feat: self-hosted remote support over VNC
Browser-based remote control (noVNC) with invite links, per-user access control, garagedoor SSO and a persisted client list. The hub proxies RFB rather than pointing the browser at a VNC server. That is what lets it authenticate upstream with a stored password the browser never sees, and enforce view-only by dropping input messages on the client->server stream instead of hiding buttons. Machines are reachable two ways: direct TCP for LAN hosts, or an outbound agent tunnel for anything behind NAT. Node 22's global WebSocket keeps the agent dependency-free, and node:sqlite keeps the image free of native builds. Ships with an end-to-end suite that boots the real server against a fake VNC server and a fake auth service (72 assertions), plus Gitea Actions CI/CD to Portainer. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
+25
@@ -0,0 +1,25 @@
|
||||
FROM node:22-alpine
|
||||
|
||||
# node:sqlite is built into Node 22, so there are no native modules to compile
|
||||
# and no build stage to carry around.
|
||||
ENV NODE_ENV=production \
|
||||
PORT=8080 \
|
||||
DB_PATH=/data/rcs.db
|
||||
|
||||
WORKDIR /app
|
||||
|
||||
RUN corepack enable
|
||||
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml* ./
|
||||
RUN pnpm install --prod --frozen-lockfile
|
||||
|
||||
COPY server ./server
|
||||
COPY public ./public
|
||||
COPY agent ./agent
|
||||
|
||||
VOLUME ["/data"]
|
||||
EXPOSE 8080
|
||||
|
||||
HEALTHCHECK --interval=30s --timeout=5s --start-period=10s \
|
||||
CMD wget -qO- http://127.0.0.1:8080/api/health || exit 1
|
||||
|
||||
CMD ["node", "server/index.js"]
|
||||
Reference in New Issue
Block a user