Skip to main content

Use the VM console

Browser-based VNC into a KubeVirt VirtualMachine. Your browser never sees the kubeconfig — DT Edge Platform proxies the connection.

Prerequisites​

  • The edge cluster has KubeVirt + CDI installed (the standard edge preset includes both)
  • At least one VirtualMachine resource is running on it
  • You have vm:console (or equivalent) permission in your role

Open a console​

Sidebar → Applications → find the release that owns the VM → Detail → VirtualMachines tab → click the VM row → VNC.

Alternatively, from a release's resource list, click any VirtualMachine resource → the right panel shows a "Open VNC" button.

A new tab opens with a noVNC client embedded in DT Edge Platform's UI. The connection establishes within a few seconds (you'll see a "Connecting…" overlay).

Inside the console​

The console behaves like a normal VNC session:

  • Mouse + keyboard work as if you were sitting at the VM
  • Clipboard sharing depends on the VM's guest OS settings; not guaranteed
  • Resolution adapts to the browser window
  • Closing the tab disconnects the session

Send special keys​

Top of the console area:

  • Ctrl-Alt-Del — login prompt on Linux, task manager on Windows
  • Send key — manual keypress for combinations the browser intercepts (e.g. F11, Print Screen)

Multiple sessions​

Each click opens its own session. KubeVirt allows multiple simultaneous viewers; they see the same screen. Don't keep more than 2-3 open against the same VM — bandwidth scales linearly.

Why does it sometimes drop?​

The VNC tunnel goes through a chain:

browser ──WebSocket──> dtedge UI ──WebSocket──> dtedge API
──> kube-apiserver ──> virt-handler ──> qemu

If any link drops (DT Edge Platform pod restart, edge network blip, apiserver restart) the WebSocket closes and you'll see a "Disconnected" overlay. Refresh the tab to reconnect.

Why does the console need this much plumbing​

  • Direct VNC over the internet would expose qemu's protocol surface — known to be loose. We tunnel inside an authenticated HTTPS WebSocket.
  • Edge clusters' kubeconfigs aren't shared with the browser. Only the DT Edge Platform backend has them. The browser → backend connection authenticates with your normal JWT; the backend → apiserver connection uses the stored kubeconfig.

If your VM is misbehaving and the console doesn't help (e.g. the guest is hung before it shows anything), check the Detail view's events tab — KubeVirt emits events for VM start failures, image pull errors, etc.

Permissions​

Console access is gated on the same edge-instances:read permission as the rest of the edge view. If you can't open a console for a VM, you probably don't have the role for that edge — ask your admin.

See also​