fix: make Guacamole fixture dual-stack and keep VM display awake
This commit is contained in:
@@ -9,6 +9,7 @@ The helper builds this private path:
|
||||
|
||||
```text
|
||||
browser -- HTTPS/self-signed --> nginx + Guacamole containers
|
||||
(IPv4 and, in public mode, a tracked IPv6 forward)
|
||||
|
|
||||
private Docker gateway
|
||||
|
|
||||
@@ -69,9 +70,23 @@ port (`54001`). They can be overridden without editing tracked files through
|
||||
`RVBOX_TEST_VBOX_HOST`, `RDP_ACCESS_VRDE_HOST`, `RDP_ACCESS_VRDE_PORT`,
|
||||
`RDP_ACCESS_WEB_USER`, `RDP_ACCESS_RDP_USER`, `RDP_ACCESS_BIND`,
|
||||
`RDP_ACCESS_HTTP_PORT`, `RDP_ACCESS_TUNNEL_PORT`, and
|
||||
`RDP_ACCESS_PUBLIC_HOST`. The helper deliberately limits the VRDE host to
|
||||
`RDP_ACCESS_PUBLIC_HOST`, `RDP_ACCESS_IPV6_BIND`, and
|
||||
`RDP_ACCESS_IPV6_FORWARD`. The helper deliberately limits the VRDE host to
|
||||
Helium loopback (`127.0.0.1` or `localhost`) so an override cannot accidentally
|
||||
turn the diagnostic server into a remote target.
|
||||
Set `RDP_ACCESS_GUACD_LOG_LEVEL=debug` temporarily when collecting detailed
|
||||
guacd/RDP negotiation diagnostics; the default is `info`.
|
||||
|
||||
When `--bind 0.0.0.0` is used, `up` also starts a tracked `socat` listener on
|
||||
`[::]:$RDP_ACCESS_HTTP_PORT` and forwards it to the IPv4 gateway listener. This
|
||||
matters when the public hostname has an AAAA record: some browsers choose IPv6
|
||||
for the WebSocket even if the initial page used IPv4. The listener is recorded
|
||||
under `.runtime/ipv6-forward.pid` and is removed by `down` and `clean`. Its
|
||||
default bind is `::` (`RDP_ACCESS_IPV6_BIND`); set
|
||||
`RDP_ACCESS_IPV6_FORWARD=never` to deliberately use IPv4 only, `always` to make
|
||||
IPv6 startup a hard requirement, or leave the default `auto` for a warning and
|
||||
an IPv4-only fallback when `socat` is unavailable. `status` reports
|
||||
`ipv6_forward=active`, `active_external`, `inactive`, or `disabled`.
|
||||
|
||||
If `up` is run again while the Compose services are still running, it is
|
||||
idempotent: an existing healthy tunnel is reused, and a missing tunnel is
|
||||
@@ -123,7 +138,9 @@ test/rdp-access/rdp-access url
|
||||
|
||||
If the browser reaches Guacamole but stays on “Waiting for response”, run
|
||||
`status` first. Confirm `private_tunnel=active` (or
|
||||
`active_external`), then check the VM state and the last lines of
|
||||
`active_external`) and, for a public dual-stack hostname,
|
||||
`ipv6_forward=active` (or a known-good external forward). Then check the VM
|
||||
state and the last lines of
|
||||
`.runtime/tunnel.log`. A tunnel can be recreated without losing the Compose
|
||||
stack by running `up` again. This helper already uses `security=rdp` and
|
||||
disables Guacamole's GFX extension, which are required by the fixture's legacy
|
||||
@@ -132,9 +149,11 @@ VRDE server. Do not switch the helper to native Windows RDP:
|
||||
unusable, stop this helper and use Guest Control for the deterministic portion
|
||||
of the work; record the blocked interactive step in the native test report.
|
||||
|
||||
The helper requires Docker/Docker Compose, SSH access through the existing
|
||||
`helium-remote` alias, and the fixture password file documented in
|
||||
The helper requires Docker/Docker Compose, `socat` for the optional public
|
||||
dual-stack forward, SSH access through the existing `helium-remote` alias, and
|
||||
the fixture password file documented in
|
||||
[`docs/testing-vm.md`](../../docs/testing-vm.md). It does not install host
|
||||
packages, write credentials into Git, or alter VM settings. The tracked files
|
||||
are Docker-only configuration and the controller script; all generated content
|
||||
is ignored beneath `.runtime/`.
|
||||
packages, write credentials into Git, or alter VM identity/settings. The
|
||||
authoritative `test-host prepare` step applies only the disposable
|
||||
display/sleep keepalive needed by VirtualBox VRDE; all generated content is
|
||||
ignored beneath `.runtime/`.
|
||||
|
||||
Reference in New Issue
Block a user