- HCL 100%
Step 2 of 2 for the `kubernetes_persistent_volume_claim` → `_v1` migration (#6). ## Migration result All workspaces were updated to the #6 template and restarted. Home PVCs verified on the cluster afterwards: | Workspace | PVC UID | Created | Result | |---|---|---|---| | ghe-perso | `46f76366…` | 2026-05-30 | same volume, resourceVersion unchanged since before the migration | | beewise | `f0194552…` | 2026-05-30 | same volume | | red-reindeer-86 (test) | `83d83509…` | 2026-09-30 | same volume; `~/toto.txt` survived two builds on the migration version | ## Change - **Removed** the `kubernetes_persistent_volume_claim_v1.existing_home` data source and the `import` block. - **Kept** the `removed { destroy = false }` block, permanently, with a comment explaining why. For a workspace that somehow missed the migration, it turns what would be a **destroy of its home PVC** (reclaimPolicy Delete) into a harmless `already exists` error on create. The fix in that case is to re-run #6's import. ## Tested (plan only, Terraform 1.14.5 / kubernetes v3.2.1) | Scenario | PVC plan | Destroy | |---|---|---| | Migrated workspace (`_v1` in state, ghe-perso's real PVC) | `_v1`: update | 0 | | Straggler (old address still in state) | old: `forget`, `_v1`: `create` (would fail "already exists") | **0** | `terraform validate`: valid, no warnings. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Reviewed-on: #7 Reviewed-by: Guillaume "B.B." Van Hemmen <guillaumehemmen@noreply.git.van-hemmen.com> |
||
|---|---|---|
| main.tf | ||
| README.md | ||
| display_name | description | icon | maintainer_github | tags | |||||
|---|---|---|---|---|---|---|---|---|---|
| Sindri (Kubernetes Deployment) | Coder workspaces backed by the Sindri image — headless or full XFCE/noVNC desktop, selectable per workspace. | ../../../site/static/icon/k8s.png | GuillaumeHemmen |
|
Sindri Coder Template (Kubernetes Deployment)
Provisions a Kubernetes Deployment + PVC as a Coder workspace, using the Sindri image family. A single template covers both variants:
- Headless (
git.van-hemmen.com/actions/sindri:coder-<tag>) — lightweightcoderuser environment, code-server, JetBrains Gateway. - Desktop (
git.van-hemmen.com/actions/sindri:coder-xfce-vnc-<tag>) — same base plus an XFCE desktop served over noVNC.
Each user chooses which variant their workspace runs via a single checkbox at workspace creation
time. See the full image-variant feature list in the project README.md.
For template admins
Variables
| Variable | Required | Default | Description |
|---|---|---|---|
namespace |
yes | — | Kubernetes namespace to create workspaces in. Must already exist. |
use_kubeconfig |
no | false |
true if the Coder host is outside the workspace cluster and uses ~/.kube/config. false if Coder itself runs as a pod in the same cluster and uses its ServiceAccount. |
image_tag |
no | "latest" |
Sindri image tag shared by both variants. Pin to a specific build SHA or Tag (e.g. ecfb1a7adaf7188e97a4d8195d42720ae0b371f7) for reproducible workspaces — SHAs come from the Forgejo Actions builds and the registry tag list. |
image_pull_policy |
no | "auto" |
imagePullPolicy for the workspace container. auto derives it from image_tag: Always for the moving latest alias, IfNotPresent for pinned version/SHA tags. Set Always, IfNotPresent or Never to override. |
How the image is selected
The user-facing "Use with desktop" checkbox flips the image between the two variants while
keeping the same image_tag:
git.van-hemmen.com/actions/sindri:coder-<image_tag> # toggle OFF
git.van-hemmen.com/actions/sindri:coder-xfce-vnc-<image_tag> # toggle ON
Bumping every workspace to a newer build is a one-line image_tag change in the template.
Architecture
This template provisions:
- A Kubernetes Deployment (ephemeral pod).
- A Kubernetes PersistentVolumeClaim mounted at
/home/coder(persistent across workspace restarts).
Anything outside /home/coder is not persisted. The Sindri image is designed for this — the
per-user runtime (NVM/Node, bash prompt, gitignore, etc.) is provisioned at workspace start by
coder-init (and coder-init-desktop for the XFCE variant). See the main
README.md for details.
For workspace users
Choose your workspace flavor
When creating a workspace, you'll see:
- Use with desktop (XFCE + noVNC) — leave off for a lightweight headless workspace (code-server + JetBrains Gateway). Turn on for a full XFCE desktop accessible in your browser via noVNC, plus Firefox and JetBrains Toolbox preinstalled.
- CPU / Memory — pick the size you need. At least 4 cores and 8 GB RAM are recommended when running with the desktop enabled or when running JetBrains IDEs locally inside the workspace.
- Home disk size — size of the persistent
/home/codervolume.
You can flip "Use with desktop" on or off later by editing your workspace parameters and
restarting. The new image is pulled on the next start; your /home/coder PVC is preserved.
Apps exposed by the workspace
| App | Available in | Notes |
|---|---|---|
| code-server | Both variants | Browser-based VS Code at the workspace root. |
| Desktop (noVNC) | Desktop only | Hidden when "Use with desktop" is off. XFCE session via noVNC in the browser. |
| JetBrains Gateway | Both variants | Connects to the workspace over SSH — works fine on the headless variant too. |
More details
For the deeper image-variant feature lists, software-rendering notes, JetBrains Toolbox specifics,
and the PVC state matrix, see the project README.md.
Note
This template is a starting point. Fork and edit the Terraform if you need to extend it for your use case.