• 26.37.0 13272e2efd

    26.37.0
    All checks were successful
    / docker-tag-ci (push) Successful in 3m50s
    / docker-tag-coder (push) Successful in 4m29s
    / docker-tag-coder-xfce-vnc (push) Successful in 9m19s
    Stable

    claude-bot released this 2026-09-11 09:32:10 +00:00 | 0 commits to master since this release

    What's new in 26.37.0

    Freelens replaces Lens in the desktop variant, the images now install Ubuntu packages from the France mirror, python3 -m venv works out of the box, and two fixes for the coder-xfce-vnc build.

    ⚠️ Ubuntu packages now come from the France mirror (#29)

    This changes the published images. They now use http://fr.archive.ubuntu.com/ubuntu instead of archive.ubuntu.com and security.ubuntu.com, for both the regular archive and security updates. It applies at build time, to apt-get inside containers and workspaces, and to images built FROM Sindri.

    Why: on 2026-09-11 Canonical's main archive went down. Every apt-get stalled, the desktop build went from about 10 minutes to 48, and a release couldn't wait for it to recover. Country mirrors run on separate hosts and kept working.

    What it means for you:

    • Integrity is unchanged: APT still checks every package list against Ubuntu's archive signing key.
    • Security updates can arrive later: the mirror can lag security.ubuntu.com by a few hours.
    • Check which mirror an image uses: docker inspect label com.van-hemmen.sindri.ubuntu-mirror, or grep '^URIs:' /etc/apt/sources.list.d/ubuntu.sources.
    • Choose another mirror when building: --build-arg UBUNTU_MIRROR=http://<cc>.archive.ubuntu.com/ubuntu. An empty value (--build-arg UBUNTU_MIRROR=) keeps Ubuntu's stock sources.
    • Restore the stock sources in an existing image: Ubuntu's original file is kept at /usr/share/sindri/ubuntu.sources.orig.
      • In a derived image: cp /usr/share/sindri/ubuntu.sources.orig /etc/apt/sources.list.d/ubuntu.sources
      • In a workspace: the same command with sudo. /etc isn't on the PVC, so add it to a Coder startup_script to keep it across restarts.

    Full details are in the README's Ubuntu Package Mirror section.

    Freelens replaces Lens in coder-xfce-vnc (#23)

    The desktop variant now ships Freelens, the MIT-licensed community fork of OpenLens, instead of proprietary Lens. It installs from Freelens's official APT repository, and the build checks the signing key's fingerprint before trusting it. Every build picks up the latest Freelens release.

    Freelens launches the same way Lens did: through /usr/local/bin/freelens and a menu entry under Development, with the settings Electron apps need in an unprivileged pod (ELECTRON_DISABLE_SANDBOX=1, --disable-dev-shm-usage).

    If you used Lens in an existing workspace:

    • Freelens stores its data in ~/.config/Freelens/, not ~/.config/Lens/, so clusters added in Lens need to be added again. ~/.kube/config is read as usual.
    • lens-desktop and its wrapper are gone. coder-init-desktop no longer tidies stale Lens menu entries.

    python3-venv in every variant (#22)

    The base image now includes python3-venv, so python3 -m venv works in ci, coder and coder-xfce-vnc. Firebase Python deploys and CI jobs no longer need to apt-get install python3-venv themselves.

    Fixes

    • coder-xfce-vnc build (#25): Nimbalyst 0.36 renamed the files inside its AppImage (@nimbalystelectron → nimbalyst), which broke the build with no error message. The build uses the new names, and if a file goes missing it now says which one and lists the bundle's contents.
    • Image publishing (#27): CI now pushes images to Forgejo's in-cluster registry service instead of through the public ingress, which cut large layer uploads off after 60 seconds (502 Bad Gateway). This needs actions/kaniko 26.37.0 (new REGISTRY_INSECURE setting). Image names don't change: pull from git.van-hemmen.com/actions/sindri:<tag> as before.

    Full changelog: 26.30.0...26.37.0

    Downloads
  • 26.30.0 018739bd48

    26.30.0
    All checks were successful
    / docker-tag-ci (push) Successful in 5m39s
    / docker-tag-coder (push) Successful in 6m15s
    / docker-tag-coder-xfce-vnc (push) Successful in 24m15s
    Stable

    GuillaumeHemmen released this 2026-07-24 07:12:28 +00:00 | 5 commits to master since this release

    What's new in 26.30.0

    A build-breaking upstream package rename fixed by moving Claude Desktop to Anthropic's official APT repo, plus Kubernetes manifest QA tooling in every variant.

    Claude Desktop now installs from Anthropic's official APT repo (#19)

    Anthropic released an official Claude Desktop for Linux beta and took the claude-desktop package name with it. The community claude-desktop-debian repack this image used therefore renamed itself to claude-desktop-unofficial, leaving claude-desktop behind as a transitional dummy — so apt-get install claude-desktop kept succeeding while every path the build asserted had moved. This broke the coder-xfce-vnc build on every branch from 2026-07-22.

    The coder-xfce-vnc variant now installs Anthropic's official package — same upstream app at the same version (1.24012.0), one fewer third-party repo — with the published signing-key fingerprint asserted before the key is trusted.

    Because Anthropic's deb symlinks /usr/bin/claude-desktop straight to the bundled Electron binary, where the community repack shipped a shell launcher, /usr/local/bin/claude-desktop is now the only place the unprivileged-pod settings (ELECTRON_DISABLE_SANDBOX=1, --disable-dev-shm-usage) get applied. The desktop-entry override follows upstream's com.anthropic.Claude.desktop, and its New chat / New Claude Code session actions are wrapper-routed too.

    Workspaces on a long-lived PVC self-heal: coder-init-desktop.sh now parks stale user-local entries under all three known names (claude-desktop.desktop, claude-desktop-unofficial.desktop, com.anthropic.Claude.desktop).

    Linux support is an Anthropic-labelled beta: no Computer Use, no dictation, Debian-based distributions only.

    kubeconform + kube-linter in the base image (#18)

    Installs kubeconform (manifest schema validation) and kube-linter (lint) as pinned prebuilt binaries in the base stage, so the ci, coder, and coder-xfce-vnc variants all ship them. This replaces a per-job actions/setup-go + go install …@latest — a Go-toolchain download plus a from-source compile of each tool on every run — with binaries present at job start.

    Full changelog: 26.25.1...26.30.0

    Downloads
  • 26.25.1 80b73d32e7

    26.25.1
    All checks were successful
    / docker-tag-coder (push) Successful in 4m41s
    / docker-tag-ci (push) Successful in 5m58s
    / docker-tag-coder-xfce-vnc (push) Successful in 16m10s
    Stable

    GuillaumeHemmen released this 2026-06-21 18:57:28 +00:00 | 7 commits to master since this release

    What's new in 26.25.1

    The Firebase CLI is now available in every variant.

    Firebase CLI (#16)

    Installs firebase-tools (the standalone binary, which bundles its own Node runtime) in the base stage, so the ci, coder, and coder-xfce-vnc variants all ship the firebase command. Combined with the Azul Zulu JDK already in the base, this enables firebase deploy and the Firebase Emulator Suite (for example Firestore security-rules unit-testing) in CI — no separate image needed.

    Full changelog: 26.25.0...26.25.1

    Downloads
  • 26.25.0 8d7cc385f6

    26.25.0
    All checks were successful
    / docker-tag-coder (push) Successful in 3m9s
    / docker-tag-ci (push) Successful in 3m25s
    / docker-tag-coder-xfce-vnc (push) Successful in 8m44s
    Stable

    GuillaumeHemmen released this 2026-06-20 14:58:49 +00:00 | 8 commits to master since this release

    What's new in 26.25.0

    Two applications added to the coder-xfce-vnc desktop variant, plus an XFCE menu tidy-up.

    Nimbalyst (#13)

    Bundles Nimbalyst — a visual workspace for building with Codex, Claude Code, and more. Upstream ships only a Linux AppImage, which can't self-mount via FUSE in an unprivileged pod (no CAP_SYS_ADMIN), so the build pulls the always-latest release and pre-extracts it to /opt/nimbalyst, then routes every launch through /usr/local/bin/nimbalyst (applying ELECTRON_DISABLE_SANDBOX=1, --disable-dev-shm-usage, and APPDIR=/opt/nimbalyst).

    LibreOffice (#14)

    Installs the LibreOffice suite (Writer, Calc, Impress, Draw, Base, Math) plus libreoffice-gtk3 for native GTK rendering under XFCE, and the English (US + GB) and French Hunspell spell-check dictionaries.

    XFCE menu

    Lens, Claude Desktop, and Nimbalyst now appear under the Development category (previously Network / Office / Utility).

    Full changelog: 26.24.2...26.25.0

    Downloads
  • 26.24.2 eb65649f42

    26.24.2
    All checks were successful
    / docker-tag-ci (push) Successful in 3m36s
    / docker-tag-coder (push) Successful in 4m7s
    / docker-tag-coder-xfce-vnc (push) Successful in 8m15s
    Stable

    GuillaumeHemmen released this 2026-06-11 16:15:27 +00:00 | 10 commits to master since this release

    This release includes:

    • Claude Desktop pre-installed in the xcfe variant, from the community claude-desktop-debian APT repo, launched through a wrapper applying the flags Electron apps need in unprivileged Kubernetes pods — menu, terminal, and claude:// URL launches alike
    • coder-init-desktop now parks stale user-local Claude Desktop menu entries left by manual installs from before the image shipped it (#12)
    Downloads
  • 26.24.1 b5bb798bce

    26.24.1
    All checks were successful
    / docker-tag-ci (push) Successful in 3m47s
    / docker-tag-coder (push) Successful in 4m25s
    / docker-tag-coder-xfce-vnc (push) Successful in 8m31s
    Stable

    GuillaumeHemmen released this 2026-06-11 15:12:52 +00:00 | 11 commits to master since this release

    This release includes:

    • Fix: Electron apps (Lens, Claude Desktop, ...) now launch in the xcfe variant on unprivileged Kubernetes pods — the Chromium sandbox cannot work there (RuntimeDefault seccomp, no CAP_SYS_ADMIN), so it is disabled image-wide via ELECTRON_DISABLE_SANDBOX=1, and Lens is routed through a wrapper adding --disable-dev-shm-usage for the 64 MiB /dev/shm
    • Fix: dead jetbrains-toolbox symlink in /usr/local/bin (Toolbox 2.x keeps the binary under bin/)
    • coder-init-desktop now heals stale user-local Lens menu entries carried over on the PVC

    Full diagnosis in the README section "Electron & Chromium-based apps" (#11)

    Downloads
  • 26.24.0 c0b0a96921

    26.24.0
    All checks were successful
    / docker-tag-ci (push) Successful in 3m4s
    / docker-tag-coder (push) Successful in 3m33s
    / docker-tag-coder-xfce-vnc (push) Successful in 6m51s
    Stable

    GuillaumeHemmen released this 2026-06-08 19:47:18 +00:00 | 12 commits to master since this release

    This release includes:

    • k8s tooling for the coder variant
    • lens k8s IDE for the xcfe variant
    Downloads
  • 26.23.0 e33cf43cf5

    26.23.0
    All checks were successful
    / docker-tag-ci (push) Successful in 3m16s
    / docker-tag-coder (push) Successful in 3m50s
    / docker-tag-coder-xfce-vnc (push) Successful in 6m1s
    Stable

    GuillaumeHemmen released this 2026-06-04 07:02:36 +00:00 | 13 commits to master since this release

    Added a few new package in the base image to support dev workflow:

    • glab
    • bat
    • fzf
    Downloads
  • 26.22.2 a71d023ceb

    26.22.2
    All checks were successful
    / docker-tag-coder (push) Successful in 3m41s
    / docker-tag-ci (push) Successful in 3m43s
    / docker-tag-coder-xfce-vnc (push) Successful in 6m1s
    Stable

    GuillaumeHemmen released this 2026-05-30 08:59:12 +00:00 | 14 commits to master since this release

    hotfix - adding support of colored emoji on desktop terminal

    Downloads
  • 26.22.1 75aa0846a7

    26.22.1
    All checks were successful
    / docker-tag-ci (push) Successful in 3m33s
    / docker-tag-coder (push) Successful in 3m49s
    / docker-tag-coder-xfce-vnc (push) Successful in 5m58s
    Stable

    GuillaumeHemmen released this 2026-05-30 08:34:44 +00:00 | 15 commits to master since this release

    hotfix seeding .profile from etc/skel

    Downloads