From 095396214285eb01d35dbc83ae039b81a722fd4c Mon Sep 17 00:00:00 2001 From: Garrett Mills Date: Tue, 6 Oct 2026 22:28:01 +0000 Subject: [PATCH] GUI support --- jump-box/Dockerfile | 24 +++++++++++++++++++++++- jump-box/README.md | 15 +++++++++++++++ jump-box/startup.bash | 34 +++++++++++++++++++++++++++++++++- jump-box/startwm-xfce.sh | 13 +++++++++++++ 4 files changed, 84 insertions(+), 2 deletions(-) create mode 100644 jump-box/README.md create mode 100644 jump-box/startwm-xfce.sh diff --git a/jump-box/Dockerfile b/jump-box/Dockerfile index cb8ee2f..a345398 100644 --- a/jump-box/Dockerfile +++ b/jump-box/Dockerfile @@ -7,6 +7,7 @@ ENV DOCKER_RUN_DIR=/run/dind COPY k8s.repo /etc/yum.repos.d/k8s.repo COPY startup.bash /usr/sbin/startup.bash +COPY startwm-xfce.sh /etc/xrdp/startwm-xfce.sh RUN dnf install -y \ https://mirrors.rpmfusion.org/free/fedora/rpmfusion-free-release-44.noarch.rpm \ @@ -18,7 +19,28 @@ RUN dnf install -y \ && wget -O /etc/yum.repos.d/kanidm.repo https://download.opensuse.org/repositories/network:/idm/Fedora_44/network:idm.repo \ && wget -O /etc/yum.repos.d/docker-ce.repo https://download.docker.com/linux/fedora/docker-ce.repo \ && dnf install -y kanidm-clients docker-ce-cli docker-buildx-plugin docker-compose-plugin \ + xfce4-session xfwm4 xfce4-panel xfdesktop xfce4-settings xfce4-terminal xfce4-appfinder \ + xfce4-notifyd xfce4-screenshooter Thunar dbus-x11 dbus-daemon adwaita-icon-theme xdg-utils \ + google-noto-sans-fonts google-noto-sans-mono-fonts liberation-fonts \ + firefox thunderbird xrdp xorgxrdp openssl fuse3 \ && dnf clean all -y \ - && chmod +x /usr/sbin/startup.bash + && chmod +x /usr/sbin/startup.bash /etc/xrdp/startwm-xfce.sh \ + && rm -f /etc/xrdp/cert.pem /etc/xrdp/key.pem /etc/xrdp/rsakeys.ini \ + && rm -f /etc/xdg/autostart/xfce-polkit.desktop /etc/xdg/autostart/geoclue-demo-agent.desktop /etc/xdg/autostart/localsearch-3.desktop \ + && sed -i \ + -e 's|^security_layer=.*|security_layer=tls|' \ + -e 's|^certificate=.*|certificate=/etc/xrdp/tls/cert.pem|' \ + -e 's|^key_file=.*|key_file=/etc/xrdp/tls/key.pem|' \ + -e 's|^autorun=.*|autorun=Xorg|' \ + -e '/^\[Xvnc\]/,$d' \ + /etc/xrdp/xrdp.ini \ + && sed -i \ + -e 's|^EnableUserWindowManager=.*|EnableUserWindowManager=false|' \ + -e 's|^DefaultWindowManager=.*|DefaultWindowManager=/etc/xrdp/startwm-xfce.sh|' \ + -e 's|^AllowRootLogin=.*|AllowRootLogin=false|' \ + /etc/xrdp/sesman.ini \ + && printf 'PasswordAuthentication no\nKbdInteractiveAuthentication no\n' > /etc/ssh/sshd_config.d/20-no-password.conf + +EXPOSE 22 3389 CMD ["/usr/sbin/startup.bash"] diff --git a/jump-box/README.md b/jump-box/README.md new file mode 100644 index 0000000..c9faf24 --- /dev/null +++ b/jump-box/README.md @@ -0,0 +1,15 @@ +# jump-box + +## GUI (XFCE over RDP) first-time setup + +1. **Set a password for RDP logins:** Generate a hash and mount it at `/etc/xrdp/secrets/password-hash`: + ```sh + openssl passwd -6 > password-hash + ``` +2. **Optional: mount a persistent TLS cert** as `cert.pem` + `key.pem` under `/etc/xrdp/tls/` + ```sh + openssl req -x509 -newkey rsa:3072 -nodes -days 3650 -keyout key.pem -out cert.pem -subj "/CN=jump-box" + ``` +3. **Expose the port:** expose TCP `3389`. +4. **Optional iGPU setup:** Pass through `/dev/dri`; the user is added to its render group on boot. +5. **Connect:** For Remmina, set colour depth to "GFX AVC444" and network type to "Automatic detection" to get H.264 diff --git a/jump-box/startup.bash b/jump-box/startup.bash index 7f04fa9..35ef4f7 100644 --- a/jump-box/startup.bash +++ b/jump-box/startup.bash @@ -10,7 +10,7 @@ mkdir -p "$(dirname "/etc/ssh/sshd_config.d/10-hostkeys.conf")" printf 'HostKey %s\n' "${keys[@]}" > "/etc/ssh/sshd_config.d/10-hostkeys.conf" # Setup the DinD socket: -if [ -n DOCKER_RUN_DIR ]; then +if [ -n "${DOCKER_RUN_DIR:-}" ]; then ln -s "$DOCKER_RUN_DIR/docker.sock" /var/run/docker.sock || echo "Failed to symlink Docker socket!" fi @@ -37,6 +37,38 @@ if [ -f "/home/$TARGET_USER/.on-boot.sh" ]; then sudo -u "$TARGET_USER" "/home/$TARGET_USER/.on-boot.sh" fi +# Set the target user's password for RDP logins (SSH remains key-only): +if [ -f /etc/xrdp/secrets/password-hash ]; then + usermod -p "$(cat /etc/xrdp/secrets/password-hash)" "$TARGET_USER" +else + echo "No /etc/xrdp/secrets/password-hash -- RDP logins will not work!" >&2 +fi + +# Use a mounted xrdp TLS cert if present, otherwise generate a self-signed one: +if [ ! -f /etc/xrdp/tls/cert.pem ] || [ ! -f /etc/xrdp/tls/key.pem ]; then + echo "No xrdp TLS cert in /etc/xrdp/tls, generating a self-signed one..." + mkdir -p /etc/xrdp/tls + openssl req -x509 -newkey rsa:3072 -nodes -days 3650 \ + -keyout /etc/xrdp/tls/key.pem -out /etc/xrdp/tls/cert.pem \ + -subj "/CN=$(hostname)" 2>/dev/null + chgrp xrdp /etc/xrdp/tls/key.pem /etc/xrdp/tls/cert.pem + chmod 640 /etc/xrdp/tls/key.pem /etc/xrdp/tls/cert.pem +fi +[ -s /etc/xrdp/rsakeys.ini ] || xrdp-keygen xrdp /etc/xrdp/rsakeys.ini >/dev/null + +# Give the target user access to the iGPU, if passed through: +if [ -e /dev/dri/renderD128 ]; then + render_gid="$(stat -c %g /dev/dri/renderD128)" + getent group "$render_gid" >/dev/null || groupadd --gid "$render_gid" host-render + usermod -aG "$(getent group "$render_gid" | cut -d: -f1)" "$TARGET_USER" +fi + +# Start the system D-Bus (no systemd here) and xrdp for the desktop: +mkdir -p /run/dbus /run/xrdp +dbus-daemon --system --fork +xrdp-sesman +xrdp + echo "Ready." tail -f /var/log/container-stdout.log & diff --git a/jump-box/startwm-xfce.sh b/jump-box/startwm-xfce.sh new file mode 100644 index 0000000..f69ce9f --- /dev/null +++ b/jump-box/startwm-xfce.sh @@ -0,0 +1,13 @@ +#!/usr/bin/bash -l + +# xrdp session entrypoint: start an XFCE desktop on the xorgxrdp display. +# Lives in /etc/xrdp (not ~/.xsession) since the home dir is mounted and shared with the CLI setup. + +unset DBUS_SESSION_BUS_ADDRESS +export XDG_RUNTIME_DIR="/tmp/runtime-$(id -u)" +mkdir -p -m 0700 "$XDG_RUNTIME_DIR" +export XDG_SESSION_TYPE=x11 +export XDG_CURRENT_DESKTOP=XFCE +export MOZ_ENABLE_WAYLAND=0 + +exec dbus-launch --exit-with-session startxfce4