vmlab-web

tool

The web UI server: an Actix-web binary exposing vmlab over REST + WebSockets and serving the embedded console UI, with username/password auth.

vmlab-web serves the web console and its REST + WebSocket API. It talks to the same supervisor and lab daemons the CLI does, over the existing unix-socket protocol — no daemon changes, no extra privileges. The official container image runs it as the default command; on a host it is just a second binary next to vmlab (built with the optional web cargo feature).

console
vmlab-web                                   # local-only: http://127.0.0.1:7878, no login
vmlab-web --bind 0.0.0.0 \
  --user admin --password-hash '$argon2id$…'   # exposed: login required
FlagEnv fallbackMeaning
--bind <ip>Address to bind (default 127.0.0.1; non-loopback implies --auth)
--port <n>TCP port (default 7878)
--authRequire login (auto-enabled for non-loopback binds); errors without credentials
--no-authExplicitly allow a non-loopback bind with no login (ignored once credentials are set)
--user <name>VMLAB_WEB_USERLogin username
--password <pw>VMLAB_WEB_PASSWORDLogin password, hashed once at startup (prefer a hash)
--password-hash <phc>VMLAB_WEB_PASSWORD_HASHPre-computed argon2 PHC hash — wins over --password
--upVMLAB_WEB_UPBring the working-directory lab up in the background on startup
--trust-proxyVMLAB_WEB_TRUST_PROXYBehind a reverse proxy: rate-limit logins by the proxy-appended X-Forwarded-For entry
VMLAB_WEB_SESSION_TTL_SECSIdle session lifetime (default 12 hours)

Secure default: a username plus a password/hash enables auth regardless of other flags; with no credentials, running open is allowed only on a loopback bind or with an explicit --no-auth opt-in — a bare non-loopback bind is refused at startup. Sessions ride an Authorization: Bearer token issued by POST /api/login; the auth gate covers everything under /api/ (the guest web-page proxy under /web/ uses its own path-scoped cookie — see the web {} block). The server also embeds this reference book at /help, which the console's Help button opens as an in-app tab.