feat(agent-relay-claude-code): declare and expose the agent_relay_client_platform parameter - #1147
Conversation
…ent_platform parameter
|
@codex review |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Codex Review: Didn't find any major issues. Swish! Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Module Scorecard Check
|
| Theme | Before | After |
|---|---|---|
| Presentation & Onboarding | 6 / 17 | 6 / 17 |
| Integration | 0 / 25 | 0 / 25 |
| Credential Hygiene | 20 / 20 | 20 / 20 |
| Restricted-Environment | 12 / 20 | 12 / 20 |
| Engineering Quality | 10 / 10 | 10 / 10 |
| Overall | 52 / 100 | 52 / 100 |
Full scorecard for this PR
| Presentation & Onboarding | Agent Integration | Credential Hygiene | Restricted-Environment Readiness | Engineering Quality | Overall |
|---|---|---|---|---|---|
| 6 / 17 | 0 / 25 | 20 / 20 | 12 / 20 | 10 / 10 | 52 / 100 |
Drilldown
Presentation & Onboarding — 6 / 17
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Configuration-mode examples | 12 | 6 | One example block shown (install_cli = true default). The install_cli = false (baked-CLI) mode is mentioned in a comment and the Requirements section but has no separate example block. The module has ~8 variables but they are configuration knobs rather than distinct modes; still, the two install paths deserve their own examples. |
| Visual preview | 5 | 0 | No embedded image, GIF, or video in the README. The icon frontmatter field references a .svg file, which does not count per calibration. |
Agent Integration — 0 / 25
| Criterion | Max | Score | Notes |
|---|---|---|---|
| AI governance | 10 | 0 | No mention of Coder AI Gateway or Agent Firewall anywhere in the README or code. The credential is a work-order JWT injected by Agent Relay, but no gateway routing or firewall policy enforcement is documented. |
| Dashboard entry point | 5 | 0 | No coder_app resource declared or documented. The module is a headless runner with no UI component. |
| Session continuity | 5 | 0 | No documentation of resuming sessions, session IDs for reconnect, or persistent session managers (tmux, screen, boo). The agent_relay_session_id parameter is Agent Relay's dispatch identifier, not a user-facing resume mechanism. |
| Managed configuration | 5 | 0 | No mention of managed MCP servers, settings files, policies, or workdir configuration. |
Credential Hygiene — 20 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Secrets marked sensitive | 16 | 16 | agent_relay_credential uses mask_input = true in its styling JSON (Coder's equivalent of sensitive = true). README examples contain no inline secrets or placeholder keys. |
| Non-hardcoded auth path | 4 | 4 | The credential is a single-use work-order JWT stamped by Agent Relay on dispatch; the README explicitly states "a human never fills it in." No raw key pasting into templates is required. |
Restricted-Environment Readiness — 12 / 20
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Mirrorable artifact source | 5 | 0 | The install URL https://claude.ai/install.sh is hardcoded in install.sh.tftpl. No module input variable overrides this download URL. cli_binary overrides the binary path, not the download source; install_cli is a boolean toggle. No variable names the download URL. |
| Bring-your-own binary | 10 | 10 | install_cli = false disables the download entirely. README documents: "Bake the CLI into the image and set this to false for faster workspaces." The install script becomes a no-op and the start script checks PATH for the pre-existing binary. |
| Egress transparency | 3 | 0 | No dedicated README section enumerating external endpoints (claude.ai, downloads.claude.ai, Anthropic API). The "Requirements" section mentions "pre-pulled images" but does not list contacted domains or provide air-gapped guidance. |
| Runs without sudo | 2 | 2 | All three scripts (install.sh.tftpl, start.sh.tftpl, status.sh.tftpl) never invoke sudo. Installation targets ~/.local/bin; all directories are created under $HOME. Verified from source. |
Engineering Quality — 10 / 10
| Criterion | Max | Score | Notes |
|---|---|---|---|
| Input quality | 6 | 6 | All 8 variables have clear descriptions and sensible defaults. cli_binary has a regex validation rejecting shell metacharacters; exit_if_unused_min has a whole-number ≥ 0 validation. |
| Test coverage | 4 | 4 | main.tftest.hcl covers parameter contract (names, ephemeral flags, styling), runner wiring, install-CLI behavior, and security (shell-injection via serving_log_pattern). main.test.ts runs the actual scripts in containers with stub binaries, testing lifecycle states, wrapper behavior, exit codes, and path overrides end-to-end. |
Overall — 52 / 100
Raw 48 / 92 → round(48 / 92 × 100) = 52
Tip
You can run this locally by telling your agent: "review this module against .github/scorecard/SCORECARD.md".
Scored against SCORECARD.md with solstice-1. Language-model scores are advisory.
Description
Declare
agent_relay_client_platform, the persistent parameter Agent Relay stamps with the surface that created a Claude Code session (web_claude_ai,claude_in_slack,desktop_app, ...), and expose it to the workspace asAGENT_RELAY_CLIENT_PLATFORMand as theclient_platformoutput so templates can vary their setup by origin.Type of Change
Module Information
Path:
registry/coder/modules/agent-relay-claude-codeNew version:
v0.2.0Breaking change: [ ] Yes [x] No
Testing & Validation
bun test)bun fmt)terraform test: 8 passed)Related Issues
RELAY-30
Coder Agents on behalf of @Emyrk.