1. They aren't allowed to use Microsoft's extension marketplace for legal reasons, so they use their own. It honestly kinda sucks though because not all the extensions are there, they're obviously behind the current version, and tons of extensions don't work out of the box because the "workaround marketplace" doesn't correctly build the extensions (lots of GitHub tickets give the advice of "run npm install in the extension directory").
Of course, that doesn't mean YOU can't configure code-server to use the Microsoft extension marketplace :). Set these environment variables before you start:
SERVICE_URL=https://marketplace.visualstudio.com/_apis/public/gallery
ITEM_URL=https://marketplace.visualstudio.com/items
2. If you're using Chrome/Safari and not using HTTPS, several extensions (e.g., vscode-vim and the Java extensions) will stay stuck saying "activating extensions" forever. There's apparently an issue with Chrome/Safari not allowing "something" when running over HTTP[1]. This all works on Firefox, but one thing I've found is that vscode-vim fails with some sort of regexp error on Firefox. So you should really be running over HTTPS and using Chrome/Safari.