-
Notifications
You must be signed in to change notification settings - Fork 0
Manual Install
For your safety you can also find the packages on pip or pipx and the requirement.txt file.
apt-get update -y -qq
apt-get install git lxc lxcfs lxc-templates qemu qemu-utils qemu-kvm virtinst bridge-utils virt-manager libvirt-daemon libvirt-daemon-system virt-viewer libvirt-clients libosinfo-bin websockify sqlite3 novnc ovmf swtpm swtpm-tools -y
apt-get install python3 python3-flask python3-flask-login python3-flask-sqlalchemy python3-requests python3-lxc python3-libvirt python3-psutil python3-werkzeug python3-websockify python3-novnc python3-flask-socketio python3-openssl
apt-get install openvswitch-switch openvswitch-common
git clone https://github.com/pyhype2/Hype2.git
cd Hype2systemctl --quiet enable --now libvirtd
systemctl --quiet start libvirtdThis bridge will allow you to connect your Virtual Servers and Containers to your local network in order to access them easily.
cp ./bridged.xml /usr/share/libvirt/networks/
virsh net-define bridged.xml
virsh net-start bridged
virsh net-autostart bridgedOn your host, create the bridge interface "br0", according to your network with :
- int The physical interface (example : enp1s0)
- ip your fixed IP
- netmask your netmask (example: 255.255.255.0)
- gateway your gateway
auto br0
iface br0 inet static
bridge_ports <int>
bridge_fd 0
bridge_maxwait 0
address <ip>
netmask <netmask>
gateway <gateway>You will have to uncomment these lines :
vnc_listen = "0.0.0.0"
user=root
group=rootThis will ajust rights for Qemu to run as root and enable VNC on all address for the console.
A default Database is provided in the git (install/db.db.admin_example), the default user is admin@admin.com / admin. To use this database, just change the name from db.db.admin_example to db.db
Once connected, you will be able to create/manage users directly on software.
cp db.db.admin_example db.dbFor security reason, you should remove db.db.admin_example
If you want to create this database by yourself, you can :
sqlite3 db.db
CREATE TABLE user (id INTEGER PRIMARY KEY AUTOINCREMENT, username NVARCHAR(200) NULL, email NVARCHAR(200) NULL, password NVARCHAR(200) NULL);python3
import app
app.encrypt('Password')
sqlite3 db.db
INSERT INTO user (id,username,email,password) VALUES (1,'<you_username>','<your_email>','<your_previous_encrypted_password');In order to access to the consoles which are running websockets on other ports (6080 vor VNC and 5008 for Pyxterm), a Reverse proxy is needed.
Whitout this, you can still access to consoles using CLI for Serial access :
lxc-attach <container>and using a tool such as :
https://www.realvnc.com/en/connect/download/viewer/
For VNC access (on port 6080).
To set your Reverse proxy, you can use the examples bellow (adapt to your case of course).
Example for nginx:
server {
listen 443 ssl;
server_name www.example.com;
ssl_certificate /path/to/your/cert.pem;
ssl_certificate_key /path/to/your/privkey.pem;
ssl_verify_client off;
ssl_protocols TLSv1.2 TLSv1.3;
ssl_ciphers 'TLS_AES_128_GCM_SHA256:TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES256-GCM-SHA384';
proxy_read_timeout 20m;
proxy_connect_timeout 20m;
proxy_send_timeout 20m;
client_max_body_size 10G;
location /websockify {
proxy_pass http://<your_ip>:6080/websockify;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
location /socket.io {
proxy_pass http://<your_ip>:5008/socket.io;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
location / {
proxy_pass https://<your_ip>:5007/;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
}Example for apache2 configuration :
<VirtualHost *:443>
ServerName www.example.com
RewriteEngine on
SSLEngine On
SSLCertificateFile /path/to/your/cert.pem
SSLCertificateKeyFile /path/to/your/privkey.pem
SSLProxyVerify none
SSLProxyCheckPeerCN off
SSLProxyEngine On
SSLProxyCheckPeerExpire off
ProxyRequests Off
ProxyPreserveHost On
RequestHeader set X-Forwarded-Proto "https"
ProxyPass /websockify ws://<your_ip>:6080/websockify retry=3
ProxyPassReverse /websockify ws://<your_ip>:6080/websockify retry=3
ProxyPass /socket.io ws://<your_ip>:5008/socket.io retry=3
ProxyPassReverse /socket.io ws://<your_ip>:5008/socket.io retry=3
ProxyPass / https://<your_ip>:5007/
ProxyPassReverse / https://<your_ip>:5007/
</VirtualHost>NB: you can set the server_name to
server_name _;
This will allow to catch all traffic without filtering source.