A browser dashboard for kvmrun. It visualizes and manages virtual machines through the kvmrund gRPC API, exposing the same information and controls as the vmm CLI.
- Live data from the
kvmrunddaemon, with no local database - Go + Gin backend with server-rendered pages and a small JSON API
- gRPC clients generated from the
kvmrunmodule, using go-grpc request-ID and request-logging interceptors - PAM authentication through the host PAM stack, with in-memory cookie sessions
- Machine list and detail pages, VM power controls, VNC and SSH consoles, task and daemon configuration information
- Embedded CSS and JS assets via
go:embed, producing a single self-contained binary
The dashboard communicates directly with kvmrund using gRPC clients generated from the kvmrun module. It uses go-grpc for request-ID and request-logging interceptors. Static frontend assets are embedded with go:embed, so the result is a single binary.
- Go 1.25 or later
- Linux with
libpamand a C toolchain, because PAM authentication is implemented with cgo - A running
kvmrunddaemon, reachable over the configured Unix socket or TCP address - Optional: kvmrun TLS client certificates (
client.crtandclient.key) in the--cert-dirdirectory
make build
./bin/dashboard --listen :8080You can also use:
make run
make test
make vet| Flag | Default | Description |
|---|---|---|
--listen |
:8080 |
HTTP server address |
--daemon |
unix:@/run/kvmrund.sock |
kvmrund daemon address (host:port or Unix/abstract socket) |
--cert-dir |
/usr/share/kvmrun/tls |
Directory containing client.crt and client.key |
--pam-service |
login |
PAM service used to verify passwords (/etc/pam.d/<name>) |
--session-ttl |
12h |
Session lifetime |
--cookie-name |
kvmrun-dashboard-session |
Session cookie name |
--debug |
false |
Enable debug logging; can also be set with KVMRUND_DEBUG or DEBUG |
The dashboard uses the same default daemon connection as the vmm CLI. If no certificates are present in --cert-dir, it connects without TLS, matching vmm behavior.
GET/POST /loginrenders a login form; passwords are verified with the host PAM stack using--pam-service.- Successful login sets an
HttpOnlycookie containing a 32-byte random session ID. - Sessions are stored in memory, live for
--session-ttl, and are removed on restart. - All routes except
/login,/logout,/static/*, and/healthzrequire a session. Browsers are redirected to/login; JSON API requests receive401.