Skip to content

fix(coder-client): surface real stderr on coder templates push failure - #361

Merged
ndefokou merged 4 commits into
developfrom
fix/coder-template-push-error
Oct 6, 2026
Merged

ndefokou merged 4 commits into
developfrom
fix/coder-template-push-error

Conversation

@ndefokou

@ndefokou ndefokou commented Oct 6, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

During ./scripts/prod.sh bootstrap, pushing the 5 workspace templates (forge, sentinel, nexus, vessel, lore) failed with only:

⚠ Template 'openflows-forge' push failed: Failed to run coder templates push
...
Error: Bootstrap failed
Caused by:
    Failed to push 5 template(s): ... Verify the session token has template management permissions.

The token was valid and the user had template-management permissions, yet the real cause was invisible.

Root cause

CoderClient::push_template shells out to the coder CLI (coder templates push) to create/update templates, because Coder v2 does not support template version updates over REST. The actual failure was masked:

  • Missing coder CLI: when the coder binary is not on PATH (or not discoverable in the workspace), spawning the command returns an io::ErrorKind::NotFound, which the code mapped to the generic .context("Failed to run coder templates push"). It never said the CLI was missing, and bootstrap wrongly attributed the failure to template-management permissions.
  • Swallowed stderr on non-zero exit: a real CLI rejection (e.g. permissions) was only logged as a WARN; push_template then continued and returned whatever template it found, so the underlying reason never reached the caller.

Change

crates/coder-client/src/lib.rs — reworked the command-run and error path in push_template:

  • Spawn errors are now actionable. A NotFound error (CLI not found) fails fast with a clear message telling the operator to install the coder CLI (curl -fsSL https://coder.com/install.sh | sh) and re-run bootstrap. Any other spawn error carries the underlying io::Error.
  • Non-zero exit surfaces the real diagnostics. The command output is validated via check_template_push_output, which returns an error carrying the template name, the exit code, and the CLI's stderr/stdout — instead of logging a warning and continuing.
  • Temp directory is cleaned up even when the CLI rejects the template.
  • Integrated with develop's resolve_coder_cli() so the CLI is found via CODER_CLI_PATH, PATH, CODER_SCRIPT_BIN_DIR, or the workspace /tmp/coder.*/coder helper before falling back to a plain coder lookup.

Why it matters

Bootstrap is the first-run setup gate for OpenFlows. When it fails, operators must be able to tell instantly whether it is an environment problem (missing CLI) or a permissions problem (token lacking template-management permissions). This change makes the two causes distinguishable and actionable, and prevents a silent "success" when a template push is actually rejected.

Testing

  • cargo build -p coder-client — clean.
  • cargo test -p coder-client — 18/18 tests pass (including coder_cli_path_override_takes_precedence, template_push_success_allows_warnings, template_push_failure_preserves_terraform_diagnostics).
  • ./scripts/prod.sh bootstrap with the coder CLI installed — all 5 templates pushed successfully and ✓ Coder bootstrapped reported.

RetriggerConfidence Score: 4/5

The PR appears safe to merge, though the quick start should retain a model-response check.

Findings

  1. P2 AI setup test no longer tests responses ▶
Fix with agent prompt
### Issue 1
quick_start.md:162
Step 7 now asks readers only to confirm that agents and models appear. A model with an invalid provider key can pass that check, and bootstrap also checks only that models are listed. Readers may not discover the problem until a later chat or agent run. Please keep the short message-and-response check in this step.

```suggestion
Open **http://localhost:7080/agents** and confirm agents/models show up. Say "hello" in the chat to verify the model responds.
```

---

For each issue above, determine whether it is valid and should be fixed. If so, fix it directly.
Summary

The PR makes CLI spawn failures more descriptive and cleans up template files before checking a completed push’s result. It also changes two quick-start instructions.

  • The removed chat check weakens the quick start’s AI setup verification.

Reviews (1) · Last reviewed commit: "fix(ci): fix pipeline"

When the coder CLI is missing from PATH, push_template reported only
'Failed to run coder templates push', masking the real cause and
bootstrap conflated it with missing template-management permissions.
Handle a NotFound spawn error with an actionable install hint, and
return the actual CLI stderr/exit code on non-zero template push.
…-push-error

# Conflicts:
#	crates/coder-client/src/lib.rs
@Christiantyemele

Copy link
Copy Markdown
Collaborator

@greptileai review

@Christiantyemele

Copy link
Copy Markdown
Collaborator

@greptileai review

Comment thread quick_start.md
@ndefokou
ndefokou merged commit 5562ecd into develop Oct 6, 2026
13 checks passed
@ndefokou
ndefokou deleted the fix/coder-template-push-error branch October 6, 2026 08:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants