Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Offical apps | Community apps | Demo | Docs | Install
  1. Cloudron Forum
  2. App Wishlist
  3. Kasm - Virtual Desktop / Browser Isolation

Kasm - Virtual Desktop / Browser Isolation

Scheduled Pinned Locked Moved App Wishlist
42 Posts 15 Posters 18.2k Views 16 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • necrevistonnezrN Offline
    necrevistonnezrN Offline
    necrevistonnezr
    wrote on last edited by
    #33

    BTW I have built something similar with Apache Guacamole (on the app store) and a local Ubuntu XFCE Docker. Although not recommended, if you configure the network for such Docker correctly, you should have no interference with Cloudron.
    If anyone is interested, I can put up a guide (and if staff doesn’t disagree)

    1 Reply Last reply
    1
    • L LoudLemur

      @robi said in Kasm - Virtual Desktop / Browser Isolation:

      I would start with the outer part, which means helping the Cloudron team integrate Sysbox.

      It would require a new base container image that runs with a new container runtime (sysbox) instead of the default. This is just an extra parameter in the docker run command.

      $ docker run --runtime=sysbox-runc -it some-image
      

      All else stays the same.

      In this container, you can now run Systemd, Docker, Kubernetes, etc., just like you would on a physical host or virtual machine. You can launch inner containers (and even inner privileged containers), knowing that the outer container is strongly isolated from the underlying host (via the Linux user-namespace). No more complex docker images or docker run commands, and no need for unsecure privileged containers.

      Thanks. Would this container need any modifications to enable it to run init daemons, like OpenRC, Dinit, s6, runit, SysVinit, and Upstart?

      robiR Offline
      robiR Offline
      robi
      wrote on last edited by
      #34

      @LoudLemur said in Kasm - Virtual Desktop / Browser Isolation:

      @robi said in Kasm - Virtual Desktop / Browser Isolation:
      ...
      Thanks. Would this container need any modifications to enable it to run init daemons, like OpenRC, Dinit, s6, runit, SysVinit, and Upstart?

      No, other than installing the init services. That's why it's a new, different or user supplied (docker) base image that already has these installed.

      Very flexible once you escape the regular docker runc limitations.

      You can run an entirely different distro if you want to. 🙂

      Conscious tech

      1 Reply Last reply
      0
      • H Offline
        H Offline
        hakunamatata
        wrote on last edited by hakunamatata
        #35

        I have Kasm running behind a Cloudron reverse proxy and connected to Cloudron's OIDC directory for user authentication. It was pretty straightforward to set up, but if anyone wants/needs a written guide, I am happy to do so.

        1 Reply Last reply
        3
        • J Offline
          J Offline
          joseph
          Staff
          wrote on last edited by
          #36

          @hakunamatata that will be great. Maybe something for https://docs.cloudron.io/guides/community/ too?

          1 Reply Last reply
          0
          • H Offline
            H Offline
            hakunamatata
            wrote on last edited by
            #37

            @joseph ok will do

            1 Reply Last reply
            1
            • H Offline
              H Offline
              hakunamatata
              wrote on last edited by hakunamatata
              #38
              1. Install Kasm. (I have it running on a dedicated VM and followed the single server installation instructions: https://kasmweb.com/docs/latest/install/single_server_install.html)

              2. Once installed, log into the Kasm host using the admin credentials and then configure the reverse proxy by going to Infrastructure > Zones in the left hand side panel and following the instructions here: https://kasmweb.com/docs/latest/how_to/reverse_proxy.html#update-zones
                (Note: in my case, the default parameters worked fine)

              3. Install the Cloudron App proxy and point it to your Kasm host e.g. https://[IP-ADDRESS]:443. Now you should be able to access the Kasm login page via the domain you set in the app proxy. e.g. kasm.yourdomain.tld

              4. To use OpenID authentication, first we need to add Kasm as an OIDC client in Cloudron. Go to Cloudron > User Director > OpenID Connect Provider > New Client, and enter the following:
                Name: kasm
                Login callback URL: https://kasm.yourdomain.tld/api/oidc_callback
                Signing Algorithm: RS256

              Copy the resulting Client ID and Client Secret for use in step 5.

              1. Now in Kasm, go to Access Management > Authentication > OpenID and follow the instructions here: https://kasmweb.com/docs/latest/guide/oidc.html
                Main parameters to be set are:
                Display Name: Can be anything e.g. Login with Cloudron
                Hostname: kasm.yourdomain.tld
                Client ID: paste from step 4
                Client Secret: paste from step 4
                Authorization URL: https://my.yourdomain.tld/openid/auth
                Token URL: https://my.yourdomain.tld/openid/token
                User Info URL: https://my.yourdomain.tld/openid/me
                Scope (One Per Line): openid profile email
                Username Attribute: sub
                Redirect URL: this should be automatically populated and should match what you entered as the callback url in step 4 i.e. https://kasm.yourdomain.tld/api/oidc_callback

              I believe that should be it! Give it a shot and let me know if you run into any issues. There could be a possibility that I forgot to document something in the above steps. Once it is confirmed to be working, I will polish it up and submit it as a community guide.

              1 Reply Last reply
              3
              • robiR Offline
                robiR Offline
                robi
                wrote last edited by
                #39

                KASM docs are fully sysbox aware: https://kasm.com/docs/1.17.0/how_to/sysbox_runtime.html

                Conscious tech

                L 1 Reply Last reply
                1
                • robiR robi

                  KASM docs are fully sysbox aware: https://kasm.com/docs/1.17.0/how_to/sysbox_runtime.html

                  L Offline
                  L Offline
                  LoudLemur
                  wrote last edited by
                  #40

                  @robi We like the look of this!

                  1 Reply Last reply
                  1
                  • robiR robi

                    I would start with the outer part, which means helping the Cloudron team integrate Sysbox.

                    It would require a new base container image that runs with a new container runtime (sysbox) instead of the default. This is just an extra parameter in the docker run command.

                    $ docker run --runtime=sysbox-runc -it some-image
                    

                    All else stays the same.

                    In this container, you can now run Systemd, Docker, Kubernetes, etc., just like you would on a physical host or virtual machine. You can launch inner containers (and even inner privileged containers), knowing that the outer container is strongly isolated from the underlying host (via the Linux user-namespace). No more complex docker images or docker run commands, and no need for unsecure privileged containers.

                    L Offline
                    L Offline
                    LoudLemur
                    wrote last edited by
                    #41

                    @robi @girish, do you think we might be able to do this sysbox integration?

                    1 Reply Last reply
                    0
                    • girishG Offline
                      girishG Offline
                      girish
                      Staff
                      wrote last edited by
                      #42

                      As it stands, sysbox integration is unlikely. There are way way more pressing things to attend to for next few months.

                      1 Reply Last reply
                      1

                      Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                      Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                      With your input, this post could be even better 💗

                      Register Login
                      Reply
                      • Reply as topic
                      Log in to reply
                      • Oldest to Newest
                      • Newest to Oldest
                      • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search