Devsy
Developing in a Workspace

Reuse local credentials

Devsy makes some of your local credentials available inside the dev container, so you do not configure them in each workspace. It supports git credentials, Docker registry credentials, and GPG keys.

Only use with trusted repositories

Code that runs in the container, including lifecycle commands and features from devcontainer.json, can use these credentials. Do not enable them for repositories or devcontainer.json files you have not reviewed.

SSH agent forwarding never exposes your private key. It does let anything in the container request signatures, and so act as you against any service the key can access, for as long as the workspace runs.

Git

Devsy provides HTTPS credentials through a git credential helper. To turn off this credential injection in the default context:

devsy context set default -o SSH_INJECT_GIT_CREDENTIALS=false

SSH agent forwarding is separate and enabled by default (SSH_AGENT_FORWARDING=true). To disable it in the default context:

devsy context set default -o SSH_AGENT_FORWARDING=false

Disabling HTTPS credential injection does not disable SSH agent forwarding.

Docker

Devsy provides registry credentials through a Docker credential helper, so you can pull and push private images from the container. To turn it off for all workspaces:

devsy context set default -o SSH_INJECT_DOCKER_CREDENTIALS=false

GPG

Devsy can forward your GPG keys into the container over the SSH tunnel, so you can sign commits there. To turn it on for all workspaces:

devsy context set default -o GPG_AGENT_FORWARDING=true

Or for one workspace:

devsy workspace up --ssh-gpg-forwarding my-workspace

On this page