VPS Console & Temporary Web VNC
Recover a KVM guest from the terminal or open a short-lived graphical console in your browser, even when its normal network access is unavailable.
Serial Console — Direct Terminal Access
Use the serial console when guest networking or SSH is not responding. One-Click resolves the VM in the virtualization inventory, locates its Fleet hypervisor and attaches to its libvirt serial console.
one-click --console mix
# Connected to domain 'mix'
# Escape character is ^] (Ctrl + ])
Use Ctrl + ] to detach from the guest console. The guest must have a usable serial console configured. This is host-side console access; it does not require the guest's SSH service or public IP.
Temporary Web VNC — Graphical Recovery
For a VM with an active graphical VNC display, open a temporary noVNC/websockify browser viewer. One-Click resolves the owning hypervisor, creates a controller-side SSH tunnel to its display and produces a time-limited session URL.
one-click --vnc mix
one-click --vnc mix 1200 # Optional duration, in seconds
The default session duration is 600 seconds (10 minutes). When prompted, choose yes to restrict viewer access to a specific IP address. If One-Click cannot determine your SSH client's address after switching users, enter the browser's actual public source IP manually. An empty address must never result in an unrestricted rule.
The browser URL contains a bearer token. Treat it as sensitive, do not share it or include it in public logs, and close the session when finished. The current example workflow may return an http:// link rather than HTTPS; avoid traversing untrusted networks with that URL. Prefer an IP restriction and a trusted encrypted access path.
What Happens on a Remote Fleet Hypervisor
- The controller identifies the target VM and its owning hypervisor from the VPS and Fleet inventories.
- For
--console, it opens a libvirt serial-console connection on that hypervisor. - For
--vnc, it finds the guest's graphical display and creates a loopback SSH tunnel to it. - It requests optional access control for the temporary viewer and applies the appropriate firewall rule.
- The temporary web proxy presents the browser session and cleans up its token, ports and tunnel after expiration.
Troubleshooting
virsh vncdisplay result.sudo, su, or within tmux. Supply the browser client's actual IP explicitly when restricting the viewer.