- Remove HOST=${SERVICE_HOSTNAME} from code-server, code-server-lsio and paseo; hostname: alone sets the name
- Move SERVICE_HOSTNAME to the top of their .env.example to match compose order
- Drop the openclaw ARM64 Chromium note from its README; docs/openclaw covers it
- List CUSTOM_USER in webtop's setup step
- Trim reasoning from diun and paseo comments
- Delete stale gitea and gitea-mirror .gitignore files
- Add TODO.md for remaining naming and README issues
- Drop the Docker and GitHub apt repositories and the Ruby build headers
from the image; keep build-essential, bubblewrap, zip and unzip.
- Document home installs for the Docker CLI with its Compose and Buildx
plugins, gh, Go, Rust, Python, Node and Java, ordered so each installer
writes to ~/.zshrc and SDKMAN stays last.
- Drop the Ruby, GitLab CLI and jq instructions.
- Install the Docker CLI with its Compose and Buildx plugins, and the GitHub
CLI, from Docker's and GitHub's signed apt repositories; drop their home
installs and the GitLab CLI from the README.
- Select the shell with SHELL and the start folder with DEFAULT_WORKSPACE
instead of chsh and working_dir.
- Add an optional CODE_SERVER_APP_NAME.
- Document installing Java with SDKMAN.
Add an entrypoint wrapper that reads the socket's GID, adds coder to a
matching group and re-execs the image's entrypoint under it, so docker
works without sudo on any host. Install build-essential and the headers
rbenv needs to build Ruby, and make zsh the login shell. Document home
installs for rbenv, Docker Compose and Buildx plugins, and jq.
A service README now describes only its own service: no links to other
services or to the root, and no restating of the shared conventions that
the root README and CLAUDE.md already carry. Each service is a separate
Coolify app on a <service>/** watch path, so a cross-link made editing one
service redeploy another. The rule is recorded at the root; the alloy
compose comment now points at a heading that exists.
The workspace moves off the config volume onto code-server-workspace, so
wiping editor state and wiping code are separate acts.
The image only ever chowns the literal path /config/workspace, and reads
DEFAULT_WORKSPACE to pick the folder to open, so a named volume on /workspace
would come up root-owned and unwritable. Creating the directory in a local
Dockerfile seeds the volume with the right ownership instead.
pnpm is not used anywhere -- npm is the package manager everywhere -- so the
mod that installs it is dead weight on every container start.
INSTALL_PACKAGES loses apache2-utils, bfs, ffmpeg, imagemagick, librsvg2-bin,
lsof, psmisc and ugrep, and gains glab. Each entry is re-resolved by apt on
every start, so the list is kept to what is actually reached for.
Coolify injects HOST=0.0.0.0 into every compose app, and zsh seeds $HOST and
the %m/%M prompt escapes from that variable rather than calling gethostname().
The prompt read "0", the first dot-separated field of 0.0.0.0, even though the
container hostname itself was set correctly.
Pass the hostname in as HOST alongside the hostname: key, both from a single
SERVICE_HOSTNAME variable. Neither service reads HOST itself -- code-server
binds [::]:8443, Paseo binds PASEO_LISTEN -- so this only affects the prompt.
Not named HOSTNAME: Compose interpolation lets the deploying shell's
environment win over the .env file, and HOSTNAME is set in every container,
including the one Coolify runs in.
PASEO_LABEL is renamed to SERVICE_HOSTNAME; it was never a Paseo variable.
The example git identity is blanked out along with it.
Bind-mount /var/run/docker.sock so the universal-docker mod's CLI has a
daemon to talk to, and document the sibling-container and permission
caveats in the service README.