feat(aws-ec2-instance-type): add AWS EC2 instance type parameter module - #1136
Conversation
Module Scorecard Check
|
| Presentation & Onboarding | Credential Hygiene | Restricted-Environment Readiness | Engineering Quality | Overall |
|---|---|---|---|---|
| 17 / 17 | 20 / 20 | N/A | 10 / 10 | 100 / 100 |
Drilldown
Presentation & Onboarding — 17 / 17
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Configuration-mode examples | 12 | 12 | README documents five distinct modes: default t3-only picker, multi-family include, custom_metadata label overrides, architecture-aware provisioning via the instances output, and create_parameter = false for catalog-only use. Each example shows sensible defaults and is self-contained. |
| Visual preview | 5 | 5 |  is embedded in the README; file verified to exist (80.6 KB). |
Credential Hygiene — 20 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Secrets marked sensitive | 16 | 16 | No sensitive inputs exist in this module (all variables are display names, instance-type strings, booleans, or metadata maps). README examples contain no inline secrets or placeholder keys. |
| Non-hardcoded auth path | 4 | 4 | The module performs no authentication; it creates a Coder parameter and reads a local JSON catalog. No keys, tokens, or credentials are involved, so the criterion is vacuously satisfied. |
Restricted-Environment Readiness — N/A
The module downloads nothing, installs nothing, and contacts no external endpoints at plan or apply time. It reads a local instance-types.json file and creates a coder_parameter. The .scripts/update.sh is a developer maintenance tool (run manually to regenerate the catalog), not part of the module's runtime. Per the rubric, "a module that downloads nothing" is the canonical N/A example for this theme. All four sub-criteria (Mirrorable artifact source, Bring-your-own binary, Egress transparency, Runs without sudo) are excluded.
Engineering Quality — 10 / 10
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Input quality | 6 | 6 | All eight variables carry clear description strings and sensible defaults. include has a validation block rejecting empty lists. custom_metadata uses a typed map(object({...})) with optional fields. |
| Test coverage | 4 | 4 | main.tftest.hcl contains 12 run blocks covering parameter naming, order propagation, default/fallback values, create_parameter = false path, family filtering (single and multi), label disambiguation, custom_metadata overrides, instances output shape (vcpus, memory_mib, gpus, coder_arch derivation for x86_64→amd64 and arm64), and value-key consistency. No TypeScript layer exists, so no e2e TS tests are expected. |
Overall — 100 / 100
Raw 47 / 47 → round(47 / 47 × 100) = 100
Track: Utility (parameter/helper module; no agent, IDE, or application component)
Tip
You can run this locally by telling your agent: "review this module against .github/scorecard/SCORECARD.md".
Scored against SCORECARD.md with solstice-1. Language-model scores are advisory.
…ib, gpus) over description
…y and coder_arch in module
…he built-in parameter
…om modules
Two parameters the template was doing by hand now come from the shared
modules, which is also where the knowledge belongs.
**The availability zone.** `"${module.aws-region.value}a"` becomes
`module.aws-region.default_availability_zone`, added by #1138.
Worth being honest about what that buys: the module computes the same
`region + "a"` string, so the behaviour is identical and it is still a guess --
AZ names are per-account aliases and some accounts are never offered the `a`
one. What changes is that there is now a single place to fix it, instead of
four templates mashing strings. aws-envbuilder still has the old form and a
`# TODO: provide a way to pick the availability zone` to go with it.
**The instance type.** The template's own `coder_parameter` and, more to the
point, the seven-row `arch_map` next to it both go. #1136's
`aws-ec2-instance-type` publishes an `instances` catalog carrying `coder_arch`
(amd64/arm64) and `ami` (x86_64/arm64) per type, which is two of the three
spellings this template needs; the third is Nix's `aarch64`, derived from the
second. So the comment that used to say the map existed "so the AMI
architecture, coder_agent.arch and the flake attribute cannot disagree" is now
true by construction rather than by maintenance.
Everything under 4 GiB is excluded, which is the rule the old curated list was
expressing: no swap, Nix store on the root volume, and a rebuild that compiles
anything exhausts a 1-2 GiB instance.
Both sources are `git::` refs, with `depth=1` so a `terraform init` clones
48 MiB of coder/registry rather than 92. Neither version exists on
registry.coder.com yet -- aws-region 1.1.0 is merged but untagged (newest
published is 1.0.31, which has no `default_availability_zone`), and #1136 is an
open PR. Both carry a TODO, the README says so, and this template cannot be
released until both are re-pointed.
Note the parameter renames from `instance_type` to `aws_ec2_instance_type`,
which is the module's name for it.
Verified on a live deployment, both architectures for the first time:
t3.medium x86_64 agent amd64 coder-workspace-x86_64 eu-west-3a
t4g.medium aarch64 agent arm64 coder-workspace-aarch64 eu-west-3a
both reaching lifecycle=ready with a healthy agent.
Regenerate the catalog from `aws ec2 describe-instance-types` with a curated family list and no jq step. Region is overridable via AWS_REGION (default us-east-1), and the output is run through prettier so it lands committable.
… parameters Coder's dynamic parameters preview resolves file() from the module directory rather than via path.module, so the option list evaluated to empty and the parameter rendered as a free-text input instead of a dropdown. Real terraform resolves path.module, which is why `terraform test` passed and hid it. Read the catalog with a try() fallback so both resolvers work, matching the approach aws-region shipped in #1138.
Show each option as "<vcpu> vCPU, <ram> GiB RAM (<arch>)" with the instance type as the tooltip, so developers pick by capability instead of AWS codes. Replace type_category and exclude with a single include list of instance families (default ["t3"]). Instance families share specs and Coder requires unique option names, so a label used by more than one included instance gets the instance type appended, e.g. "2 vCPU, 4 GiB RAM (amd64, c5.large)".
…tion Filtering moved to instance families, so family_category and the derived category field are no longer used. The field was only surfaced in the instances output and never documented there, so remove both.
Curate only the instance families in the update script and pull their sizes from ec2:DescribeInstanceTypes with an instance-type wildcard filter, so new sizes in those families are picked up on regeneration. bare-metal=false keeps the catalog to virtualized sizes.
…data, clearer options Rename the JSON catalog fields value -> type and ami -> arch (ami never held an AMI, it is the AWS architecture). Merge custom_names and custom_descriptions into a single typed custom_metadata map (requires Terraform >= 1.3 for optional object attributes). Build the picker options from a precomputed, memory-ordered list so the dynamic block no longer reads option.value.value.
|
LGTM I will load up into my deployment as well to test it out but I cant imagine it wouldn't work 😸 |
|
ive been testing it like this if that helps module "aws-ec2-instance-type" {
source = "git::https://github.com/coder/registry.git//registry/coder/modules/aws-ec2-instance-type?ref=phorcys/aws-ec2-instance-type&depth=1"
default = "t3.medium"
description = trimspace(<<-EOT
t3.medium is the smallest that works: the NixOS AMI configures no swap and
the Nix store shares the root volume, so a rebuild that has to compile
anything will exhaust a 1-2 GiB instance.
EOT
)
} |
|
Works fine for me I will let you decide when to merge and release since I see you are still committing 😄 |
|
i'm trying to get that scorecard up hahaha |
…egistry #1136 merged and 1.0.0 is published, so the module comes from registry.coder.com instead of a branch of this repository -- which was mutable, and the reason the template could not be released. aws-region stays on Git: `default_availability_zone` is tagged as 1.1.0 but the registry still serves 1.0.31, whose only output is `value`. The pin moves from `main` to the release tag, so it is at least immutable.
AWS EC2 Instance Type
A
coder_parameterhelper that presents AWS EC2 instance types with human-readable labels (vCPU, RAM, architecture, and GPU count), filtered by instance family. Follows the same pattern ascoder/aws-region.Specs come straight from the AWS EC2 API (
aws ec2 describe-instance-types);.scripts/update.shregeneratesinstance-types.json, so vCPU/RAM/GPU/arch are never hand-maintained.Usage
Behavior
include(default["t3"], validated non-empty) selects which families appear in the picker. Bundled catalog:t3,t4g,m5,m7g,c5,r5,i3,g4dn."<vCPU> vCPU, <RAM> GiB RAM[, <n> GPU] (<arch>)"with the instance type as its tooltip. Labels shared across families are disambiguated with the instance type.instancesoutput exposesarch(x86_64/arm64) andcoder_arch(amd64/arm64) per type, so templates can pick a matching AMI and setcoder_agent.arch.custom_metadataoverrides an option's name/description per instance type.create_parameter = falseskips thecoder_parameter(returnsdefault) while keeping theinstancescatalog.Outputs
value— the selected instance type (ordefaultwhen the picker is disabled).instances— the full catalog keyed by instance type (vcpus,memory_mib,gpus,arch,coder_arch).Every type used by the AWS templates (
t3.micro–t3.2xlarge, used byaws-linux/aws-windows) is in the defaultt3family; a test pins that coverage.Checks
terraform fmt,terraform validate,terraform test(13/13),prettier --check, andshellcheckon.scripts/update.sh. The dynamic-parameters render was captured from a live Coder instance (see preview).Design decisions
includeover categories — earlier drafts used purpose categories (general/compute/…) with anexcludelist. Replaced with a flat familyinclude(defaultt3): simpler to reason about and maps directly to how AWS names instances..scripts/update.shenumerates sizes per family viadescribe-instance-typeswith an inline--querythat emits the final JSON shape (nojq), so new sizes are picked up automatically. Curated family list rather than the entire EC2 catalog.{ type, vcpus, memory_mib, gpus, arch };coder_archis derived in Terraform (AWS usesx86_64, Coder usesamd64).custom_metadata— singlemap(object({ name = optional(string), description = optional(string) }))replacing separatecustom_names/custom_descriptions. Requires Terraform>= 1.3foroptional().file()fallback —jsondecode(try(file("${path.module}/instance-types.json"), file("instance-types.json"))), because Coder's dynamic-parameters preview resolvesfile()from the module dir differently than real Terraform (matches mergedaws-region)..tftest.hclonly (13 runs). Nomain.test.ts: this is a parameter-only module with no runtime script to exercise end to end.verified: false, initialversion 1.0.0.Preview
🤖 Opened by Coder Agents on behalf of @phorcys420.