Workspaces
File explorer
The Files tab on a Layerbase Workspace shows the files your agents work on, right in the dashboard: browse your repositories, read what an agent changed, make a small edit, or upload a screenshot for an agent to look at. No SSH key, editor or terminal is needed.
The file explorer is rolling out with the web terminal and is part of the Workspaces early adopter program.
What you can see
Three folders, and nothing else on the workspace:
~/dev: your repositories.~/worktrees: the worktrees agents create for feature branches.~/uploads: files you uploaded.
Your SSH keys, agent sign-ins and settings live elsewhere in the home folder and are never shown. Hidden files inside the three folders are listed; .git folders are tucked away behind a Show .git link.
Opening the explorer
- Open the workspace in the dashboard.
- Choose the Files tab and pick a folder at the top.
- Select a folder to open it, or a file to view it.
If the tab asks you to update workspace tools, open the Settings tab and run Update workspace tools once. It takes about a minute and does not restart anything you are running.
Viewing files
- Text files up to 1 MB are shown as plain text. Markdown files show a formatted preview, with a Source button for the raw text. Images in Markdown are not loaded, and only web links are clickable.
- PNG, JPEG, GIF and WebP images are shown as pictures. SVG files are shown as text.
- Larger files, and binary files such as archives, are not shown. Open them in the terminal instead.
- Copy path copies the full path on the workspace, ready to hand to an agent.
- Folders with more than 1,000 entries load in pages; only the first 5,000 are shown.
Files with secrets
Files that usually hold passwords, keys or tokens are listed with a lock, and their contents stay hidden until you choose Reveal:
- .env and .env.* (but not .env.example)
- .envrc and .dev.vars
- .npmrc, .netrc, .pgpass and .git-credentials
- .git/config (remote URLs can hold tokens)
- keys and certificates: *.pem, *.key, *.p12, *.pfx, id_*
- credentials*.json, *.tfvars and Terraform state
Any other text file that contains a private key or a well-known token format is hidden the same way. Reveal protects you from showing a secret on a shared screen by accident; the contents are never stored in your browser.
Editing a file
Choose Edit on a text file, make your change, and choose Save (or press Ctrl+S, Cmd+S on Mac).
- Only existing UTF-8 text files up to 1 MB can be edited, and never anything inside a
.gitfolder. - Files with secrets stay read-only here, even after Reveal, and so does a file without write permission for its owner (for example mode
0444). Change those in the terminal. - If an agent changed the file after you opened it, Save is refused instead of overwriting the agent's work. Reload the file and make your edit again.
- The file keeps its permissions. Creating, renaming and deleting files is done in the terminal.
Uploading files
Choose Upload, or drop files onto the file list, to save them into the folder you are viewing. After an upload the tab shows the full path with a Copy path button, so you can paste it into an agent's prompt.
- The same types as the terminal: images (PNG, JPEG, GIF, WebP), PDFs, and text files, up to 20 MB each.
- Files are saved as
YYYYMMDD-HHMMSS-name.extand never overwrite an existing file. - Only uploads in
~/uploadsitself are cleaned up after 7 days, and that folder holds at most 200 MB. Files you upload into a repository stay until you remove them.
Limits
- The explorer can be open in 2 browser tabs per workspace. It does not use up any of the terminal's tabs.
- It disconnects after 30 minutes without use and reconnects when you next click. Once you edit or upload, the connection allows changes for up to 2 hours.
Security and privacy
- Every file is read and written as the
ubuntuuser, the same as your agents, by a separate process with limited rights. Nothing in the explorer runs as root. - Links are shown but never followed, so a link inside a repository cannot lead the explorer outside the three folders.
- Only the workspace owner can open the explorer, using a single-use pass that is valid for one minute and only for that workspace. Browsing uses a read-only pass; editing and uploading ask for one that allows changes.
- File names, paths and contents are never logged or recorded. We keep only connection metadata (when a session started and ended, how many requests it made) to run the service.