code-server
Protect a self-hosted code-server browser IDE with Pomerium authentication and route policy, with WebSocket support and the correct public host.
Overview
code-server is a self-hosted browser IDE from Coder. Pomerium can protect its HTTP and WebSocket route before a user reaches the development session.
code-server can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to code-server. code-server remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.
Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.
Route the public HTTPS host to http://code-server:8080. Preserve the Host header, support WebSockets, keep port 8080 unpublished, and place Pomerium and code-server on a shared private network.
Example
A development team keeps code-server on a private container network. Pomerium authenticates each user, checks route policy, and forwards approved browser and WebSocket traffic to code-server.
Considerations
- The shell, files, extensions, and workspace permissions remain code-server concerns.
- If code-server runs with authentication disabled, Pomerium must be the only reachable path to it.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
Sources and official resources
- code-serverOfficial website
- code-server guideOfficial documentation
- code-server repositoryOfficial repository
- Secure code-server with PomeriumPomerium documentation
- Pomerium HTTP and WebSocket routingPomerium documentation
- Pomerium route timeoutsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
