cloud dev environments

Spin up a dev workspace in seconds.

Self-hosted cloud dev environments on your own cluster — a Codespaces alternative: pick a template, get an owner-scoped DevWorkspace, and jump straight into a browser IDE (openvscode-server) or an in-pod terminal — RBE-ready, with your agent CLIs a click away, and scale-to-zero when idle.

available
Owner-scoped DevWorkspace + WorkspaceConfig CRsOne click to a browser IDE or an in-pod terminalReusable config templates — no per-repo devcontainer wranglingRBE-ready + agent CLIs (opencode / Claude Code / Codex) built inScale-to-zero when idle — the volume is retainedCompose from 19 version-pinned tool layers — à la carte or by bundle
seconds
to a running workspace
pick a config → a DevWorkspace CR
VS Code + terminal
in the browser
openvscode-server + ttybroker
scale-to-zero
idle → suspended
30m idle, PVC retained
owner-scoped
yours alone
spec.owner = your identity, immutable
why it's different

A dev environment is a Kubernetes resource.

Managed cloud dev environments run in a vendor's cloud, on the vendor's terms. Workspaces models the same idea as first-class CRs on your own cluster — inspectable, template-driven, and wired into your RBE.

Pick a WorkspaceConfig — a reusable template carrying the image, repo, storage, idle timeout, dotfiles, and tool set — and the facade writes an owner-scoped DevWorkspace CR. The operator reconciles it into a StatefulSet with a persistent home volume, a headless Service, and a per-workspace Secret, mounting the config's files read-only at /etc/fastverk/config so every workspace boots RBE-ready. You land in a browser IDE (openvscode-server) or an in-pod terminal, with agent CLIs — opencode, Claude Code, Codex — a click away. When you step away it scales to zero; the volume is kept.

A dev environment is a Kubernetes resource — owner-scoped, template-driven, and scale-to-zero when idle.

plugin-workspaces · a self-hosted Codespaces alternative
the console

Your workspaces, live.

A card per DevWorkspace — its config, phase, and URL, with a launch button per provisioned tool. Values illustrative.

Workspaces live
DevWorkspace CRs · fastverk.savvifi.com/v1
workspaceconfigphaseurl
spurious-racoon default Running spurious-racoon.ws.fastverk.com
brave-otter rust-rbe Provisioning —
quiet-lynx default Suspended resumes on access
phases: Pending · Provisioning · Running · Suspended · Failedname: random adjective-animal
one click in

VS Code, a terminal, or an agent.

A config's tools become launch buttons on the card — web tools open a URL, tty tools open an in-pod terminal wired to the broker. The default config ships these.

default · tools
openvscode-server + ttybroker (:7681)
toolkindlaunches
VS Code web openvscode-server on :3000
Terminal tty /bin/bash -l
opencode tty the opencode agent CLI
Claude Code tty the claude agent CLI
Codex tty the codex agent CLI
agent CLIs: light up as the devcontainer image ships them
compose

A workspace is a set of layers. Pick them.

Beyond the default tools, a config is a composition you assemble from a searchable gallery — languages, runtimes, browsers, databases, CLIs, an agent — added à la carte or pulled whole from a bundle, each pinned to a version. Save the result as a template your team launches from. Preview — the ToolLayer catalog and the compose gallery are in build; layer sizes below are read from the shipped catalog.

compose · rust-bazel-rbe preview
WorkspaceConfig · tools + bundleRefs
layerversionsource
Rust stable rust-bundle
Bazel 7.3 rust-bundle
Claude Code Bedrock claude-mcp
PostgreSQL 16 à la carte
Chrome 129 à la carte
resolved: 5 layers · image +840 MB · cached on RBEgallery: 19 layers · 34 pinned versions · 3 bundles
the pipeline

Pick → provision → route → land.

One wildcard absorbs all the networking — no per-workspace DNS, cert, or Ingress.

01

Pick

Choose a WorkspaceConfig in the console (or fv ws create --config <name>). The facade writes an owner-scoped DevWorkspace CR with a random adjective-animal name.

02

Provision

The operator reconciles it into a StatefulSet, a persistent home volume, a headless Service, and a per-workspace Secret — mounting the config's files at /etc/fastverk/config.

03

Route

ws-proxy authenticates your session against spec.owner and routes <name>.ws.fastverk.com to the pod. No per-workspace DNS, cert, or Ingress is created.

04

Land

You're in a browser IDE or an in-pod terminal — RBE-ready (grpcs://rbe.fastverk.com:8980), with your agent CLIs a click away.

config-as-code + scale-to-zero

Templates you fork; workspaces that sleep.

The two properties that make it cheap and consistent.

How it stays cheap and consistent

  • Configs are templates: a WorkspaceConfig carries the image, repo, storage, idle timeout, dotfiles, and tools — the managed default plus any you author. No secrets in config; tokens arrive at runtime.
  • Scale-to-zero: after the idle timeout (default 30m) the workspace suspends — replicas to 0, the PVC retained — and resumes on next access. After the retention window (14 days) it's garbage-collected and its volume reclaimed.
  • Config-mount: the rendered files land read-only at /etc/fastverk/config (bazelrc, npmrc), so every workspace boots RBE-ready with no manual setup.
  • Owner-scoped: spec.owner is your identity and it's immutable — ws-proxy enforces it on every request, so a workspace is yours alone.
vs a managed cloud IDE

Your cluster, your RBE, your rules.

The alternative runs in a vendor's cloud, on a vendor's billing, behind vendor-managed URLs.

fastverk workspaces
managed cloud IDE
Where it runs
✓ Your cluster, wired to your RBE
A vendor's cloud
Model
✓ First-class Kubernetes CRs, inspectable
An opaque managed service
Templates
✓ WorkspaceConfig as code, forkable
A devcontainer file, per repo
Agents
✓ opencode / Claude Code / Codex built in
Bring your own
Networking
✓ One wildcard, no per-workspace Ingress
Vendor-managed URLs
Idle cost
✓ Scale-to-zero, volume retained
Per-vendor billing

Creating a workspace or forwarding a port creates no new DNS, cert, or Ingress — the wildcard and ws-proxy absorb all of it.

plugin-workspaces · one wildcard, owner-scoped

source · github.com/fastverk/plugin-workspaces

Prove it's safe to merge.

workspaces is one of 14 plugins in the fastverk console — hosted, or in your own cloud.