Spin up a dev workspace in seconds.
Self-hosted cloud dev environments on your own cluster — a Codespaces alternative: pick a template, get an owner-scoped DevWorkspace, and jump straight into a browser IDE (openvscode-server) or an in-pod terminal — RBE-ready, with your agent CLIs a click away, and scale-to-zero when idle.
A dev environment is a Kubernetes resource.
Managed cloud dev environments run in a vendor's cloud, on the vendor's terms. Workspaces models the same idea as first-class CRs on your own cluster — inspectable, template-driven, and wired into your RBE.
Pick a WorkspaceConfig — a reusable template carrying the image, repo, storage, idle timeout, dotfiles, and tool set — and the facade writes an owner-scoped DevWorkspace CR. The operator reconciles it into a StatefulSet with a persistent home volume, a headless Service, and a per-workspace Secret, mounting the config's files read-only at /etc/fastverk/config so every workspace boots RBE-ready. You land in a browser IDE (openvscode-server) or an in-pod terminal, with agent CLIs — opencode, Claude Code, Codex — a click away. When you step away it scales to zero; the volume is kept.
A dev environment is a Kubernetes resource — owner-scoped, template-driven, and scale-to-zero when idle.
Your workspaces, live.
A card per DevWorkspace — its config, phase, and URL, with a launch button per provisioned tool. Values illustrative.
| workspace | config | phase | url |
|---|---|---|---|
| spurious-racoon | default | Running | spurious-racoon.ws.fastverk.com |
| brave-otter | rust-rbe | Provisioning | — |
| quiet-lynx | default | Suspended | resumes on access |
VS Code, a terminal, or an agent.
A config's tools become launch buttons on the card — web tools open a URL, tty tools open an in-pod terminal wired to the broker. The default config ships these.
| tool | kind | launches |
|---|---|---|
| VS Code | web | openvscode-server on :3000 |
| Terminal | tty | /bin/bash -l |
| opencode | tty | the opencode agent CLI |
| Claude Code | tty | the claude agent CLI |
| Codex | tty | the codex agent CLI |
A workspace is a set of layers. Pick them.
Beyond the default tools, a config is a composition you assemble from a searchable gallery — languages, runtimes, browsers, databases, CLIs, an agent — added à la carte or pulled whole from a bundle, each pinned to a version. Save the result as a template your team launches from. Preview — the ToolLayer catalog and the compose gallery are in build; layer sizes below are read from the shipped catalog.
| layer | version | source |
|---|---|---|
| Rust | stable | rust-bundle |
| Bazel | 7.3 | rust-bundle |
| Claude Code | Bedrock | claude-mcp |
| PostgreSQL | 16 | à la carte |
| Chrome | 129 | à la carte |
Pick → provision → route → land.
One wildcard absorbs all the networking — no per-workspace DNS, cert, or Ingress.
Pick
Choose a WorkspaceConfig in the console (or fv ws create --config <name>). The facade writes an owner-scoped DevWorkspace CR with a random adjective-animal name.
Provision
The operator reconciles it into a StatefulSet, a persistent home volume, a headless Service, and a per-workspace Secret — mounting the config's files at /etc/fastverk/config.
Route
ws-proxy authenticates your session against spec.owner and routes <name>.ws.fastverk.com to the pod. No per-workspace DNS, cert, or Ingress is created.
Land
You're in a browser IDE or an in-pod terminal — RBE-ready (grpcs://rbe.fastverk.com:8980), with your agent CLIs a click away.
Templates you fork; workspaces that sleep.
The two properties that make it cheap and consistent.
How it stays cheap and consistent
- Configs are templates: a WorkspaceConfig carries the image, repo, storage, idle timeout, dotfiles, and tools — the managed default plus any you author. No secrets in config; tokens arrive at runtime.
- Scale-to-zero: after the idle timeout (default 30m) the workspace suspends — replicas to 0, the PVC retained — and resumes on next access. After the retention window (14 days) it's garbage-collected and its volume reclaimed.
- Config-mount: the rendered files land read-only at /etc/fastverk/config (bazelrc, npmrc), so every workspace boots RBE-ready with no manual setup.
- Owner-scoped: spec.owner is your identity and it's immutable — ws-proxy enforces it on every request, so a workspace is yours alone.
Your cluster, your RBE, your rules.
The alternative runs in a vendor's cloud, on a vendor's billing, behind vendor-managed URLs.
Creating a workspace or forwarding a port creates no new DNS, cert, or Ingress — the wildcard and ws-proxy absorb all of it.
Prove it's safe to merge.
workspaces is one of 14 plugins in the fastverk console — hosted, or in your own cloud.