- Shell 82.5%
- Python 17.5%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
Zwei Abschnitte, ein Ziel: "Anwendungen" und "Geoeffnet" fuehrten beide an
dieselbe Stelle, weil eine Kachel eine laufende Anwendung ohnehin nach vorn
holt, statt sie neu zu starten. Zwei Kacheln fuer eine Sache sehen aber aus
wie zwei Sachen.
Jetzt gibt es nur noch "Anwendungen". Laeuft eine, bekommt ihre Kachel einen
Rand in der Signalfarbe - man sieht also vorher, ob der Klick hinfuehrt oder
erst startet. Der zweite Abschnitt heisst "Weitere Fenster" und zeigt nur
noch, was zu keiner Kachel gehoert; meist ist er leer und dann unsichtbar.
Dazu zwei Dinge, die dabei aufgefallen sind:
* Der Launcher war 1416 statt 1280 Pixel breit, die letzte
Einstellungskachel stand ausserhalb des Schirms. Ursache war ein langer
Fenstertitel ("ivCAMPUS - Other User - OX App Suite") in einer Kachel:
Eine Rollflaeche mit waagerechter Vorgabe NEVER verlangt die volle
Mindestbreite ihres Inhalts. Jetzt EXTERNAL, und die Beschriftungen
werden abgeschnitten statt zu wachsen. Dieselbe Falle wie zuvor bei der
Hoehe.
* Die Fensterklasse kommt nicht mehr aus "wmctrl -lx", sondern aus xprop.
Chromium haengt den Profilpfad in den Instanznamen - mit Leerzeichen
darin, sodass das Zerlegen nach Spalten die falsche Spalte trifft.
Ausserdem Benachrichtigungen: NotificationsAllowedForUrls fuer die
eingestellte Adresse, alles andere blockiert. Auf "fragen" erschiene sonst
der Balken mit "Zulassen" und "Blockieren" im Fenster - und wer einmal
blockiert, bekommt nie wieder einen Hinweis, ohne Weg zurueck.
Auf VM 103 geprueft: drei Fenster, richtige Klassen, beide Kacheln
markiert, Holen gibt 0 zurueck und die Fensterzahl bleibt bei drei.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
||
| auto | ||
| config | ||
| docs | ||
| infrastructure | ||
| Logos | ||
| screens | ||
| .gitignore | ||
| ivcampus-logo.png | ||
| ivcampus.svg | ||
| oxCampusOS.code-workspace | ||
| README.md | ||
OxCampusOS
A lean Debian 13 system for kiosk devices. It boots straight into a full-screen Chromium browser without a login, and is managed centrally through TacticalRMM.
| Boot menu | Splash screen | Kiosk | Console |
|---|---|---|---|
![]() |
![]() |
![]() |
![]() |
The full installation sequence, with explanations, is in docs/installation.md.
What the image brings
- Debian 13 "Trixie" with kernel 7.1 from backports — so hardware the stable kernel does not know yet works too
- Starts without a login into Chromium on a freely chosen address
- Installs itself almost entirely: only language, country and keyboard layout are asked
- Assigns its own device names following the pattern
oxcampusos-a3f91c2e - Ready for meetings: camera, microphone, audio and screen sharing are pre-authorised for the configured address — no permission dialogue in full screen
- Prints without drivers over IPP Everywhere
- Launcher on the Super key: switch between open windows, plus volume, network, printer, connection test, restart and shut down
- Remote management over SSH and TacticalRMM
- Overview on login at the console: device, address and the state of kiosk, TacticalRMM and lockdown
- UEFI with Secure Boot
Where to go next
| You want to … | Go here |
|---|---|
| get from nothing to a running device | docs/quickstart.md |
| understand how the image is put together | docs/architecture.md |
| build or change an image | docs/building.md |
| know what happens during installation | docs/installation.md |
| configure or reach a running device | docs/operating.md |
| adjust the boot menu, splash screen or console | docs/appearance.md |
| look up an error | docs/pitfalls.md |
| manage devices through TacticalRMM | infrastructure/tacticalrmm/ |
| prepare the servers around the devices | infrastructure/ |
| see where the launcher and Keycloak are heading | docs/launcher.md |
| contribute to the project | docs/contributing.md |
What is still missing
-
Disk encryption with LUKS and TPM binding, set up by the installer. Deliberately last — before that it gets in the way of testing. check-encryption.sh already reports which devices would need reinstalling for it.
-
Enforcing Secure Boot. The signed chain is in place —
shim-signed,grub-efi-amd64-signed, UEFI-only — but nothing makes a device refuse to boot with Secure Boot switched off in firmware. Only a firmware password on the device itself can do that, which is work for the person mounting it, not something the image can carry. What the image could do is report it:check-encryption.shreads the state, but only monthly. -
The oxCampus branding. The address is now the real one —
https://langen.demo.open-xchange.com/inkiosk.conf, in the launcher's application entry, and in every fallback. What still shows ivCampus is the artwork: the logos in the boot menu, the splash screen and the console, and the colours they were derived from. That is a handful of image files; see appearance.md for which image sits where. -
Locale. After the installation
/etc/default/localecontainsLANG=C.UTF-8even though a language was chosen — the image sets it correctly, the installer overwrites it. The visible consequence is not the console but the browser: Chromium derives itsAccept-Languageheader fromLANG, so the web application is asked in the wrong language and answers accordingly.The fix most likely belongs in
preseed/late_command, next to the existing repairs of/etc/network/interfacesandsources.list: read the chosen locale back from debconf (debian-installer/locale) and write it to/target/etc/default/locale. Read back rather than hard-coded — whoever picks French at install time should get French.
Licence and origin
The configuration in this repository is freely available to the project.
The TacticalRMM agent is compiled during the build from amidaware/rmmagent and deliberately not kept in the repository: the Tactical RMM licence permits use on your own and customer networks, but not redistribution. Details in docs/operating.md.



