This commit is contained in:
Maxim Devaev
2026-07-04 08:51:33 +03:00
parent 6a6f02aa74
commit 5a8468d3ed
6 changed files with 30 additions and 19 deletions
+11 -5
View File
@@ -68,15 +68,21 @@ Docker must work in privileged mode.
TIMEZONE = Europe/Nicosia
# For SSH root user
ROOT_PASSWD = rootpass
ROOT_PASSWD = change_me
# Web UI credentials: user=admin, password=adminpass
WEBUI_ADMIN_PASSWD = adminpass
# Web UI credentials: user=admin, password=admin_change_me
WEBUI_ADMIN_PASSWD = admin_change_me
# IPMI credentials: user=admin, password=adminpass
IPMI_ADMIN_PASSWD = adminpass
# IPMI credentials: password=ipmi_change_me
IPMI_ADMIN_PASSWD = ipmi_change_me
```
!!! warning
Due to the [legacy of the IPMI protocol](ipmi.md), passwords for it are stored as plain text in `/etc/kvmd/ipmipasswd`.
Do not use passwords for IPMI that you use somewhere else.
4. Build the OS. It may take about one hour depending on the Internet connection:
```console
-6
View File
@@ -370,12 +370,6 @@ kvmd
```sudoers
kvmd ALL=(ALL) NOPASSWD: /usr/bin/reboot
```
NON Granular example (Captures ALL commands)
```sudoers
kvmd ALL=(ALL) NOPASSWD: ALL
```
Example of the `/etc/kvmd/override.yaml`:
+1 -1
View File
@@ -29,7 +29,7 @@ It can be useful for managing a large number of machines with PiKVM. Its advanta
[root@pikvm ~]# rw
```
2. Set up IPMI account in file `/etc/kvmd/ipmipasswd` (see the comment inside it).
2. Set up IPMI account in file `/etc/kvmd/ipmipasswd` (see the comment inside it). Passwords are stored as plain text due to the IPMI legacy. Do not use passwords for IPMI that you use somewhere else.
3. Enable the `kvmd-ipmi` daemon:
+5 -5
View File
@@ -205,8 +205,8 @@ These instructions are for how to install and use the **`acme-dns-client`** with
### Assumptions
- ACME DNS is already set up and functioning in the environment
- ACME DNS Server is **`auth.example.org`**
- PiKVM Fully Qualified Domain Name (FQDN) is **`pikvm.example.org`**
- ACME DNS Server is **`auth.example.com`**
- PiKVM Fully Qualified Domain Name (FQDN) is **`pikvm.example.com`**
- PiKVM is running on a supported Raspberry Pi using the [PiKVM OS](https://github.com/pikvm/os) (which is 32-bit as of the writing of this documentation)
- All configuration examples below are as user **`root`** via a terminal session to PiKVM
@@ -251,7 +251,7 @@ These instructions are for how to install and use the **`acme-dns-client`** with
This is interactive, follow instructions for creating and verifying the appropriate `CNAME` record.
```
# acme-dns-client register -d pikvm.example.org -s http://auth.example.org
# acme-dns-client register -d pikvm.example.com -s https://auth.example.com
```
Once registration is complete ownership of `clientstorage.json` must be changed to `kvmd-certbot`.
@@ -272,11 +272,11 @@ These instructions are for how to install and use the **`acme-dns-client`** with
6. Request Certificate via Certbot
```
# kvmd-certbot certonly --manual --preferred-challenges dns --manual-auth-hook 'acme-dns-client' -d pikvm.example.org
# kvmd-certbot certonly --manual --preferred-challenges dns --manual-auth-hook 'acme-dns-client' -d pikvm.example.com
```
!!! note
If using an ACME compatible Certificate Authority (other than Let's Encrypt) do not forget to add `--server https://ca.example.org/acme/acme/directory` to `kvmd-certbot`
If using an ACME compatible Certificate Authority (other than Let's Encrypt) do not forget to add `--server https://ca.example.com/acme/acme/directory` to `kvmd-certbot`
7. Follow steps 3 through 5 under [Basic Setup](https://docs.pikvm.org/letsencrypt/#basic-setup) to complete setup and renewal of certificates
+9 -2
View File
@@ -232,11 +232,18 @@ linux kernel will default to 'root' ownership of the mountpoint. This means the
volume will be visible in the 'Media' menu, but will be marked as `[read-only]`, without
any obvious reason.
First, you need to find out UID of the `kvmd` user:
```console
[root@pikvm ~]# id kvmd
uid=966(kvmd) ...
```
The correct `/etc/fstab` entry for a USB drive that presents as `/dev/sda1` with an
exfat filesystem is:
exfat filesystem is (use your actual UID of `kvmd`):
```fstab
/dev/sda1 /var/lib/kvmd/msd/usb exfat auto,nofail,rw,umask=0000 0 0
/dev/sda1 /var/lib/kvmd/msd/usb exfat auto,nofail,rw,umask=0133,uid=966 0 0
```
This says to mount it automatically, do not fail if it's missing, mount it read/write by
default, and allow all users and groups access to it.
+4
View File
@@ -52,6 +52,10 @@ HTTPS for them.
* Disabling HTTPS. All requests will be handled via HTTP port `80`.
Please note that this disables encryption.
You are supposed to use this only in trusted networks in order to put PiKVM
behind a reverse proxy with its own SSL certificate.
```yaml
nginx:
https: