X inside VE

From OpenVZ Linux Containers Wiki
Jump to: navigation, search

There are several ways to run X applications inside your container.

X forwarding[edit]

Single application[edit]

To run an X application inside a container, one needs simply to connect to a container with ssh -X:

host# ssh -2 -c blowfish -X user@address

After login to container check that $DISPLAY variable is set and X11 forwarding is enabled:

ve# echo $DISPLAY

In case $DISPLAY is not set, make sure that X forwarding is enabled in sshd config inside container. In most Linux distros sshd configuration is stored in /etc/ssh/sshd_config. You should set parameter X11Forwarding to yes. Also container should contain xauth package, thus install xauth if it is missing (in Debian this is part of the xbase-clients package). After that, restart your sshd daemon:

ve# /etc/init.d/sshd restart
Yellowpin.svg Note: Don't forget to reconnect after this

Now you can run X applications from your container:

ve# firefox


Note : If you want to run complete X window environment (including window manager), you should kill local window manager and run only pure X server. Secondly you should use -Y option when invoking ssh. And if you want to run gnome/kde/..., don't forget to increase UBC limits, 'cause default values are certainly too small for these monsters. ;)

You can run a desktop with xinit (on the node):

xinit -e ssh -XCc blowfish user@ip_address "/usr/bin/xfce4-session &" -- :1 & disown
  • Substitute the window manager of choice
  • Once xfce has started, you can then close the xterm if you like

Your node will be on Ctrl-Alt-F7

And your VM on Ctrl-Alt-F8

VNC for X desktop[edit]

First, one need to run Xvnc server inside container. The easiest way for this is to run vncserver script. This scripts starts all the required services and small http daemon which provides graphical web access to your desktop (via Java applet).

ve# vncserver -name mydesktop
New 'mydekstop' desktop is ve:1

Starting applications specified in ~/.vnc/xstartup
Log file is ~/.vnc/ve:1.log

Now when your desktop is up and running you can connect to it using vncviewer command:

host# vncviewer <container_IP>:1

If the VNC desktop is the same size or larger than your X desktop, you will see scroll bars on the bottom and the side. This is often inconvenient. You may reduce your VNC desktop to a more reasonable size like this:

vncserver -geometry 1000x650

This setting works quite well for a 1024 by 768 X desktop setting.

Starting KDE desktop with VNC[edit]

To start KDE desktop instead of default twm one replace twm & line with startkde & in user's ~/.vnc/xstartup file on the container.

Connecting with VNC from firewalled network[edit]

VNC uses 590x TCP ports for its connections. These ports can be firewalled in many networks so in order to be able to connect to remote side one need to tunnel VNC connections somehow. A usual ssh can be used for tunneling VNC connections as described below.

localhost# ssh -L 5900:localhost:5900 <remote host>

where <remote host> is the name of the system you want to connect to. When you are asked for a username and password enter your normal username and password. Then start the VNC session to localhost, i.e.

localhost# vncviewer localhost

Using Xephyr[edit]

Xephyr gives you nested X windows.

First, install Xephyr on your host.

Start Xephyr

Xephyr -ac -screen 1280x1024 -br -reset -terminate :1 &

Change your display settings (don't forget to change them back after you establish a connection)


Forward your application or desktop over ssh to Xephyr

ssh -XfC -c blowfish user@server xfce4-session

If you use an alternate window manager, substitute "startkde", "gnome-session", "startfluxbox", etc. as needed.


Using XDM with XDMCP[edit]

This method will give you a graphical login prompt remotely similar to VNC, but with some differences. Most notably, XDMCP is faster than VNC (due to the way each deals with screen handling) and but you CANNOT connect to existing sessions like you can with VNC. Each time you logout, your programs are closed. XDMCP is better suited in situations where you don't have a local display (or dumb terminals/clients) but want to run X11 programs

container Configuration[edit]

Install your desktop environment as you'd like (kde/gnome/xfce/etc) and ensure you install at least XDM. You can opt to use GDM/KDM as they also do the same job as XDM. The configuration for KDM/GDM is different than XDM's and I was only able to find one link on configuring GDM (more below).


Configuring XDM requires editing 3 files: /etc/X11/xdm/xdm-config, /etc/X11/xdm/Xservers, /etc/X11/xdm/Xaccess

In xdm-config, comment out the line where it says DisplayManager.requestPort: 0

In Xservers, comment out the line :0 local /usr/bin/X :0 vt7' (this starts a local X server, which will fail)

In Xaccess, uncomment the line with * #any host can get a login window (Please keep in mind the security implications by the above line. Read the comments found in the file and set it appropriately)

To provide the possibility to run sound applications from container, /dev/dsp device file needs to be exported in container:

vzctl set 221 --devnodes dsp:rw --save

Finally, if you intend to make xdm invoking a heavy desktop like kde, it is reasonable to increase the amount of memory available for allocation inside this container:

vzctl set 221 --privvmpages 500M:600M --save

For light desktop like icewm this is not needed.

Once these changes have been made, start your xdm server by the appropriate startup script (typically similar to /etc/init.d/xdm start). That concludes the XDM setup in the container.


Edit the gdm.conf file and in xdmcp section, comment out the 0=standard line under the [servers] section - this will prevent gdm from trying to launch an X server on the local machine - it will simply listen for xdmcp requests. Insert 0=inactive in [servers] section. Insert Enable=1 in [xdmcp] section. Also, change from VCAllocation=true to VTAllocation=false and comment out the FirstVT=7 line if that lines exists. Change the access restrictions (if any) to suit your needs and then start GDM.

Client/Host Configuration[edit]

On the Client/Host (whatever machine you are connecting from to the container), you need to install ONLY a bare Xserver as per your OS instructions (use yum, emerge, apt, whatever). A desktop environment like XFCE/GNOME/KDE is entirely optional on the client, but keep in mind that it won't be used while you're connecting to the desktop on the container.

To get access to the XDM server, just start an Xserver with X -query <remote IP> :0 (where :0 is the local display...set to :1 if you already have an X session running, or use Xnest)

There are guides online on howto securely tunnel XDMCP over the Internet (typically vpn as XDMCP can't be tunneled over ssh afaik), in an otherwise INSECURE protocol.


On a side note, as of December 2007, I was never able to successfully get an Xserver to run inside a container and have the display output onto virtual-terminal 7 (the Xserver default), However, you can get an Xserver running on the hostnode to display output on virtual-terminal 7 without any special configuration (as the hostnode has direct access to all necessary devices).

Another user has done this with XDM and X. Just follow the directions on the wiki. It is possible.

See also[edit]

External links[edit]