Coder/coder: self-hosted cloud development environments and AI agents
Secure environments for developers and their agents. Coder Agents runs a native AI coding agent whose loop executes in the control plane on your infrastructure, with no API keys in workspaces.
At a glance
- What is it?
- Coder defines workspaces in Terraform, connects them over a Wireguard tunnel, and runs its AI agent loop in the control plane so no LLM credentials live inside a workspace. It is infrastructure, not a hosted IDE.
- Who is it for?
- Adopt Coder if you already run Kubernetes, EC2 or Docker and you want workspace definitions in Terraform plus a central place to hold model credentials. Do not adopt it if you want a hosted IDE with no server to operate, or if nobody on the team owns a PostgreSQL instance and a template repository.
- Can I use it commercially?
- Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
- Is it still maintained?
- Yes. The repository last received commits 4 days ago.
- What is it written in?
- Mainly Go, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.
DEEP OPEN-SOURCE ANALYSIS
The problem Coder solves, and who ends up operating it
The README frames the product as a self-hosted platform for cloud development environments and AI coding agents. The concrete problem is that a developer laptop is a snowflake: dependencies, IDE configuration and credentials accumulate locally, onboarding takes days, and idle machines keep costing money. Coder moves that environment into infrastructure you control, described by a Terraform template rather than by a setup document. The README names EC2 VMs, Kubernetes Pods and Docker Containers as the targets.
The second problem is newer. If developers run AI coding agents locally, model API keys end up on workstations, spend is invisible, and there is no audit trail tying an action to a person. Coder Agents is the answer to that: the agent loop executes in the control plane on your infrastructure, and the README states there are no LLM credentials in workspaces. The README lists Anthropic, OpenAI, Google, Bedrock and self-hosted models as supported backends, with centralized model governance, cost tracking and audit logging.
Who is this for? Platform and infrastructure engineers at organizations large enough to have a template repository and a PostgreSQL server, and security-conscious teams that cannot send source code through a vendor's hosted agent. It is not a product for a solo developer who wants a browser IDE in two minutes; the operational surface is real.
How the pieces fit: Terraform templates, a Wireguard tunnel, and a control plane
The repository layout shows the split clearly. coderd/ is the control plane server, provisioner/ and provisionerd/ handle template execution, cli/ and cmd/ build the coder binary, codersdk/ is the Go client, and agent/ is the component that runs inside each workspace. A template is Terraform, and the provisioner applies it to create the workspace's infrastructure. The README says workspaces are connected through a secure Wireguard tunnel, which is how a developer reaches a workspace without exposing it to the public internet.
Coder Agents changes where the loop runs. Instead of the agent process living beside the code with a key in its environment, the loop executes in the control plane. The README describes the result as user identity on every action, with centralized model governance, cost tracking and audit logging. For a security reviewer, that is the whole argument: the credential sits on the server, and the workspace only carries the agent's effect.
Idle shutdown is the other mechanism worth noting. The README says resources are automatically shut down when not used, which is the cost story. Templates also carry parameters; the repository ships examples/parameters/ and examples/parameters-dynamic-options/, and examples/workspace-tags/ for tagging. The aibridge/ and enterprise/ directories are where the AI gateway and commercial code live, which is the boundary you should map before planning a rollout.
Installing Coder and provisioning a first workspace
The README points at install.sh for Linux and macOS, and at GitHub Releases for a Windows binary or installer. The script is fetched and piped to a shell, which is the fastest path and also the one you should read before running in a regulated environment.
curl -L https://coder.com/install.sh | shWith the binary in place, start the server. The README says this opens http://localhost:3000, where you create the initial user, create a Docker template, and provision your first workspace.
coder serverWithout extra flags, Coder uses a built-in database and sets up a *.try.coder.app access URL for evaluation. That is fine for a first look and wrong for anything real. For production the README asks for a PostgreSQL database (version 13 or later) and an external access URL:
coder server --postgres-url <url> --access-url <url>The README also points at validated architectures for sizing and infrastructure guidance, and says coder --help lists the full set of flags and environment variables. If you prefer containers, the repository ships compose.yaml, which runs the image ghcr.io/coder/coder on port 7080 and a postgres:17 service. Note the comment in that file: CODER_ACCESS_URL cannot be localhost or 127.0.0.1 for non-Docker templates, because workspaces have to reach it. The same file mounts /var/run/docker.sock and documents a group_add workaround when the coder user lacks write permission on the socket.
Where Coder is the wrong tool
The evaluation defaults are a trap if you forget them. A built-in database and a *.try.coder.app URL are described in the README as evaluation settings; running a team on them is not a supported posture, and the PostgreSQL requirement of version 13 or later is a hard floor for the production path.
Templates are Terraform, and that is the real adoption cost. Your platform team has to write and maintain Terraform that describes developer environments, plus the parameters and tags that go with them. Teams without Terraform experience will find the template repository harder than the workspace experience it produces. The examples/ directory softens this, and the Coder Registry publishes templates and modules, but the maintenance burden does not disappear.
For Docker-based templates, the compose.yaml mounts the Docker socket into the Coder container. That is a privileged arrangement, and the file itself notes the group permission workaround. If your security model forbids socket mounts, the Kubernetes path is the alternative, and it comes with its own cluster requirements.
Finally, scale. A single coder server process, a PostgreSQL database and a provisioner pool are components you operate, back up and upgrade. If your team is five people who want a remote editor, the operational cost of Coder exceeds the problem it solves.
Coder compared with GitHub Codespaces and Gitpod
The honest comparison is between Coder and hosted environment services such as GitHub Codespaces or Gitpod. The difference is not features, it is where the compute and the control plane live.
Codespaces and Gitpod run the environment on the vendor's infrastructure and bill you for it. Coder runs coderd on your infrastructure, against your cloud account, with templates you write. That is why the README can talk about automatic shutdown of idle resources as a cost lever: the machines are yours, so the savings are yours too. It is also why Coder asks for PostgreSQL and an access URL before it is production-ready, which a hosted service never does.
The agent story is the sharper split. Coder Agents executes the loop in the control plane and the README states there are no LLM credentials in workspaces, with model governance and audit logging handled centrally. A hosted service that runs agents inside its own environment gives you less to operate and less to inspect. If your requirement is that model traffic and credentials stay inside your perimeter, that requirement points at self-hosting.
The trade is straightforward: hosted services minimize operations, Coder minimizes third-party exposure and gives you the template layer. Pick based on which of those two you cannot compromise on.
Licence, upgrade cadence and what maintenance actually costs
Coder is licensed under AGPL-3.0, and the repository also carries a LICENSE.enterprise file alongside an enterprise/ directory. The practical reading is that the core is AGPL and some features are commercial; the README links to a pricing page for Premium, described as paid features built for large teams. If you plan to modify Coder and offer it as a network service, the AGPL is the clause to read carefully, and that is a question for your own counsel rather than for this article.
The release history shows a steady cadence: v2.36.3 and v2.35.6 both landed on 2026-08-25, with v2.36.1 a few days earlier on 2026-08-20. The last push to the default branch was on 2026-08-25. Two release lines being patched in parallel means you should expect to track a minor version and take patch releases, not pin once and walk away.
Upgrade cost is dominated by the database and the templates. PostgreSQL migrations run with the server, so you need a backup path and a window. Templates are Terraform you own, and Terraform providers change independently of Coder. The coderd Terraform Provider exists for managing deployment configuration as code, which helps, but it adds another version to track. Budget for a platform engineer who owns the control plane, not for a one-time install.
Editorial conclusion
Adopt Coder if you already run Kubernetes, EC2 or Docker and you want workspace definitions in Terraform plus a central place to hold model credentials. Do not adopt it if you want a hosted IDE with no server to operate, or if nobody on the team owns a PostgreSQL instance and a template repository. Before committing, verify four things: that your PostgreSQL is version 13 or later, that a non-localhost CODER_ACCESS_URL is reachable from the machines that will host workspaces, that the Docker socket permissions in compose.yaml match your host, and which of the features you need sit behind the Premium licence rather than in the AGPL-3.0 core.
Frequently asked questions
How do I install Coder/coder?
On Linux and macOS the README gives a one-line install script, curl -L https://coder.com/install.sh | sh. Windows users are pointed at the binary or installer on GitHub Releases, and the README links install guides for other methods.
How do I use Coder/coder after installing it?
Run coder server, then open http://localhost:3000 to create your initial user, create a Docker template, and provision your first workspace. For production the README asks you to add a PostgreSQL database and an external access URL with coder server --postgres-url <url> --access-url <url>.
What is Coder Agents?
Coder Agents runs a native AI coding agent whose loop executes in the control plane on your infrastructure. The README states there are no LLM credentials in workspaces, and that model governance, cost tracking and audit logging are centralized.
Can Coder/coder run on my own infrastructure?
Yes. Coder is described as a self-hosted platform, and workspaces can target EC2 VMs, Kubernetes Pods or Docker Containers through Terraform templates. The repository also ships a compose.yaml that runs the Coder image and a postgres:17 service.
What database does Coder/coder need?
For production the README asks for PostgreSQL version 13 or later, and compose.yaml notes that 13 is the minimum supported version. Without a database flag, Coder falls back to a built-in database and a *.try.coder.app URL for evaluation.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/coder-coder)
Community notes