Runs code-server — VS Code in the browser, the well-known self-hosted editor — on Rigbox. Open the app and you get the full VS Code UI: file tree, editor, integrated terminal, extensions. This is an established off-the-shelf product, not hand-written app code.
The whole point here is running a real, third-party product as-is through a
reproducible deploy. rig.yaml's install: script puts code-server onto the
Rigbox base with its official installer, and reproducible: true freezes the
result so it only ever runs once:
reproducible: true
install: |
set -euo pipefail
# Install code-server (VS Code in the browser) on top of the rigbox base.
curl -fsSL https://code-server.dev/install.sh | sudo shNo Dockerfile — install: is the same script a plain deploy would run on the
VM; reproducible: true is what makes rig deploy freeze its result.
The deploy is hybrid — the image carries the environment, rsync carries the code:
- First
rig deploy: boots a throwaway builder VM from thebaseimage, runsinstall:inside it (code-server installed once), snapshots the rootfs as a content-addressed image, boots the workspace from it. - Later
rig deploy: if the build inputs (install:script, base image) are unchanged, it reuses the cached image — no re-install, fast.
cd code-server && rig deployNo required env — DATA_DIR is set in rig.yaml.
- The VS Code UI in the browser — open a file, use the integrated terminal, install an extension.
- The editor opens on
$DATA_DIR(/home/developer/data) as its workspace folder. Back up those files before image replacement.
- Persistence. User data, settings, extensions, and edited files live under
$DATA_DIR=/home/developer/data. Code-only redeploys preserve them; re-imaging replaces the root filesystem. Back up this directory before an image deployment. --auth noneis intentional. The app is private by default and the Rigbox gateway auth-gates anonymous traffic, so code-server's own password gate is redundant — the gateway is the front door. Don't set this apppublicwithout re-adding code-server auth.- Health:
GET /healthz→ 200 (served by code-server); the process binds0.0.0.0:8080.timeoutSeconds: 90covers a cold first boot.
This example explicitly uses workspace.deployment.strategy: image because its installer changes system packages, global executable paths, or shared tool configuration. The badge review shows image replacement and requires permission before replacing an existing workspace root filesystem. It is not an incremental app release. Use a dedicated workspace and back up root-filesystem development files; persistent volumes are retained. Migrating this installer to app-local releases remains separate work.