Lifecycle specification

Post-Attach Phase

Human-facing hooks that run each time a developer or editor attaches — short guidance, actionable warnings, and pointers to interactive sign-in.

Applies at
.devcontainer/lifecycle/post-attach.d/
Status
Stable

01 Defines

The postAttachCommand phase: scripts in post-attach.d/ that run every time a developer or editor attaches to a running container.

02 Applies when

  • A task only makes sense once a person is present.
  • Interactive authentication cannot happen unattended and needs a short prompt instead.
  • The developer benefits from next-step guidance once the workspace is ready.

03 Boundaries

  • Workspace mutations, dependency installs, and service startup happen whether or not an editor attaches, so they belong earlier.
  • Nothing the repository needs in order to be usable depends on this phase.

Expected behaviour

  1. 01
    Scripts are fast and non-blocking, so they do not delay the editor.
  2. 02
    Scripts may run many times as developers detach and reattach.
  3. 03
    Missing authentication produces an instruction, not a failure.

Behaviour#

Post-attach is the last phase and the only one aimed at a person. It runs on every attach, including reattaching to a container that has been running for days, so it says what is useful now and gets out of the way.

The repository stays usable without it. A container that is started and never attached — by automation, for example — has everything it needs from the earlier phases; post-attach only adds guidance on top. Anything that has to happen for the session itself belongs in Post-Start Phase .

Good uses

  • Checking aws sts get-caller-identity and suggesting aws sso login --profile sandbox
  • Checking gh auth status and showing a short gh auth login instruction
  • Showing next steps such as npm run dev or hugo server -D

Avoid

  • Workspace mutations, dependency installs, or service startup
  • Long-running tasks that delay the editor
  • Anything that must succeed before the repository is usable

Examples#

.devcontainer/lifecycle/post-attach.d/10-check-github-auth.sh
#!/usr/bin/env bash
set -euo pipefail

if ! gh auth status >/dev/null 2>&1; then
    echo "GitHub authentication is not configured. Run: gh auth login"
fi

The hook prints and exits successfully either way. Signing in is left to the developer, and an earlier phase is never blocked waiting for it.