Deployment Overview of Kasm Workspaces on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the server must meet the following requirements:
-
Operating System: Debian or Ubuntu (specifically Jammy Jellyfish for certain Docker version locks).
-
Privileges: Root or sudo access is required for package installation and service management.
-
Dependencies: The system requires
ca-certificates,curl,gnupg,python3-pip,python3-requests, andpython3-docker. -
Docker Requirements: A specific version of Docker CE (e.g.,
5:28.5.2-1~ubuntu.22.04~jammy) may be required on Ubuntu systems to ensure compatibility, with the package held to prevent unintended upgrades.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain template based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | kasm |
| Domain | hostkey.in |
| Full template | kasm{Server_ID}.hostkey.in |
File and Directory Structure¶
The application utilizes the following directory structure for configuration, data, and certificates:
-
/opt/kasm: Main application installation directory. -
/opt/kasm/current/certs/: Location of active Kasm Nginx certificates. -
/etc/docker/: Docker daemon configuration (daemon.json). -
/data/kasm/: Primary data storage for the application. -
/data/kasm/profiles: Directory dedicated to user profiles. -
/root/kasm_release: Temporary directory used during the installation process.
Application Installation Process¶
The installation method varies depending on the operating system:
Debian and Ubuntu Systems¶
-
The system packages are updated via
apt. -
A specific version of Docker CE is installed and "held" to prevent automatic updates that might cause incompatibility.
-
An official Kasm release archive (
kasm_release_1.17.0.bbc15c.tar.gz) is downloaded and extracted in the/rootdirectory. -
The installation script
./install.shis executed from the/root/kasm_releasedirectory with parameters for administrative credentials, public hostname, EULA acceptance, and a swap size of 8192MB.
RHEL Systems¶
-
Docker is installed to provide the container runtime.
-
Data directories (
/data,/data/kasm/, and/data/kasm/profiles) are created with restricted permissions (0640). -
The application is deployed as a Docker container using the
lscr.io/linuxserver/kasm:latestimage.
Access Rights and Security¶
-
Firewall: Ensure that the Kasm port (as defined in configuration) and standard web ports are open.
-
Permissions: Data directories are owned by
rootwith mode0640. -
SSL/TLS: SSL certificates are obtained via Certbot using the
--standalonemethod to secure the connection.
Docker Containers and Their Deployment¶
The deployment utilizes Docker for service orchestration.
Kasm Container (RHEL Method)¶
-
Image Name:
lscr.io/linuxserver/kasm:latest -
Ports:
-
3000:3000 -
{KASM_PORT}:{KASM_PORT} -
Volumes:
-
/data/kasm:/opt -
/data/kasm/profiles:/profiles -
/dev/input:/dev/input -
/run/udev/data:/run/udev/data -
Environment Variables:
KASM_PORT -
Restart Policy:
unless-stopped -
Privileges: The container runs in
--privilegedmode.
Custom Scripts and Additional Setup¶
The following actions are performed during the setup process:
-
Docker Configuration: A custom
daemon.jsonis deployed to/etc/docker/. -
Compose Plugin Management: Older versions of Docker Compose (1.42) are removed, and version 1.52 is installed into
/usr/local/lib/docker/. -
SSL Certificate Integration: After obtaining certificates via Certbot, the existing Kasm Nginx certificates (
kasm_nginx.keyandkasm_nginx.crt) are backed up and replaced with the Let's Encrypt full chain and private key files.
Application Update Instructions¶
To update the application:
-
Docker-based deployments: Use the following command to pull the latest images and restart services:
-
Script-based deployments: Re-run the installation script located in the
/root/kasm_releasedirectory.
Location of Configuration Files and Data¶
-
Application Configs:
/opt/kasm/current/ -
User Profiles:
/data/kasm/profiles -
Docker Daemon Config:
/etc/docker/daemon.json -
SSL Certificates:
-
/etc/letsencrypt/live/{domain}/(Source) -
/opt/kasm/current/certs/(Active application certs)
Available Ports for Connection¶
-
Web Interface: Accessible via the configured KASM port and standard HTTPS.
-
Internal Container Port:
3000
Starting and Stopping the Application¶
The following commands are used to manage the Kasm services:
-
Stop Services:
/opt/kasm/bin/stop -
Start Services:
/opt/kasm/bin/start