‹ BackHN Continuity

Thread

VSCode's SSH Agent Is Bananas (2025)

310 points · 218 comments · Rapzid

  1. danielklnstein · · focus · HN ↗
    Missing a (2025)

    FYI VSCode's SSH Agent is a godsend for remote development - the "disadvantages" that Fly lists are part of its advantages. I've worked in several teams that have made extensive use of the extension, and it's never been an issue. You can restrict SSH access arbitrarily to ensure whatever security or access guardrails you need.

    1. godelski · · focus · HN ↗
      As a Linux user I've hated VSCode's ssh. There's lot of annoying things that make it harder to admin for. Like it doesn't pick up the MotD, preventing me from showing users important messages. I've found that it also doesn't reuse sessions (at least by default. TBF, neither does ssh) and I'll find that there's just dozens of open sessions over months from users. I literally had to write a script to boot people...

      It would be one thing if the plugin was just a wrapper and people were still expected to know ssh but the plugin abstracts away all that and is intended to make it a "use VSCode on remote machine" tool. So it needs to do more than just handle creds, otherwise it creates a divergent experience while making people think it's just ssh

      1. throw0101a · · focus · HN ↗
        > There's lot of annoying things that make it harder to admin for.

        It also (AIUI) tries to walk the entire file tree, so have fun with NFS (auto)mounts.

        It also amounts to letting off fork bombs: we set up limits for a maximum of 256 process per UID, and regularly get folks asking "what does this 'cannot fork' message mean?": it mean you're trying to DoS the system.

        1. astrange · · focus · HN ↗
          And it doesn't work on BSD, and fails in an opaque way when it tries.
        2. DougBTX · · focus · HN ↗
          > we set up limits for a maximum of 256 process per UID, and regularly get folks asking "what does this 'cannot fork' message mean?"

          The max limit on 64 bit systems is what, 4,194,303? So if you have over 16,000 users per VM this limit makes sense, otherwise it just seems user-hostile.

          1. dspillett · · focus · HN ↗
            Every process takes some memory and other resource, yes a stale process will pretty much all end up all paged out and not massively in the way of active processes, but they still aren't entirely free so it is more than a bean-counting number.

            Yes, under Linux (and most unix-a-like systems) small processes are cheap to bring up and tear down which is why we create them so much, and it is not uncommon for complex interactive commands and bits of shell scripts to create several¹, but these are all likely to be short-lived so a limit of 256 certainly doesn't seem to be obscenely low to me.

            What could it be doing that requires 256+ processes to be kept around for a prolonged time?

            --------

            [1] made up example: comparing filtered content of two gzipped files and sending the result through a script to send alerts by mail if certain things are found would be 7+ (2x gzip, 2x or more grep, diff, bash, mail or curl depending on what service you are sending alerts through)

          2. throw0101a · · focus · HN ↗
            > The max limit on 64 bit systems is what, 4,194,303? So if you have over 16,000 users per VM this limit makes sense, otherwise it just seems user-hostile.

            And yet we still regularly loads of >100 on our 64 core HPC login codes, and swap is regularly used even with 96G of system memory (we have per UID memory limits too).

            What's hostile is the VSCode (and Codex and Claude) makers developing tools that basically DoS a system because they assume it will operate only on single-user machines.

            (And WTF are you doing that you're forking 256 processes? We have quite a few expensive HPC nodes: use those to build, not the damn login nodes.)

          3. godelski · · focus · HN ↗

              > The max limit on 64 bit systems is what, 4,194,303?
            
            What a weird framing... I'm not sure what you're even trying to argue. I mean a single process can overload the machine. Just because you can label 4m processes doesn't mean you can actually run that many programs. Just think about that for a minute. 256 processes is pretty generous
            1. pinkgolem · · focus · HN ↗
              i am not sure what you are arguing, but if user frequently run into it.. it seems hostile?

              if you have a paid tier which offers more, you do you

              if this is internally and you are a service provider to people.. why?

              also 256 is not much today, my mac with a few things open is at 800

              1. californical · · focus · HN ↗
                800 running a desktop environment, iCloud syncing, tons of background programs (wallpaper manager is one! Another for keyboard brightness, probably)

                Compared to someone on an ssh connection. No desktop, no Apple Account, no user session programs, etc. You really don’t need much

                1. pinkgolem · · focus · HN ↗
                  i mean you wrote yourself that users are frequently running into this..

                  i do not know why/in which context you are running this, and how frequently your users are executing forkbombs(i assume school/kids?)

                  my server is also running 400 something processes, one postgres instance alone is like 40?

                  1. godelski · · focus · HN ↗
                    Are all those processes 1 UID?
              2. bitfilped · · focus · HN ↗
                It might seem hostile to one user, it's not to the other 20-40 trying to get work done on a login node with runaway processes.
          4. cmiles74 · · focus · HN ↗
            What would truly be user hostile would be to allow so many processes per UID that a small handful (maybe using VSCode) make the system slow or unresponsive to everyone else.
        3. drowsspa · · focus · HN ↗
          Honestly every developer needs to increase those default limits, they are too low for modern development... So you are just crippling them and a proof of that is they keep getting this error while in their regular workflow
          1. eqvinox · · focus · HN ↗
            I don't even hit 256 on my desktop with a shitton of things open and 75 firefox sandbox processes, much less on a remote server. What in heaven's name are you doing to cross 256?

            (Also this isn't a default limit.)

          2. godelski · · focus · HN ↗

              > they are too low for modern development...
            
            Do the math, 256 processes 50 MB each. How much RAM is that?

            Too low? 256 reads as *pretty* generous to me.

            1. bitfilped · · focus · HN ↗
              Honestly I think this thread has just devolved to HPC admins vs people who don't understand how shared multiuser sytems work cause they've been stuck on a laptop for too long to remember.
          3. throw0101a · · focus · HN ↗
            > Honestly every developer needs to increase those default limits, they are too low for modern development...

            The users can develop on >100 compute nodes, but choose not to bother doing any kind of forwarding/proxying/jumping to them and just do stuff on the login nodes.

            If they can't be bothered to do a "ssh -J …" then it's on them. The resources are there.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.