You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the Mux module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
Agent Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
17 / 17
5 / 25
20 / 20
18.5 / 20
10 / 10
77 / 100
Drilldown
Presentation & Onboarding — 17 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
12
Ten distinct examples covering every major mode: basic, pin version, add-project, additional arguments, restart-on-kill, custom port, custom package manager (npm/pnpm/bun), custom registry, use-cached, and skip-install. Each shows sensible defaults and the relevant variable.
Visual preview
5
5
README embeds ; file verified present at 249.1 KB.
Credential Hygiene — 20 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
No user-provided secrets exist; the auth token is auto-generated via random_password. No README example contains an inline key or placeholder secret.
Non-hardcoded auth path
4
4
The module generates a per-instance 64-char token with random_password and injects it into the process env and app URL. No user ever pastes a raw key into a template.
Restricted-Environment Readiness — 18.5 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
5
registry_url (default https://registry.npmjs.org) overrides the download URL for @coder/xum in all install paths (npm/pnpm/bun --registry flag and tarball fallback META_URL). Documented in the "Custom Registry" example.
Bring-your-own binary
10
10
install = false skips all network install and expects a pre-baked binary at install_prefix/mux. use_cached = true reuses an existing copy. Both documented with dedicated README examples ("Skip Install", "Use Cached Installation").
Egress transparency
3
1.5
The "Notes" section mentions npm registry, Node.js bootstrap from nodejs.org, and "requires internet connectivity," but there is no dedicated network/egress/air-gapped section enumerating the specific endpoints contacted. Scattered mentions across Notes and examples earn at most half per calibration.
Runs without sudo
2
2
run.sh installs to $HOME/.coder-modules/coder/mux, uses mkdir -p, curl, tar, npm install, ln -sf, chmod +x—no sudo invocation anywhere. Works entirely as an unprivileged user.
Engineering Quality — 10 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All 21 variables carry description and sensible defaults. validation blocks guard package_manager, restart_delay_seconds, max_restart_attempts, share, and open_in. A lifecycle.precondition catches the install=false + use_cached=true conflict.
Test coverage
4
4
mux.tftest.hcl (20+ runs) covers validation, conflict detection, script-content assertions, path defaults, registry override, and package-manager selection. main.test.ts (6 tests) exercises end-to-end install (tarball + npm), argument parsing, signal-kill logging, clean-exit restart, SIGTERM restart, and restart-cap enforcement in real containers.
Agent Integration — 5 / 25
Criterion
Max
Score
Notes
AI governance
10
0
No mention of Coder AI Gateway or Agent Firewall in the README or code. The module's own random_password token is a local auth mechanism, not Coder-governed routing or policy enforcement.
Dashboard entry point
5
5
Built-in coder_app resource with healthcheck (/health, 5 s interval, 6 threshold), configurable subdomain, share, order, group, and open_in. Documented via the app URL and all README examples.
Session continuity
0
0
The Features list mentions "Resume AI work after interruptions" as a Mux capability, but the module documents no session-ID, resume flag, or persistent session manager (tmux/screen/boo). No README section explains how to continue an agent session across reconnects.
Managed configuration
0
0
No documented support for managed MCP servers, settings files, policies, or workdir configuration. add_project opens a folder; additional_arguments passes CLI flags—neither constitutes managed agent configuration.
Overall — 77 / 100
Raw 70.5 / 92 → round(70.5 / 92 × 100) = 77
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the Mux module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 17 / 17
; file verified present at 249.1 KB.Credential Hygiene — 20 / 20
random_password. No README example contains an inline key or placeholder secret.random_passwordand injects it into the process env and app URL. No user ever pastes a raw key into a template.Restricted-Environment Readiness — 18.5 / 20
registry_url(defaulthttps://registry.npmjs.org) overrides the download URL for@coder/xumin all install paths (npm/pnpm/bun--registryflag and tarball fallbackMETA_URL). Documented in the "Custom Registry" example.install = falseskips all network install and expects a pre-baked binary atinstall_prefix/mux.use_cached = truereuses an existing copy. Both documented with dedicated README examples ("Skip Install", "Use Cached Installation").run.shinstalls to$HOME/.coder-modules/coder/mux, usesmkdir -p,curl,tar,npm install,ln -sf,chmod +x—nosudoinvocation anywhere. Works entirely as an unprivileged user.Engineering Quality — 10 / 10
descriptionand sensible defaults.validationblocks guardpackage_manager,restart_delay_seconds,max_restart_attempts,share, andopen_in. Alifecycle.preconditioncatches theinstall=false+use_cached=trueconflict.mux.tftest.hcl(20+ runs) covers validation, conflict detection, script-content assertions, path defaults, registry override, and package-manager selection.main.test.ts(6 tests) exercises end-to-end install (tarball + npm), argument parsing, signal-kill logging, clean-exit restart, SIGTERM restart, and restart-cap enforcement in real containers.Agent Integration — 5 / 25
random_passwordtoken is a local auth mechanism, not Coder-governed routing or policy enforcement.coder_appresource with healthcheck (/health, 5 s interval, 6 threshold), configurablesubdomain,share,order,group, andopen_in. Documented via the app URL and all README examples.add_projectopens a folder;additional_argumentspasses CLI flags—neither constitutes managed agent configuration.Overall — 77 / 100
Raw 70.5 / 92 → round(70.5 / 92 × 100) = 77
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions