raft / docs
Guides

Desktop and private services

Forward network ports and connect to an on-demand graphical desktop over authenticated host SSH tunnels bound to controller loopback.

Target workspace handle

Commands in this guide target a running workspace. Select one from raft list (see First working box):

CONTROLLER: Select running workspace
raft list
box="lab:rf-a1b2c3d4e5f60718"  # Replace with your actual workspace handle

Forwarding network ports

Create a secure tunnel between your local controller and a workspace service:

raft forward "$box" --remote <REMOTE_PORT> --local <LOCAL_PORT>

End-to-end example: Running a web service

Start a detached HTTP server inside the workspace:

CONTROLLER: Start detached HTTP server inside workspace
job=$(raft exec "$box" --detach -- python3 -m http.server 8080 --bind 0.0.0.0)
echo "Started web service job: $job"

Open the forwarding tunnel:

CONTROLLER: Open port forwarding tunnel
raft forward "$box" --remote 8080 --local 8080

raft forward runs in the foreground. Open http://127.0.0.1:8080 in your browser or run curl http://127.0.0.1:8080 in another terminal.

When finished:

  1. Press Ctrl+C to close the tunnel.
  2. Cancel the background job:
    CONTROLLER: Stop the background server job
    raft cancel "$box" "$job"

Binding requirement

Bind to all interfaces or guest IP

Services inside the container must bind to all interfaces (0.0.0.0) or to the container's private eth0 IP address. A service listening strictly on container loopback (127.0.0.1) cannot receive traffic routed across the container bridge.

The controller listener binds strictly to 127.0.0.1 on your local workstation, without exposing ports to your local network.

On-demand desktop environment

The development image includes a graphical desktop stack using Xvfb (display :99), Openbox, x11vnc, and noVNC.

Start the desktop and establish a private tunnel:

CONTROLLER: Launch desktop and establish private tunnel
raft desktop "$box" --local 6080

raft desktop starts raft-desktop.service inside the container if needed, waits for Xvfb and VNC readiness, and opens a tunnel to local port 6080.

Open the client in your browser:

http://127.0.0.1:6080/vnc.html

Browser URL requirement

Include /vnc.html in the URL. The root path / displays an index directory; /vnc.html loads the desktop canvas with mouse, keyboard, and clipboard support.

Desktop characteristics

  • Display environment: Virtual X display :99 at 1280x720 resolution with 24-bit color.
  • User session: Openbox runs under the developer user account.
  • Clipboard support: The noVNC sidebar provides a clipboard drawer for text exchange.
  • Tunnel lifecycle: Pressing Ctrl+C closes the local tunnel. The desktop service keeps running until the workspace stops or expires.
  • Reconnecting: Running raft desktop "$box" --local 6080 reconnects without interrupting open windows.

On this page