You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the RDP Desktop module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
6 / 17
20 / 20
2 / 2
7 / 10
71 / 100
Drilldown
Track: Utility (RDP desktop access module — not an AI agent, not an IDE)
Presentation & Onboarding — 6 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
6
README shows three examples (Basic, Custom display name, Generated credentials) covering the main use cases. However, the username and group variables are never demonstrated in any example block. The module has 7 input variables but only 4 are exercised across the examples.
Visual preview
5
0
No image, GIF, or video is embedded in the README. The frontmatter references an SVG icon (icon: ../../../../.icons/rdp.svg) but no  or <img> tag appears in the README body.
Credential Hygiene — 20 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
variable "password" in main.tf is marked sensitive = true. README tf code blocks do not inline the password as a literal; the "Basic Usage" section mentions the default in prose only, and the "Generated credentials" example uses random_password.rdp.result.
Non-hardcoded auth path
4
4
The "Generated credentials" section explicitly documents using random_password to produce a per-workspace password so the credential never lives in the template.
The module downloads and installs nothing. It ships a local configure-rdp.ps1 and invokes Coder provider resources only. No download URL exists to override.
Bring-your-own binary
10
N/A
No binary is downloaded or installed by the module. The PowerShell script is bundled in the module directory.
Egress transparency
3
N/A
The module contacts no external endpoints. The coder:// URI is handled by the Coder Desktop client on the user's machine, not by the module.
Runs without sudo
2
2
The configure-rdp.ps1 script (referenced via templatefile) performs firewall, service, and password operations. In a Coder Windows workspace the agent runs as Administrator by default; the script contains no explicit elevation call (Start-Process -Verb RunAs, sudo, etc.) and works in the admin context it is given.
Engineering Quality — 7 / 10
Criterion
Max
Score
Notes
Input quality
6
3
All 7 variables have clear description strings and sensible defaults. However, no variable uses a validation block (e.g., password has no minimum-length check, order has no range constraint). Descriptions and defaults are good; validation is absent.
Test coverage
4
4
local-windows-rdp.tftest.hcl covers business logic (default password encoding, special-character preservation in both the PowerShell script and the app URL). main.test.ts provides end-to-end tests via runTerraformApply verifying app slug, URI format, script content, custom credentials, sensitive-variable handling, and full URI regex. Clear separation of concerns.
Overall — 71 / 100
Raw 35 / 49 → round(35 / 49 × 100) = 71
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the RDP Desktop module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Track: Utility (RDP desktop access module — not an AI agent, not an IDE)
Presentation & Onboarding — 6 / 17
usernameandgroupvariables are never demonstrated in any example block. The module has 7 input variables but only 4 are exercised across the examples.icon: ../../../../.icons/rdp.svg) but noor<img>tag appears in the README body.Credential Hygiene — 20 / 20
variable "password"inmain.tfis markedsensitive = true. README tf code blocks do not inline the password as a literal; the "Basic Usage" section mentions the default in prose only, and the "Generated credentials" example usesrandom_password.rdp.result.random_passwordto produce a per-workspace password so the credential never lives in the template.Restricted-Environment Readiness — 2 / 2 (18 pts N/A)
configure-rdp.ps1and invokes Coder provider resources only. No download URL exists to override.coder://URI is handled by the Coder Desktop client on the user's machine, not by the module.configure-rdp.ps1script (referenced viatemplatefile) performs firewall, service, and password operations. In a Coder Windows workspace the agent runs as Administrator by default; the script contains no explicit elevation call (Start-Process -Verb RunAs,sudo, etc.) and works in the admin context it is given.Engineering Quality — 7 / 10
descriptionstrings and sensible defaults. However, no variable uses avalidationblock (e.g.,passwordhas no minimum-length check,orderhas no range constraint). Descriptions and defaults are good; validation is absent.local-windows-rdp.tftest.hclcovers business logic (default password encoding, special-character preservation in both the PowerShell script and the app URL).main.test.tsprovides end-to-end tests viarunTerraformApplyverifying app slug, URI format, script content, custom credentials, sensitive-variable handling, and full URI regex. Clear separation of concerns.Overall — 71 / 100
Raw 35 / 49 → round(35 / 49 × 100) = 71
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions