1
0

GUI support
All checks were successful
ci/woodpecker/push/woodpecker Pipeline was successful
ci/woodpecker/deployment/woodpecker Pipeline was successful

This commit is contained in:
2026-10-06 22:28:01 +00:00
parent d1c70186b5
commit 0953962142
4 changed files with 84 additions and 2 deletions

View File

@@ -10,7 +10,7 @@ mkdir -p "$(dirname "/etc/ssh/sshd_config.d/10-hostkeys.conf")"
printf 'HostKey %s\n' "${keys[@]}" > "/etc/ssh/sshd_config.d/10-hostkeys.conf"
# Setup the DinD socket:
if [ -n DOCKER_RUN_DIR ]; then
if [ -n "${DOCKER_RUN_DIR:-}" ]; then
ln -s "$DOCKER_RUN_DIR/docker.sock" /var/run/docker.sock || echo "Failed to symlink Docker socket!"
fi
@@ -37,6 +37,38 @@ if [ -f "/home/$TARGET_USER/.on-boot.sh" ]; then
sudo -u "$TARGET_USER" "/home/$TARGET_USER/.on-boot.sh"
fi
# Set the target user's password for RDP logins (SSH remains key-only):
if [ -f /etc/xrdp/secrets/password-hash ]; then
usermod -p "$(cat /etc/xrdp/secrets/password-hash)" "$TARGET_USER"
else
echo "No /etc/xrdp/secrets/password-hash -- RDP logins will not work!" >&2
fi
# Use a mounted xrdp TLS cert if present, otherwise generate a self-signed one:
if [ ! -f /etc/xrdp/tls/cert.pem ] || [ ! -f /etc/xrdp/tls/key.pem ]; then
echo "No xrdp TLS cert in /etc/xrdp/tls, generating a self-signed one..."
mkdir -p /etc/xrdp/tls
openssl req -x509 -newkey rsa:3072 -nodes -days 3650 \
-keyout /etc/xrdp/tls/key.pem -out /etc/xrdp/tls/cert.pem \
-subj "/CN=$(hostname)" 2>/dev/null
chgrp xrdp /etc/xrdp/tls/key.pem /etc/xrdp/tls/cert.pem
chmod 640 /etc/xrdp/tls/key.pem /etc/xrdp/tls/cert.pem
fi
[ -s /etc/xrdp/rsakeys.ini ] || xrdp-keygen xrdp /etc/xrdp/rsakeys.ini >/dev/null
# Give the target user access to the iGPU, if passed through:
if [ -e /dev/dri/renderD128 ]; then
render_gid="$(stat -c %g /dev/dri/renderD128)"
getent group "$render_gid" >/dev/null || groupadd --gid "$render_gid" host-render
usermod -aG "$(getent group "$render_gid" | cut -d: -f1)" "$TARGET_USER"
fi
# Start the system D-Bus (no systemd here) and xrdp for the desktop:
mkdir -p /run/dbus /run/xrdp
dbus-daemon --system --fork
xrdp-sesman
xrdp
echo "Ready."
tail -f /var/log/container-stdout.log &