fix: keep Guacamole VRDE tunnel alive
This commit is contained in:
+33
-13
@@ -12,7 +12,7 @@ browser -- HTTPS/self-signed --> nginx + Guacamole containers
|
||||
|
|
||||
private Docker gateway
|
||||
|
|
||||
controller SSH tunnel --> Helium 127.0.0.1:3389 --> VirtualBox VRDE --> VM console
|
||||
controller SSH watchdog/tunnel --> Helium 127.0.0.1:3389 --> VirtualBox VRDE --> VM console
|
||||
```
|
||||
|
||||
Only the HTTPS listener can be made public, and that requires an explicit
|
||||
@@ -53,7 +53,12 @@ For localhost-only use, omit `--bind` and `--public-host`. The default listener
|
||||
is `127.0.0.1:5002`; use a local SSH forward or a browser on the controller.
|
||||
Choose alternate ports with `--http-port` and `--tunnel-port` if either is in
|
||||
use. The VM must already be running. `up` checks the documented VM/snapshot
|
||||
identity but intentionally does not restore, start, stop, or reset the VM.
|
||||
identity but intentionally does not restore, start, stop, or reset the VM. It
|
||||
starts a small host-side watchdog for the SSH master. The watchdog reconnects
|
||||
after a transient Helium/SSH failure while preserving the same Docker-gateway
|
||||
listener, so an already-open Guacamole session can recover without restarting
|
||||
the containers. Its PID, stop marker, and diagnostic log are kept under the
|
||||
ignored `.runtime/` directory.
|
||||
|
||||
All fixture-specific values have embedded, working defaults: the
|
||||
`helium-remote` SSH alias, Helium's loopback VRDE endpoint (`127.0.0.1:3389`),
|
||||
@@ -66,6 +71,18 @@ port (`54001`). They can be overridden without editing tracked files through
|
||||
Helium loopback (`127.0.0.1` or `localhost`) so an override cannot accidentally
|
||||
turn the diagnostic server into a remote target.
|
||||
|
||||
If `up` is run again while the Compose services are still running, it is
|
||||
idempotent: an existing healthy tunnel is reused, and a missing tunnel is
|
||||
recreated in place. `status` reports a helper-owned tunnel as
|
||||
`private_tunnel=active` and a listener supplied by an external/interactive
|
||||
SSH supervisor as `private_tunnel=active_external`. A missing listener is
|
||||
reported as `private_tunnel=inactive`; inspect `.runtime/tunnel.log` and run
|
||||
`up` again to trigger a bounded reconnect attempt.
|
||||
|
||||
The XML mapping intentionally uses Guacamole's `${GUAC_PASSWORD}` connection
|
||||
parameter token. Guacamole resolves this to the password entered at web login;
|
||||
it is not a host environment variable and must remain in the template.
|
||||
|
||||
After the interactive action, close the browser connection and remove the
|
||||
temporary access path before releasing the fixture lease:
|
||||
|
||||
@@ -74,9 +91,10 @@ test/rdp-access/rdp-access down
|
||||
scripts/windows/test-host reset --run-id interactive-rdp
|
||||
```
|
||||
|
||||
`down` stops containers and the SSH master/tunnel but retains the one-day
|
||||
certificate and password verifier for a quick restart. To remove all generated
|
||||
state, including the certificate and verifier:
|
||||
`down` stops containers and the SSH watchdog/master/tunnel but retains the
|
||||
one-day certificate and password verifier for a quick restart. To remove all
|
||||
generated state, including the certificate, verifier, watchdog PID, and tunnel
|
||||
log:
|
||||
|
||||
```sh
|
||||
test/rdp-access/rdp-access clean
|
||||
@@ -101,14 +119,16 @@ test/rdp-access/rdp-access logs --tail=100
|
||||
test/rdp-access/rdp-access url
|
||||
```
|
||||
|
||||
If the browser reaches Guacamole but stays on “Waiting for response”, verify
|
||||
that the VM is running and the private tunnel is active with `status`. This
|
||||
helper already uses `security=rdp` and disables Guacamole's GFX extension,
|
||||
which are required by the fixture's legacy VRDE server. Do not switch the
|
||||
helper to native Windows RDP: `TermService` is intentionally disabled in the
|
||||
baseline. If VRDE remains unusable, stop this helper and use Guest Control for
|
||||
the deterministic portion of the work; record the blocked interactive step in
|
||||
the native test report.
|
||||
If the browser reaches Guacamole but stays on “Waiting for response”, run
|
||||
`status` first. Confirm `private_tunnel=active` (or
|
||||
`active_external`), then check the VM state and the last lines of
|
||||
`.runtime/tunnel.log`. A tunnel can be recreated without losing the Compose
|
||||
stack by running `up` again. This helper already uses `security=rdp` and
|
||||
disables Guacamole's GFX extension, which are required by the fixture's legacy
|
||||
VRDE server. Do not switch the helper to native Windows RDP:
|
||||
`TermService` is intentionally disabled in the baseline. If VRDE remains
|
||||
unusable, stop this helper and use Guest Control for the deterministic portion
|
||||
of the work; record the blocked interactive step in the native test report.
|
||||
|
||||
The helper requires Docker/Docker Compose, SSH access through the existing
|
||||
`helium-remote` alias, and the fixture password file documented in
|
||||
|
||||
Reference in New Issue
Block a user