You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the RStudio Server module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
IDE Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
5 / 17
13 / 25
16 / 20
2 / 20
6 / 10
46 / 100
Drilldown
Presentation & Onboarding — 5 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
0
README shows a single bare-bones example (agent_id only). The module exposes 12+ variables (disable_auth, enable_renv, project_path, docker_socket, port, etc.) but no alternative mode examples are documented (e.g., with auth enabled, with a project path, with a custom Docker socket).
Visual preview
5
5
README embeds ; file verified to exist (191.1 KB).
Credential Hygiene — 16 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
rstudio_user and rstudio_password both carry sensitive = true. README example contains no inline secrets or placeholder keys.
Non-hardcoded auth path
4
0
Auth is limited to rstudio_user/rstudio_password passed as container env vars, or disabled entirely via disable_auth. No ServiceAccount, IAM, OAuth, API-key helper, or AI Gateway path is documented.
Restricted-Environment Readiness — 2 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
run.sh hardcodes IMAGE="rocker/rstudio:${SERVER_VERSION}" and calls docker pull "$${IMAGE}". No module input variable overrides the registry host or full image reference.
Bring-your-own binary
10
0
No variable or flag to skip docker pull or use a pre-loaded local image. The script unconditionally pulls on every start.
Egress transparency
3
0
No dedicated README section enumerating external endpoints. The script contacts Docker Hub and https://cloud.r-project.org (renv), but these are only visible in source code, not documented.
Runs without sudo
2
2
run.sh never invokes sudo. All operations use docker CLI commands, which work for any user in the docker group.
Engineering Quality — 6 / 10
Criterion
Max
Score
Notes
Input quality
6
6
All 12 variables carry description and sensible default values. share includes a validation block restricting to owner/authenticated/public.
Test coverage
4
0
No .tftest.hcl, no TypeScript tests, and no testing documentation are present in the module.
IDE Integration — 13 / 25
Criterion
Max
Score
Notes
Dashboard entry point
7
7
coder_app resource defined with subdomain = true, url = "http://localhost:${var.port}", icon, share, order, and group — proper launch behavior.
Managed configuration
6
0
No support for managed RStudio settings, .Rprofile, rstudio.conf, or policy files is documented or implemented.
Configurable folder or workdir
6
6
project_path variable (documented: "The path to RStudio project, it will be mounted in the container") is bind-mounted to /home/${RSTUDIO_USER}/project, allowing the user to start in a chosen directory.
Pre-installed extensions
6
0
No documented mechanism for pre-installing R packages, RStudio add-ons, or extensions at module deploy time. The optional renv restore is user-driven (requires a renv.lock in the project) and not a module-level pre-install feature.
Overall — 46 / 100
Raw 42 / 92 → round(42 / 92 × 100) = 46
Scored against SCORECARD.md on 2026-09-28 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the RStudio Server module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 5 / 17
agent_idonly). The module exposes 12+ variables (disable_auth,enable_renv,project_path,docker_socket,port, etc.) but no alternative mode examples are documented (e.g., with auth enabled, with a project path, with a custom Docker socket).; file verified to exist (191.1 KB).Credential Hygiene — 16 / 20
rstudio_userandrstudio_passwordboth carrysensitive = true. README example contains no inline secrets or placeholder keys.rstudio_user/rstudio_passwordpassed as container env vars, or disabled entirely viadisable_auth. No ServiceAccount, IAM, OAuth, API-key helper, or AI Gateway path is documented.Restricted-Environment Readiness — 2 / 20
run.shhardcodesIMAGE="rocker/rstudio:${SERVER_VERSION}"and callsdocker pull "$${IMAGE}". No module input variable overrides the registry host or full image reference.docker pullor use a pre-loaded local image. The script unconditionally pulls on every start.https://cloud.r-project.org(renv), but these are only visible in source code, not documented.run.shnever invokessudo. All operations usedockerCLI commands, which work for any user in thedockergroup.Engineering Quality — 6 / 10
descriptionand sensibledefaultvalues.shareincludes avalidationblock restricting toowner/authenticated/public..tftest.hcl, no TypeScript tests, and no testing documentation are present in the module.IDE Integration — 13 / 25
coder_appresource defined withsubdomain = true,url = "http://localhost:${var.port}", icon,share,order, andgroup— proper launch behavior..Rprofile,rstudio.conf, or policy files is documented or implemented.project_pathvariable (documented: "The path to RStudio project, it will be mounted in the container") is bind-mounted to/home/${RSTUDIO_USER}/project, allowing the user to start in a chosen directory.renvrestore is user-driven (requires arenv.lockin the project) and not a module-level pre-install feature.Overall — 46 / 100
Raw 42 / 92 → round(42 / 92 × 100) = 46
Scored against SCORECARD.md on 2026-09-28 with
solstice-1.All reactions