From 5a8468d3edac4a49b6db040d6cd56db33b1f2117 Mon Sep 17 00:00:00 2001 From: Maxim Devaev Date: Sat, 4 Jul 2026 07:47:51 +0300 Subject: [PATCH] fix --- docs/building_os.md | 16 +++++++++++----- docs/gpio.md | 6 ------ docs/ipmi.md | 2 +- docs/letsencrypt.md | 10 +++++----- docs/msd.md | 11 +++++++++-- docs/reverse_proxy.md | 4 ++++ 6 files changed, 30 insertions(+), 19 deletions(-) diff --git a/docs/building_os.md b/docs/building_os.md index 91db2b63..c86748f2 100644 --- a/docs/building_os.md +++ b/docs/building_os.md @@ -68,15 +68,21 @@ Docker must work in privileged mode. TIMEZONE = Europe/Nicosia # For SSH root user - ROOT_PASSWD = rootpass + ROOT_PASSWD = change_me - # Web UI credentials: user=admin, password=adminpass - WEBUI_ADMIN_PASSWD = adminpass + # Web UI credentials: user=admin, password=admin_change_me + WEBUI_ADMIN_PASSWD = admin_change_me - # IPMI credentials: user=admin, password=adminpass - IPMI_ADMIN_PASSWD = adminpass + # IPMI credentials: password=ipmi_change_me + IPMI_ADMIN_PASSWD = ipmi_change_me ``` + !!! warning + + Due to the [legacy of the IPMI protocol](ipmi.md), passwords for it are stored as plain text in `/etc/kvmd/ipmipasswd`. + + Do not use passwords for IPMI that you use somewhere else. + 4. Build the OS. It may take about one hour depending on the Internet connection: ```console diff --git a/docs/gpio.md b/docs/gpio.md index 80353fc3..faca8c4a 100644 --- a/docs/gpio.md +++ b/docs/gpio.md @@ -370,12 +370,6 @@ kvmd ```sudoers kvmd ALL=(ALL) NOPASSWD: /usr/bin/reboot ``` - - NON Granular example (Captures ALL commands) - - ```sudoers - kvmd ALL=(ALL) NOPASSWD: ALL - ``` Example of the `/etc/kvmd/override.yaml`: diff --git a/docs/ipmi.md b/docs/ipmi.md index 9f3d1ed3..55feff6b 100644 --- a/docs/ipmi.md +++ b/docs/ipmi.md @@ -29,7 +29,7 @@ It can be useful for managing a large number of machines with PiKVM. Its advanta [root@pikvm ~]# rw ``` - 2. Set up IPMI account in file `/etc/kvmd/ipmipasswd` (see the comment inside it). + 2. Set up IPMI account in file `/etc/kvmd/ipmipasswd` (see the comment inside it). Passwords are stored as plain text due to the IPMI legacy. Do not use passwords for IPMI that you use somewhere else. 3. Enable the `kvmd-ipmi` daemon: diff --git a/docs/letsencrypt.md b/docs/letsencrypt.md index 8d2f17f2..75c720d2 100644 --- a/docs/letsencrypt.md +++ b/docs/letsencrypt.md @@ -205,8 +205,8 @@ These instructions are for how to install and use the **`acme-dns-client`** with ### Assumptions - ACME DNS is already set up and functioning in the environment -- ACME DNS Server is **`auth.example.org`** -- PiKVM Fully Qualified Domain Name (FQDN) is **`pikvm.example.org`** +- ACME DNS Server is **`auth.example.com`** +- PiKVM Fully Qualified Domain Name (FQDN) is **`pikvm.example.com`** - PiKVM is running on a supported Raspberry Pi using the [PiKVM OS](https://github.com/pikvm/os) (which is 32-bit as of the writing of this documentation) - All configuration examples below are as user **`root`** via a terminal session to PiKVM @@ -251,7 +251,7 @@ These instructions are for how to install and use the **`acme-dns-client`** with This is interactive, follow instructions for creating and verifying the appropriate `CNAME` record. ``` - # acme-dns-client register -d pikvm.example.org -s http://auth.example.org + # acme-dns-client register -d pikvm.example.com -s https://auth.example.com ``` Once registration is complete ownership of `clientstorage.json` must be changed to `kvmd-certbot`. @@ -272,11 +272,11 @@ These instructions are for how to install and use the **`acme-dns-client`** with 6. Request Certificate via Certbot ``` - # kvmd-certbot certonly --manual --preferred-challenges dns --manual-auth-hook 'acme-dns-client' -d pikvm.example.org + # kvmd-certbot certonly --manual --preferred-challenges dns --manual-auth-hook 'acme-dns-client' -d pikvm.example.com ``` !!! note - If using an ACME compatible Certificate Authority (other than Let's Encrypt) do not forget to add `--server https://ca.example.org/acme/acme/directory` to `kvmd-certbot` + If using an ACME compatible Certificate Authority (other than Let's Encrypt) do not forget to add `--server https://ca.example.com/acme/acme/directory` to `kvmd-certbot` 7. Follow steps 3 through 5 under [Basic Setup](https://docs.pikvm.org/letsencrypt/#basic-setup) to complete setup and renewal of certificates diff --git a/docs/msd.md b/docs/msd.md index cf02c389..02471f24 100644 --- a/docs/msd.md +++ b/docs/msd.md @@ -232,11 +232,18 @@ linux kernel will default to 'root' ownership of the mountpoint. This means the volume will be visible in the 'Media' menu, but will be marked as `[read-only]`, without any obvious reason. +First, you need to find out UID of the `kvmd` user: + +```console +[root@pikvm ~]# id kvmd +uid=966(kvmd) ... +``` + The correct `/etc/fstab` entry for a USB drive that presents as `/dev/sda1` with an -exfat filesystem is: +exfat filesystem is (use your actual UID of `kvmd`): ```fstab - /dev/sda1 /var/lib/kvmd/msd/usb exfat auto,nofail,rw,umask=0000 0 0 + /dev/sda1 /var/lib/kvmd/msd/usb exfat auto,nofail,rw,umask=0133,uid=966 0 0 ``` This says to mount it automatically, do not fail if it's missing, mount it read/write by default, and allow all users and groups access to it. diff --git a/docs/reverse_proxy.md b/docs/reverse_proxy.md index 1d0e02fa..56185979 100644 --- a/docs/reverse_proxy.md +++ b/docs/reverse_proxy.md @@ -52,6 +52,10 @@ HTTPS for them. * Disabling HTTPS. All requests will be handled via HTTP port `80`. + Please note that this disables encryption. + You are supposed to use this only in trusted networks in order to put PiKVM + behind a reverse proxy with its own SSL certificate. + ```yaml nginx: https: