You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A discussion dedicated to the RStudio Server module. Share your thoughts, questions, and feedback here.
Module Scorecard
Presentation & Onboarding
IDE Integration
Credential Hygiene
Restricted-Environment Readiness
Engineering Quality
Overall
11 / 17
13 / 25
16 / 20
2 / 20
3 / 10
49 / 100
Drilldown
Presentation & Onboarding — 11 / 17
Criterion
Max
Score
Notes
Configuration-mode examples
12
6
README shows a single bare-bones example (agent_id only). The module exposes 12+ variables (auth on/off, project_path, docker_socket, enable_renv, custom port, share, etc.) but no documented examples for any major mode (e.g., auth-enabled, project-mounted, custom registry).
Visual preview
5
5
README embeds ; file verified to exist (191.1 KB).
Credential Hygiene — 16 / 20
Criterion
Max
Score
Notes
Secrets marked sensitive
16
16
rstudio_user and rstudio_password both carry sensitive = true. README example contains no inline secrets or placeholder keys.
Non-hardcoded auth path
4
0
No alternative auth mechanism documented. When disable_auth = false, the only path is username/password via rstudio_user/rstudio_password. No ServiceAccount, IAM, OAuth, API-key helper, or AI Gateway option is mentioned.
Restricted-Environment Readiness — 2 / 20
Criterion
Max
Score
Notes
Mirrorable artifact source
5
0
run.sh hardcodes IMAGE="rocker/rstudio:${SERVER_VERSION}" and calls docker pull. No module variable overrides the registry or image URL. rstudio_server_version only pins the tag, not the source.
Bring-your-own binary
10
0
No variable or flag to skip docker pull or use a pre-loaded local image. The script unconditionally pulls on every start.
Egress transparency
3
0
No dedicated README section enumerating external endpoints (Docker Hub, cloud.r-project.org for renv). No air-gapped or restricted-network guidance.
Runs without sudo
2
2
run.sh never invokes sudo. All operations are docker CLI commands, which work for any user in the docker group.
Engineering Quality — 3 / 10
Criterion
Max
Score
Notes
Input quality
6
3
12 of 13 variables have descriptions and sensible defaults; share has validation but is missing a description. No other validation blocks present (e.g., port range, rstudio_server_version format).
Test coverage
4
0
No .tftest.hcl, no test files, and no testing story documented in the README.
IDE Integration — 13 / 25
Criterion
Max
Score
Notes
Dashboard entry point
7
7
coder_app resource with subdomain = true, proper URL (http://localhost:${var.port}), icon, display name, and configurable share/order/group.
Managed configuration
6
0
No documented support for managed RStudio settings, policies, or configuration injection.
Configurable folder or workdir
6
6
project_path variable (documented: "The path to RStudio project, it will be mounted in the container") is bind-mounted to /home/${RSTUDIO_USER}/project, allowing the user to choose the working directory.
Pre-installed extensions
6
0
No variable or documentation for pre-installing RStudio addins or R packages. enable_renv restores project-scoped dependencies from a lock file but is not a general pre-install mechanism.
Overall — 49 / 100
Raw 45 / 92 → round(45 / 92 × 100) = 49
Scored against SCORECARD.md on 2026-10-05 with solstice-1.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
A discussion dedicated to the RStudio Server module. Share your thoughts, questions, and feedback here.
Module Scorecard
Drilldown
Presentation & Onboarding — 11 / 17
agent_idonly). The module exposes 12+ variables (auth on/off,project_path,docker_socket,enable_renv, customport,share, etc.) but no documented examples for any major mode (e.g., auth-enabled, project-mounted, custom registry).; file verified to exist (191.1 KB).Credential Hygiene — 16 / 20
rstudio_userandrstudio_passwordboth carrysensitive = true. README example contains no inline secrets or placeholder keys.disable_auth = false, the only path is username/password viarstudio_user/rstudio_password. No ServiceAccount, IAM, OAuth, API-key helper, or AI Gateway option is mentioned.Restricted-Environment Readiness — 2 / 20
run.shhardcodesIMAGE="rocker/rstudio:${SERVER_VERSION}"and callsdocker pull. No module variable overrides the registry or image URL.rstudio_server_versiononly pins the tag, not the source.docker pullor use a pre-loaded local image. The script unconditionally pulls on every start.cloud.r-project.orgfor renv). No air-gapped or restricted-network guidance.run.shnever invokessudo. All operations aredockerCLI commands, which work for any user in thedockergroup.Engineering Quality — 3 / 10
sharehasvalidationbut is missing adescription. No other validation blocks present (e.g.,portrange,rstudio_server_versionformat)..tftest.hcl, no test files, and no testing story documented in the README.IDE Integration — 13 / 25
coder_appresource withsubdomain = true, proper URL (http://localhost:${var.port}), icon, display name, and configurableshare/order/group.project_pathvariable (documented: "The path to RStudio project, it will be mounted in the container") is bind-mounted to/home/${RSTUDIO_USER}/project, allowing the user to choose the working directory.enable_renvrestores project-scoped dependencies from a lock file but is not a general pre-install mechanism.Overall — 49 / 100
Raw 45 / 92 → round(45 / 92 × 100) = 49
Scored against SCORECARD.md on 2026-10-05 with
solstice-1.All reactions