Skip to content

Use CodeArtifact mirrors for virtual-browser AWS apps - #491

Merged
june-hua merged 4 commits into
masterfrom
migrate-to-code-artifact
Sep 29, 2026
Merged

june-hua merged 4 commits into
masterfrom
migrate-to-code-artifact

Conversation

@june-hua

Copy link
Copy Markdown
Contributor
  1. Airlocked apps cannot reach public PyPI or npm. The virtual-browser Jupyter and RStudio templates now opt in to the account's CodeArtifact mirrors when the instance has the vwbusr:codeartifact-domain-name tag.
  2. virtual-browser-jupyter also gains the AWS CLI feature that the AWS startup scripts need.
  3. configure-codeartifact.sh reads the account and region from instance metadata, writes them to /etc/workbench-codeartifact.conf, and installs refresh-codeartifact-login.sh. It runs regardless of LOG_IN, and a failed login logs a warning instead of failing app creation.
  4. refresh-codeartifact-login.sh logs pip and npm in to pypi-mirror and npm-mirror with 12-hour tokens. It uses only the EC2 instance role, ignoring workspace AWS profiles and other credential sources, and keeps both config files at mode 600. It attempts both logins even if one fails, and a lock serializes concurrent refreshes. --start refreshes once, then ensures a single background worker that refreshes every six hours, or after five minutes if the last refresh failed. remount-on-restart.sh runs --start on every container restart.
  5. Document the behavior and log location in the startupscript README, and add a CI job for tests/test-codeartifact.bats.

PHP-180400

1. Airlocked apps cannot reach public PyPI or npm. The virtual-browser
Jupyter and RStudio templates now opt in to the account's CodeArtifact
mirrors when the instance has the vwbusr:codeartifact-domain-name tag.
2. virtual-browser-jupyter also gains the AWS CLI feature that the AWS
startup scripts need.
3. configure-codeartifact.sh reads the account and region from instance
metadata, writes them to /etc/workbench-codeartifact.conf, and installs
refresh-codeartifact-login.sh. It runs regardless of LOG_IN, and a
failed login logs a warning instead of failing app creation.
4. refresh-codeartifact-login.sh logs pip and npm in to pypi-mirror and
npm-mirror with 12-hour tokens. It uses only the EC2 instance role,
ignoring workspace AWS profiles and other credential sources, and keeps
both config files at mode 600. It attempts both logins even if one
fails, and a lock serializes concurrent refreshes. --start refreshes
once, then ensures a single background worker that refreshes every six
hours, or after five minutes if the last refresh failed.
remount-on-restart.sh runs --start on every container restart.
5. Document the behavior and log location in the startupscript README,
and add a CI job for tests/test-codeartifact.bats.

PHP-180400
@june-hua june-hua self-assigned this Sep 23, 2026
Comment thread src/virtual-browser-jupyter/.devcontainer.json
Comment thread startupscript/aws/refresh-codeartifact-login.sh Outdated
@june-hua
june-hua marked this pull request as ready for review September 29, 2026 19:08
@june-hua
june-hua requested review from a team as code owners September 29, 2026 19:08
@june-hua
june-hua merged commit b160f8e into master Sep 29, 2026
19 of 21 checks passed
@june-hua
june-hua deleted the migrate-to-code-artifact branch September 29, 2026 19:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants