Skip to main content
See All Integrations

code-server

Protect a self-hosted code-server browser IDE with Pomerium authentication and route policy, with WebSocket support and the correct public host.

First-party Pomerium integration guide

Category
Cloud Workstation

Overview

code-server is a self-hosted browser IDE from Coder. Pomerium can protect its HTTP and WebSocket route before a user reaches the development session.

code-server can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to code-server. code-server remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.

Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.

Route the public HTTPS host to http://code-server:8080. Preserve the Host header, support WebSockets, keep port 8080 unpublished, and place Pomerium and code-server on a shared private network.

Example

A development team keeps code-server on a private container network. Pomerium authenticates each user, checks route policy, and forwards approved browser and WebSocket traffic to code-server.

Considerations

  • The shell, files, extensions, and workspace permissions remain code-server concerns.
  • If code-server runs with authentication disabled, Pomerium must be the only reachable path to it.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.

Sources and official resources

  • Put the Cockpit Linux administration interface behind Pomerium so users pass identity-aware route policy before Cockpit host login.

  • Protect access to JupyterHub notebook environments as an upstream web application.

  • Put GitLab Self-Managed behind a Pomerium HTTPS route so users pass identity-aware policy before GitLab login.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo