Actions
16 actions, callable from the panel, the command palette and the API as
POST /api/v1/a/<id>. Internal actions used between modules are not listed.
| Action | What it does | Risk | Preview |
|---|---|---|---|
editor.install | Install code-server on a server | high | No dry run |
editor.session.open | Open the editor | medium | No dry run |
editor.status | Editor status of an account (read) | low | No dry run |
editor.instance.stop | Stop the editor | low | No dry run |
editor.instance.list | Running editor instances (read) | low | No dry run |
editor.instance.admin_stop | Stop any editor instance | low | No dry run |
editor.extension.install | Install an extension | medium | No dry run |
editor.extension.uninstall | Uninstall an extension | low | No dry run |
editor.extension.list | Installed extensions (read) | low | No dry run |
editor.pack.list | Recommended extension packs (read) | low | No dry run |
editor.pack.install | Install a recommended pack | medium | No dry run |
editor.policy.get | Show the extension policy (read) | low | No dry run |
editor.policy.set | Set the extension policy | high | No dry run |
editor.policy.check | Test an extension id against the policy (read) | low | No dry run |
editor.settings.get | Show editor settings (read) | low | No dry run |
editor.settings.set | Change editor settings | high | No dry run |
Permissions and limits
Permissions
editor.useOpen the editor and manage own extensionseditor.admin.viewSee editor instances, policy and settingseditor.instance.manageStop any editor instanceeditor.policy.manageChange the extension policyeditor.adminInstall code-server and change editor settings
Engineering notes
Generated from modules/editor/docs.md at build d90e9e2. These are the notes the engineers keep
next to the code: precise, technical, and honest about what is not done yet.
Declared in module.yaml; agent driver internal/agent/editor.go; op types sdk/agentop/editor.go; policy and
packs in modules/editor/policy.
Model
editor.install(admin): downloads the pinned code-server 4.141.0 deb (MIT), verifies its sha256, installs it.editor.session.open: starts (or reuses)rc-editor-<user>.serviceand returns a ticket. The unit runs as the account user inrc-acct-<user>.slice,NoNewPrivileges,PrivateTmp,ProtectSystem=strict,TemporaryFileSystem=/home+BindPaths=<own home>(other accounts' homes do not exist in its mount namespace), optionalMemoryMax. It listens only on/run/rc-editor-<user>/code.sock(runtime dir 0700, socket 0600), auth none behind the socket, telemetry and update checks off (telemetry.telemetryLevel=off,update.mode=noneare enforced on every start, plus the admin's locked settings),--idle-timeout-seconds(default 30 min) so it stops itself. Extensions:EXTENSIONS_GALLERYpoints at Open VSX only.editor.session.open {app_id}opens~/apps/<app>/currentand returns the matchingsuggested_pack;file+linedeep-link into the workbench. Nothing is installed without an expliciteditor.pack.install.- Extensions:
editor.extension.install/uninstall/list,editor.pack.list/install(16 vetted packs, every id checked on Open VSX), policyeditor.policy.get/set/check(open | allow_list, allow/denypublisher.nameorpublisher.*, deny wins). The control plane checks and the agent checks again. - Admin:
editor.settings.get/set(idle minutes, memory,max_running_per_node, default + locked settings),editor.instance.list/admin_stop.
The gateway (core, not built here)
Same pattern as the terminal (docs/security/terminal.md). This module provides the ticket side:
editor.ticket.redeem (internal, system actor only) consumes the ticket atomically if it is unused, unexpired, opened by
that principal from that browser session (web_session<>'', so API-token tickets never redeem), and returns
{node_id, username, socket, url_path}. What core must add (internal/api, outside this card's paths): a
GET /api/v1/editor/open?ticket= + proxied /editor/... HTTP and WebSocket route that checks, in order, Origin (as
terminalGW.originAllowed), ticket shape, session cookie only (AuthenticateStream), redeems via the system actor,
then reverse-proxies to the unix socket (same node) or over the bus (other nodes), re-validating the session every 15 s
and on every WebSocket upgrade, with a per-principal/global cap and audit editor.stream.opened|closed|denied. See the
handover for the exact request.
Not done
Socket activation (the unit starts on session.open and idles out by itself; no systemd .socket), queueing instead of a
refusal at max_running_per_node, workbench-side enforcement of the policy (the policy is enforced on panel installs;
the workbench's own marketplace view talks to Open VSX directly until a gallery proxy exists), port-forward previews,
debug-mode toggle, Git credential helper, collaboration (AC-editor-10/12/13/17).