11 ms·
Running GUI apps within Docker containers
- jandeboevrie 5y agoThis is fun, I did it as well to get an old flash player from 2011 working in modern Linux: https://raymii.org/s/tutorials/Running_gnash_on_Ubuntu_20.04.html https://raymii.org/s/tutorials/Running_gnash_on_Ubuntu_20.04...
- zubnix 5y agoanother solution that allows both wayland and x11 applications accessible from the browser (disclaimer: I am the author, it’s also still very much under development) https://github.com/udevbe/greenfield https://github.com/udevbe/greenfield
- modinfo 5y agoAnd how to launch GUI app from docker via ssh?
- jbverschoor 5y agoRun X and set the display host?
- ttyprintk 5y agossh -X will do, but in this thread is a project using Xpra. Assuming your docker is remote, that’s probably better. https://www.xpra.org/ https://www.xpra.org/
- adhesive_wombat 5y ago> This is beneficial for things like social media management, growth hacking (either via social media automation or manual labour done by VAs) or OSINT investigations. Ugh, sounds like the software equivalent of using a huge stack of ingenious hardware to just do something parasitic like high-frequency trading.
- pronoiac 5y agoOh hey, I just automated this a bit to run the Linux version of Scantailor Advanced on a Mac. I contributed it back upstream. It's not too complicated, but it took a while to get it working. https://github.com/ryanfb/docker_scantailor https://github.com/ryanfb/docker_scantailor Edit: this method uses xquartz on the Mac side, and socat to bridge between a network port and a file socket.
- mg 5y agoYou can also do it with this one-liner: docker run -it --rm -e DISPLAY --net=host -v $XAUTHORITY:/root/.Xauthority -v /tmp/.X11-unix:/tmp/.X11-unix debian:11-slim Then inside the container, run: apt update apt install firefox-esr firefox Now Firefox runs inside the container but displays on your hosts screen and you can use it right away.
- bheadmaster 5y agoThanks, this is much simpler than the original post. Here's the equivalent Dockerfile + docker-compose.yaml for convenience: # Dockerfile FROM debian:11-slim RUN apt-get -y update && apt-get -y install firefox-esr CMD ["firefox"] # docker-compose.yaml services: firefox: image: firefox build: . environment: DISPLAY: ${DISPLAY} network_mode: host volumes: - ${XAUTHORITY}:/root/.Xauthority - /tmp/.X11-unix:/tmp.X11-unix This way you can run it with just: docker-compose up
- moody5bundle 5y agoif you want to remove network_mode=host you need to run firefox with the --no-xshm flag
- ThePhysicist 5y agoYes, I think few people seem to realize X Windows can be operated over a network as well. I used to do that with the Windows Subsystem for Linux to use the KDE Konsole and other great tools on my Windows machine using an X server running on the Windows side and a few environment variable tweaks on the Linux side. My colleagues were always confused when they saw the Linux UI seamlessly mixed with the Windows stuff on my display. For the use case mentioned in the article xvfb probably makes more sense though as that stuff often runs on a server and you don't want to stream the output somewhere to work with it interactively.
- zozbot234 5y agoThis is not running X on any network, just sharing access to the resources that the containerized app needs to find the X server on the same host. There's probably an equivalent incantation for Wayland, too.
- 999900000999 5y agoI know this isn't the focus of the article, but this license provision in a linked project is outright strange. >By using this software you agree that the following non-PII (non personally identifiable information) data will be collected, processed and used by the maintainers for the purpose of improving the docker-android project. Anonymisation with respect of the IP address means that only the first two octets of the IP address are collected. https://github.com/budtmo/docker-android/blob/master/LICENSE.md https://github.com/budtmo/docker-android/blob/master/LICENSE... How can you call a project Apache when you're forcing people to pay via their data ? Why is their no opt out option? Absent that this seems like a great QA automation tool. Or a Tinder bot farm...
- arghwhat 5y agoWhile nasty, the Apache license does not concern itself with what an application does, only how it is distributed.
- detaro 5y agoThe especially weird thing is putting something like that in the license.
- detaro 5y agoAccording to the documentation about analytics, there is an opt-out.
- 999900000999 5y agoWhere exactly, I'd expect them to both mention the analytics and the opt out option in the readme. Just rubs me the wrong way, you can easily use this without knowing it phones home
- metadat 5y agoSadly, today this is more common than not, even with OSS. Even Elasticsearch has been doing collecting and transmitting their telemetry shit for many years now (since well before Kimchi decided to change the license from OSS-friendly to a hostile one).
- mellosouls 5y agoIs Sandboxie still around? It used to do that (containerised GUI apps) pre-Docker on Windows very effectively. Ah (edit), there it is: https://github.com/sandboxie-plus/Sandboxie https://github.com/sandboxie-plus/Sandboxie
- varbhat 5y agoDistrobox let's you do the same(using docker or podman) imo and is pretty good. https://github.com/89luca89/distrobox https://github.com/89luca89/distrobox
- AnIdiotOnTheNet 5y agoDistrobox (or Toolbox) is a nice tool[0], but honestly the reliance on Podman doesn't make a lot of sense to me. The necessary container functionality is available directly from the kernel[1] with little of the complication that Podman brings along, and from what I can tell[1] it is pretty straight-forward to pull docker and OCI images with simple HTTP interaction (or wget/curl) and extract with tar. This could be a stand-alone statically compiled executable with no dependencies that could work on any Linux distribution with no hassle at all, but isn't for some reason[2]. [0] I was exposed to it via Fedora Silverblue, where something like it is a necessity since the base OS is immutable. I've found it very useful even outside that use case however. [1] Seems to me you could even use bwrap if you were reluctant to use syscalls directly. [2] having done a little research towards creating my own tool because I'd rather not depend on a package that isn't available in many LTS distros, among other reasons.
- eurasiantiger 5y agoThe author seems to focus on something called ”growth hacking”, which seems to boil down to social media fraud akin to the cyberwarfare psyops various nation-states have been doing. Fast capitalism, to me, seems to be an ideology entirely centered on an authoritarian we-versus-them mindset where profit is king, civilian collateral be damned.
- ttyprintk 5y agoWell, growth hacking is a buzzword for a marketing position in a company encountering the steep part of the curve. I suppose one of the innovations is that a widget becomes more attractive to a segment of the population when you bolt on some social functionality, what you’re seeing. At the top of growth is incumbency. I think that’s where your second paragraph comes in. Incumbents surveil innovations, and “growth hackers” don’t like to talk about this obvious conclusion. They’d rather inhabit a role that concludes once growth has succeeded and slowed. This is no more revolutionary than traditional marketing. Marxism talks about capitalist marketing as a way to channel alienation among working classes away from collective organization. But, Marx from the beginning needed to market his ideas to different groups. He needed those groups to realize that they needed his political orientation. He tries to do this with abstractions, and explicitly gives up on whole classes he deems unfit to understand those ideas (the lumpenproletariat). As the product of a growth hacker reaches incumbency, marketing gives way to public relations. We might consider Cambridge Analytica public relations hackers. Same level of statistical sophistication, same single-focus of corporate promotion over all other advancements.
- RVuRnvbM2e 5y agoThis is what Flatpak (https://flatpak.org/ https://flatpak.org/) is designed for.. why would you use docker?
- sascha_sl 5y agoBecause Flatpak imposes some design choices that are... less than optimal for porting existing applications, and if you ask them to change maintainers will insist this is the way to go. They have told users that if they want, for instance, Jetbrains IDEs to work, they should simply get a Job at Jetbrains and convince them to rewrite their entire IDE to support the flatpak model.[1] This is the reason I avoid distros with Flathub enabled by default. Half the software on there is broken in some pretty subtantial way, and nobody at Flatpak or Flathub cares. They really need to realize they're not Apple, they simply can't tell everyone to do things their way and hope to build a working and reliable ecosystem. They have the equivalent to snap's classic confinement, but it needs to be explicitly enabled every time you launch an app. [1]: https://github.com/flathub/com.jetbrains.IntelliJ-IDEA-Community/issues/14#issuecomment-488178015 https://github.com/flathub/com.jetbrains.IntelliJ-IDEA-Commu...
- AnIdiotOnTheNet 5y agoSeems like just allowing the user to specify 'unconfined' as an override. Then the user would just need to do that with flatseal. Alternatively, and with much more needless complication, some kind of fuse-mounted /bin directory that acts as a portal could be used. Point is there are solutions that don't require huge perversions of the Flatpak model and also don't require Jetbrains to rewrite everything. Personally I like that the Linux Desktop community is finally starting to wake up to the idea of universal application distribution that doesn't require armies of unpaid third party maintainers, and while Flatpak is definitely not perfect it is, in my opinion, a huge step forward in that regard[0]. [0] Not that the idea is really that new, there have been many attempts at bringing sanity to Linux application distribution, many of them better (IMO), but they've just never really been embraced by the community the way Flatpak has.
- 5y ago
- moody5bundle 5y agoI am actually running a few of my daily applications, such as firefox, vscode, or spotify inside a podman container (rootless makes me feel a little safer). I build a small python script around it, which creates a desktop icon, tags the current version (so you can rollback), and updates the images after x amount of time. I'll clean it up and put it on github if someone is interested :)
- ntietz 5y agoPlease do share! I would be interested in seeing it and doing something similar (and use podman for the same reason).
- moody5bundle 5y agoI will! cleaning up now and going to publish it later on github. The main idea was a least privilege approach to running simple desktop applications independent from the host OS and being able to control filesystem/network access on a per app basis. (spotify on fedora without flatpak or rpm-fusion repo's, not even sudo needed to install)
- zozbot234 5y agoNo real need for full Flatpak, Bubblewrap (bwrap) is intended to be a lightweight sandbox providing this out of the box, with Flatpak (and other stuff besides) building upon it. The Arch wiki has a nice introductory page: https://wiki.archlinux.org/title/Bubblewrap https://wiki.archlinux.org/title/Bubblewrap
- moody5bundle 5y agoOh didn't know about bwrap yet! If i understand the wiki page correctly, you still need to get those binaries to your pc. So thats why i went with plain and simple dockerfiles.
- Proven 5y ago
- galoisscobi 5y agoReading this makes me want to revisit running i3wm in a docker container on macOS. After having tried Amethyst (current daily driver), yabai, and hammerspoon, nothing comes close to i3wm, in my experience.
- adamnew123456 5y agoI looked into the equivalent setup for WSL a while ago. The thing I could never solve was: how to manage the hosts windows via the virtual environment's WM? Without the integration that setup is just extra config for no gain. Because if most tools belong to the VM, then just run a VM in full screen and use that. No need to have the display server shared if you're using mostly Linux tools that display on the VM's X server.
- galoisscobi 5y agoThat’s a good point. I’ll try out the VM route and see how that goes. I mainly just want to tile the web browser, some docs, a terminal emulator and vim/IDE and be able to switch between layouts and apps seamlessly and VM does seem like a good option. Kinda sad that macOS WM is a joke to do all this compared to some of the TWMs out there.
- adamgordonbell 5y agoOf course you can also play DOOM in docker: https://earthly.dev/blog/dos-gaming-in-docker/ https://earthly.dev/blog/dos-gaming-in-docker/
- phil294 5y agoI cannot recommend the mentioned x11docker cmd line tool enough for this. It takes care of all possible edge cases, supports different outlets (like nxagent or xephyr), focuses on security and exposes an easy interface. I'm using it for day to day work with VSCode, for example, to fix its atrocious security model, or more recently, to try out JPEXS (Java), IDA (wine) and AHK (wine). I specially like that this leaves no config or cache files left behind. The article says you need a compatible image for that, but in my experience, everything launches just fine.
- stickac 5y agoExactly that https://subuser.org https://subuser.org does
- ttyprintk 5y agoLooks like its the only solution in this thread leveraging Xpra. https://www.xpra.org/ https://www.xpra.org/
- madduci 5y agoI'm doing this since quite a while and I am happy with this approach, especially with applications that tend to pollute my machine in every folder possible, like IntelliJ: https://github.com/madduci/docker-intellij https://github.com/madduci/docker-intellij
- janjones 5y agoThis is also supported directly in VSCode Dev Containers by using just a feature switch[1] [1] https://github.com/microsoft/vscode-dev-containers/blob/main/script-library/docs/desktop-lite.md https://github.com/microsoft/vscode-dev-containers/blob/main...
- corobo 5y agoAdditional reading on this topic if you fancy it. This is the first one I read regarding docker for GUI apps https://blog.jessfraz.com/post/docker-containers-on-the-desktop/ https://blog.jessfraz.com/post/docker-containers-on-the-desk...
- Legogris 5y agojessfraz maintains quite a collection of Dockerfiles you can borrow: https://github.com/jessfraz/dockerfiles https://github.com/jessfraz/dockerfiles
- TacticalCoder 5y agoOne advantage one running GUI apps within a Docker container is that it is, in my experience, totally trivial to put RAM/CPU quotas on piggy apps. Sure, you may put quotas using other means but it can get tricky (if I'm not mistaken it's particularly tricky on processes forking themselves like there's no tomorrow). Using a Docker container, which you may already have anyway, putting CPU/RAM quotas is a one-liner.
- amelius 5y agoCan you also add bandwidth quotas?
- TacticalCoder 5y agoThat's a good question, I never tried so I don't know either.
- akvadrako 5y agoIf that's all you want it's easier to use systemd-run and start your process as a service. I do this to put many of my resource hungry apps like FF in slices.
- g8oz 5y ago>>"This would provide a degree of protection against social media platform cracking down on sock puppet accounts being used from single setup because traffic is kept separate for each account and cookie cross-contamination is being prevented." This can also be accomplised by using Firefox's Multi-Account Container extension in conjunction with the Container Proxy extension. The Multi-Account Container extension is also great for non-dirtbag purposes. For instance testing different user profiles in an application - create 1 container for User, 1 for Admin etc.
- mirekrusin 5y agoNice article. ps. you know, for some people it's very hard to read bright text on black background. Especially if you're flipping from opposite contrast.
- LoveGracePeace 5y agoAgreed, I bring this up all the time, FYI it's about 40% of the population according to several decades of research.
- Klasiaster 5y agoFor getting a proper Wayland session I recommend doing this with Phosh and wayvnc (WLR_BACKENDS=headless WLR_LIBINPUT_NO_DEVICES=1 as env vars for starting Phosh and then "wayvnc 0.0.0.0 7050"). You can even have a whole systemd setup in a container using this VNC backend, here in this Dockerfile with CPU rendering (LIBGL_ALWAYS_SOFTWARE=1) to avoid requring a GPU: FROM docker.io/fedora RUN dnf -y update && dnf install -y phosh phoc wayvnc sudo socat iproute mutter xorg-x11-server-Xwayland dbus-x11 mesa-libgbm mesa-libOpenCL mesa-libGL mesa-libGLU mesa-libEGL mesa-vulkan-drivers mesa-libOSMesa mesa-dri-drivers mesa-filesystem gnome-shell gnome-terminal RUN mkdir -p /etc/systemd/system/phosh.service.d && echo -e '\ [Unit]\n\ ConditionPathExists=\n\ [Service]\n\ Environment=WLR_BACKENDS=headless\n\ Environment=WLR_LIBINPUT_NO_DEVICES=1\n\ StandardInput=null\n\ TTYPath=/dev/console\n\ TTYReset=no\n\ TTYVHangup=no\n\ TTYVTDisallocate=no\n\ ExecStart=\n\ ExecStart=/usr/bin/phoc --exec "bash -lc \"/usr/libexec/phosh --unlocked & wayvnc 0.0.0.0 7050\""\n\ ' > /etc/systemd/system/phosh.service.d/10-headless.conf RUN systemctl enable phosh.service # Work around a problem with a missing dbus.service unit file RUN mkdir -p /etc/systemd/system && ln -fs /usr/lib/systemd/system/dbus-broker.service /etc/systemd/system/dbus.service # Mask udev instead of making /sys/ read-only as suggested in https://systemd.io/CONTAINER_INTERFACE/ RUN systemctl mask systemd-udevd.service systemd-modules-load.service systemd-udevd-control.socket systemd-udevd-kernel.socket ENV container=docker RUN groupadd --system sudo RUN useradd --create-home --shell /bin/bash -G sudo user RUN echo '%sudo ALL=(ALL) NOPASSWD:ALL' >> /etc/sudoers ENV LIBGL_ALWAYS_SOFTWARE=1 RUN sudo -u user gsettings set sm.puri.phoc auto-maximize false EXPOSE 7050 # Set up a /dev/console link to have the same behavior with or without "-it", needs podman run --systemd=always CMD [ "/bin/sh", "-c", "if ! [ -e /dev/console ] ; then socat -u pty,link=/dev/console stdout & fi ; exec /sbin/init" ] Use as: podman run --systemd=always --rm -p 7050:7050 imagename
- qbasic_forever 5y agoVery cool! systemd is so underrated and underappreciated in the container world.
- timmattison 5y agoI love the idea of this. I’ve struggled to get a setup like this to work on MacOS though. Which X server is the “right” one to use? Which is the easiest? Is there some way to make it work seamlessly with built in tools? As an aside, instead of talking about growth hacking, and OSINT I think this whole thing could be a lot more relatable if the author chose a simple motivation like privacy. Another comment here mentioned subtools (?) which clearly highlights that not everything should be trusted with full access to your system.
- hoherd 5y agoIt sounds like you missed the x11vnc part of this. You connect into the container using vnc, not x11, and potentially via a browser based vnc client. If you want to see a working example of a gui app running successfully in docker, check out https://github.com/jlesage/docker-handbrake https://github.com/jlesage/docker-handbrake
- FPGAhacker 5y agothe vnc solution was one of several presented in the article. The second was using the host x11 server by sharing the socket.
- FPGAhacker 5y agoI've used xquartz for this on macOS in the past.
- jcastro 5y agoDistrobox is handy for this: https://github.com/89luca89/distrobox https://github.com/89luca89/distrobox It just lets you reuse any docker image on your desktop (both podman and docker), and has some nice features like the ability to create a launcher shortcut on the host and transparently mapping your home directory. I switched to it full time, all my CLI work is just done in a container, and it's pretty transparent.
- melony 5y agoWhat about in Wayland environments?
- heavyset_go 5y agoI've successfully used systemd-nspawn with my native Wayland session and nested Wayland sessions.
- pvtmert 5y agofor macOS, you can use -e DISPLAY=host.docker.internal:0 if docker version is >20.10.x also works with Linux
- rovr138 5y agoI use some projects that use vnc and also have setup novnc on them.. Here’s an example of one, https://github.com/accetto/ubuntu-vnc-xfce-g3 https://github.com/accetto/ubuntu-vnc-xfce-g3 Novnc just allows accessing things via a browser too. I use it for quick checks but VNC when I want a client
- throwaway69123 5y agoAnyway to do this on windows?
- naikrovek 5y agoSandboxie
- heavyset_go 5y agoTruthfully, I think systemd-nspawn and Firejail are better solutions than Docker for GUI apps and desktop use.