Coder powers secure, scalable development across key industries — automotive, finance, government, and technology — enabling faster builds, tighter compliance, and seamless AI adoption in enterprise-grade cloud environments.
To reuse code across different Coder templates, such as common scripts or
resource definitions, we suggest using
Terraform Modules.
You can store these modules externally from your Coder deployment, like in a git
repository or a Terraform registry. This example shows how to reference a module
from your template:
data "coder_workspace" "me" {}
module "coder-base" {
source = "github.com/my-organization/coder-base"
# Modules take in variables and can provision infrastructure
vpc_name = "devex-3"
subnet_tags = { "name": data.coder_workspace.me.name }
code_server_version = 4.14.1
}
resource "coder_agent" "dev" {
# Modules can provide outputs, such as helper scripts
startup_script=<<EOF
#!/bin/sh
${module.coder-base.code_server_install_command}
EOF
}
Module caching is enabled by default for all templates. When you publish a
new template version, Coder runs terraform init to resolve every module the
template references, then archives the resulting .terraform/modules
directory and stores it alongside that template version. On every subsequent
workspace build, Coder provisioners reuse this cached archive instead of
re-fetching modules from their original sources (a git repository, the Coder
registry, or another Terraform registry). This avoids redundant network and
disk I/O on each build and prevents build failures caused by a module source
being slow or temporarily unavailable.
Coder limits cached module archives to 20 MB per template version.
If your modules exceed this limit, some are skipped and unavailable for Dynamic Parameters evaluation, though builds still fetch the skipped modules directly.
Template versions published before Coder started archiving modules have no cache at all, which produces the same "Module not loaded" warnings for every module in the workspace creation form; publishing a new template version fixes this.
To force Coder to re-download modules on every workspace build instead of
using the cached archive, select Disable Terraform module caching in a
template's Settings > General page, or set disable_module_cache to
true with the templates API.
Warning
Disabling module caching makes workspace builds slower and less
predictable, since Terraform re-resolves and downloads every module on each
build. This isn't recommended for production templates.
Offline installations
In offline and restricted deployments, there are three ways to fetch modules.
Configure Artifactory as a Remote Terraform Repository that proxies and
caches the Coder registry. This approach provides automatic updates and
requires no manual synchronization.
We have an example template
here
that uses our
JFrog Docker
template as the underlying module.
Private git repository
If you are importing a module from a private git repository, the control plane or
provisioner needs git credentials. Since this token
will only be used for cloning your repositories with modules, it is best to
create a token with access limited to the repository and no extra permissions.
In GitHub, you can generate a
fine-grained token
with read only access to the necessary repos.
If you are running Coder on a VM, make sure that you have git installed and
the coder user has access to the following files:
# /home/coder/.gitconfig
[credential]
helper = store
If you are running Coder on Docker or Kubernetes, git is pre-installed in the
Coder image. However, you still need to mount credentials. This can be done via
a Docker volume mount or Kubernetes secrets.
Pass git credentials in Kubernetes
First, create a .gitconfig and .git-credentials file on your local machine.
You might want to do this in a temporary directory to avoid conflicting with
your own git credentials.
Next, create the secret in Kubernetes. Be sure to do this in the same namespace
that Coder is installed in.