptions. Sensible defaults provided (port = 6800, kasm_version = "1.4.0", subdomain = true, share = "owner"). Validation blocks on desktop_environment (whitelist) and share (enum).
Test coverage
4
2
main.test.ts tests required variables and applies the module across 5 desktop environments. However, it only asserts runTerraformApply does not throw—no assertions on app URL, subdomain behavior, share level, or port. No .tftest.hcl file present.
Overall — 55 / 100
Raw 37 / 67 → round(37 / 67 × 100) = 55
Track: Utility (VNC remote-desktop server; not an AI agent or IDE)
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the KasmVNC module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 6 / 17
desktop_environment = "xfce",subdomain = true). The module supports 8 desktop environments, subdomain on/off (path-based sharing), and 3 share levels, but no additional examples or mode documentation are provided.Credential Hygiene — 18 / 20
run.shis a placeholder explicitly noted as unused ("The server is protected via the Coder session token / tunnel"). README example contains no inline secrets.run.sh.Restricted-Environment Readiness — 5 / 20
run.shashttps://github.com/kasmtech/KasmVNC/releases/download/v${KASM_VERSION}. No module input variable overrides this base URL.kasm_versiononly pins the version, not the source.run.shcontains acheck_installed()function that skips installation ifkasmvncserveris already onPATH. However, this behavior is not documented in the README.run.shexplicitly requiressudo -n truefor the install step and exits with an error if unavailable. Package installation (apt-get, dnf, zypper) is core functionality and cannot proceed without root. A user-config fallback exists for the config file, but not for installation.Engineering Quality — 8 / 10
port = 6800,kasm_version = "1.4.0",subdomain = true,share = "owner"). Validation blocks ondesktop_environment(whitelist) andshare(enum).main.test.tstests required variables and applies the module across 5 desktop environments. However, it only assertsrunTerraformApplydoes not throw—no assertions on app URL, subdomain behavior, share level, or port. No.tftest.hclfile present.Overall — 55 / 100
Raw 37 / 67 → round(37 / 67 × 100) = 55
Track: Utility (VNC remote-desktop server; not an AI agent or IDE)
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions