Skip to content

feat(selkies-project/templates): add a Selkies desktop template for Docker - #1150

Draft
ehfd wants to merge 2 commits into
coder:mainfrom
ehfd:selkies-template
Draft

ehfd wants to merge 2 commits into
coder:mainfrom
ehfd:selkies-template

Conversation

@ehfd

@ehfd ehfd commented Sep 28, 2026

Copy link
Copy Markdown

Description

Adds registry/selkies-project/templates/docker-desktop, a Docker workspace on Selkies' desktop image (ghcr.io/selkies-project/selkies/desktop:latest-ubuntu26.04: LXQt, Firefox, and Chrome, with Selkies and Xvfb installed), with a persistent home on /home/ubuntu, 2 GB of shared memory for the desktop's browsers, and the Selkies module with install_selkies = false, which starts the image's default desktop behind Coder's proxy. It follows the shape of the Docker Containers template: the docker_socket variable, the host.docker.internal rewrite, and the labeled home volume.

  • GPU: none or NVIDIA. NVIDIA passes the GPUs in with the nvidia runtime, as Selkies' Getting Started does, and NVENC then encodes the stream. None sets NVIDIA_VISIBLE_DEVICES=void, since the image asks for every NVIDIA GPU and a host whose default runtime is NVIDIA's would otherwise pass them in regardless.
  • Display backend: X11 or Wayland.
  • Intel and AMD need the Docker host's render-node group ID, which a template cannot know, so the README names the two attributes to add rather than offering an option that fails where that ID differs from the image's.

This branch is stacked on #1149 and carries its commit (the namespace, the module, and its icon) until that merges; a rebase then leaves only this template's commit. terraform init of the registry.coder.com/selkies-project/selkies/coder source passes once the module is published; until then scripts/terraform_validate.sh stops at "Module not found".

Type of Change

  • New template

Template Information

Path: registry/selkies-project/templates/docker-desktop

Testing & Validation

  • Tests pass: templates have no test suite; terraform validate passes with the module source pointed at feat(selkies-project/selkies): add the Selkies desktop module #1149's branch, and go run ./cmd/readmevalidation accepts the README.
  • Code formatted (bun fmt): Prettier, terraform fmt, and typos are clean.
  • Changes tested locally, in Coder v2.37.3 with Docker on a host with two Tesla P100 GPUs, with the module source pointed at feat(selkies-project/selkies): add the Selkies desktop module #1149's branch, opening the Selkies app as a subdomain app in Chrome 154, Firefox 156, and WebKit 26.6:
    • No GPU, X11: no NVIDIA or DRM device in the container, although the host's default runtime is NVIDIA's; LXQt on Xvfb with software H.264; 60 fps in all three browsers.
    • NVIDIA, X11: NVENC H.264 on the P100 with zero-copy capture through the X server's DRI3; 60 fps in Chrome and Firefox.
    • NVIDIA, Wayland: NVENC H.264 with zero-copy capture on the render node; 60 fps in all three browsers.
    • No GPU, Wayland, switched on a restart: software H.264; 60 fps in Chrome.
    • The home volume starts with the image's skeleton files and keeps a file across a stop and start.
    • The Intel and AMD attributes in the README, applied through the Docker provider: without group_add the render node is refused; with the host's render group ID it opens.
    • WebKit presented the NVENC streams unevenly in some runs (stalls of a few seconds, then a burst), while it was steady on the software streams; that is a Selkies client matter, independent of this template.

Related Issues

#1149, coder/coder#30026, selkies-project/selkies#64

ehfd added 2 commits October 2, 2026 16:10
Stream the workspace's desktop to the browser with Selkies behind a
coder_app, with the KasmVNC module's variables so a template swaps one for
the other. The install script installs what the workspace lacks of Selkies
and Xvfb, with PulseAudio where no sound server is installed, from the
release's native package and the distribution, as root or with passwordless
sudo, or nothing with install_selkies = false; the start script starts
selkies-session on the loopback addresses, without a login or TLS of its
own, and waits until it answers.
…ocker

Run Selkies' desktop image as a Docker workspace with a persistent home,
shared memory for the desktop's browsers, and the Selkies module starting
the image's default desktop. A workspace picks no GPU or an NVIDIA one,
whose NVENC then encodes the stream, and X11 or Wayland. Without a GPU,
the container keeps NVIDIA's runtime from passing the host's GPUs in, as
it would where that runtime is Docker's default.
@ehfd
ehfd force-pushed the selkies-template branch from 6d99fc0 to 4096031 Compare October 2, 2026 07:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant