No description
  • Shell 82.5%
  • Python 17.5%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Daniel Duarte 2441f7faed Launcher zusammengelegt, Benachrichtigungen freigegeben
Zwei Abschnitte, ein Ziel: "Anwendungen" und "Geoeffnet" fuehrten beide an
dieselbe Stelle, weil eine Kachel eine laufende Anwendung ohnehin nach vorn
holt, statt sie neu zu starten. Zwei Kacheln fuer eine Sache sehen aber aus
wie zwei Sachen.

Jetzt gibt es nur noch "Anwendungen". Laeuft eine, bekommt ihre Kachel einen
Rand in der Signalfarbe - man sieht also vorher, ob der Klick hinfuehrt oder
erst startet. Der zweite Abschnitt heisst "Weitere Fenster" und zeigt nur
noch, was zu keiner Kachel gehoert; meist ist er leer und dann unsichtbar.

Dazu zwei Dinge, die dabei aufgefallen sind:

* Der Launcher war 1416 statt 1280 Pixel breit, die letzte
  Einstellungskachel stand ausserhalb des Schirms. Ursache war ein langer
  Fenstertitel ("ivCAMPUS - Other User - OX App Suite") in einer Kachel:
  Eine Rollflaeche mit waagerechter Vorgabe NEVER verlangt die volle
  Mindestbreite ihres Inhalts. Jetzt EXTERNAL, und die Beschriftungen
  werden abgeschnitten statt zu wachsen. Dieselbe Falle wie zuvor bei der
  Hoehe.

* Die Fensterklasse kommt nicht mehr aus "wmctrl -lx", sondern aus xprop.
  Chromium haengt den Profilpfad in den Instanznamen - mit Leerzeichen
  darin, sodass das Zerlegen nach Spalten die falsche Spalte trifft.

Ausserdem Benachrichtigungen: NotificationsAllowedForUrls fuer die
eingestellte Adresse, alles andere blockiert. Auf "fragen" erschiene sonst
der Balken mit "Zulassen" und "Blockieren" im Fenster - und wer einmal
blockiert, bekommt nie wieder einen Hinweis, ohne Weg zurueck.

Auf VM 103 geprueft: drei Fenster, richtige Klassen, beide Kacheln
markiert, Holen gibt 0 zurueck und die Fensterzahl bleibt bei drei.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-10-01 17:28:52 +02:00
auto Kiosk-Image bootet erstmals vollstaendig durch 2026-09-09 13:33:11 +02:00
config Launcher zusammengelegt, Benachrichtigungen freigegeben 2026-10-01 17:28:52 +02:00
docs Launcher zusammengelegt, Benachrichtigungen freigegeben 2026-10-01 17:28:52 +02:00
infrastructure Launcher als Oberflaeche: GTK statt yad-Menue 2026-10-01 13:41:47 +02:00
Logos Kiosk-Image bootet erstmals vollstaendig durch 2026-09-09 13:33:11 +02:00
screens Bildschirmfotos in screens/, zwei Anzeigefehler behoben 2026-09-11 18:59:54 +02:00
.gitignore Launcher als Oberflaeche: GTK statt yad-Menue 2026-10-01 13:41:47 +02:00
ivcampus-logo.png GRUB-Menue: Preseed verlinkt, GUI-Varianten entfernt 2026-09-08 21:57:44 +02:00
ivcampus.svg GRUB-Menue: Preseed verlinkt, GUI-Varianten entfernt 2026-09-08 21:57:44 +02:00
oxCampusOS.code-workspace Ordner infrastructure/, Keycloak-Leitfaden, Launcher-Entwurf 2026-10-01 11:48:09 +02:00
README.md Echte oxCampus-Adresse eingetragen 2026-10-01 17:18:22 +02:00

OxCampusOS

A lean Debian 13 system for kiosk devices. It boots straight into a full-screen Chromium browser without a login, and is managed centrally through TacticalRMM.

Boot menu Splash screen Kiosk Console
Boot menu Splash screen Kiosk Console

The full installation sequence, with explanations, is in docs/installation.md.

What the image brings

  • Debian 13 "Trixie" with kernel 7.1 from backports — so hardware the stable kernel does not know yet works too
  • Starts without a login into Chromium on a freely chosen address
  • Installs itself almost entirely: only language, country and keyboard layout are asked
  • Assigns its own device names following the pattern oxcampusos-a3f91c2e
  • Ready for meetings: camera, microphone, audio and screen sharing are pre-authorised for the configured address — no permission dialogue in full screen
  • Prints without drivers over IPP Everywhere
  • Launcher on the Super key: switch between open windows, plus volume, network, printer, connection test, restart and shut down
  • Remote management over SSH and TacticalRMM
  • Overview on login at the console: device, address and the state of kiosk, TacticalRMM and lockdown
  • UEFI with Secure Boot

Where to go next

You want to … Go here
get from nothing to a running device docs/quickstart.md
understand how the image is put together docs/architecture.md
build or change an image docs/building.md
know what happens during installation docs/installation.md
configure or reach a running device docs/operating.md
adjust the boot menu, splash screen or console docs/appearance.md
look up an error docs/pitfalls.md
manage devices through TacticalRMM infrastructure/tacticalrmm/
prepare the servers around the devices infrastructure/
see where the launcher and Keycloak are heading docs/launcher.md
contribute to the project docs/contributing.md

What is still missing

  • Disk encryption with LUKS and TPM binding, set up by the installer. Deliberately last — before that it gets in the way of testing. check-encryption.sh already reports which devices would need reinstalling for it.

  • Enforcing Secure Boot. The signed chain is in place — shim-signed, grub-efi-amd64-signed, UEFI-only — but nothing makes a device refuse to boot with Secure Boot switched off in firmware. Only a firmware password on the device itself can do that, which is work for the person mounting it, not something the image can carry. What the image could do is report it: check-encryption.sh reads the state, but only monthly.

  • The oxCampus branding. The address is now the real one — https://langen.demo.open-xchange.com/ in kiosk.conf, in the launcher's application entry, and in every fallback. What still shows ivCampus is the artwork: the logos in the boot menu, the splash screen and the console, and the colours they were derived from. That is a handful of image files; see appearance.md for which image sits where.

  • Locale. After the installation /etc/default/locale contains LANG=C.UTF-8 even though a language was chosen — the image sets it correctly, the installer overwrites it. The visible consequence is not the console but the browser: Chromium derives its Accept-Language header from LANG, so the web application is asked in the wrong language and answers accordingly.

    The fix most likely belongs in preseed/late_command, next to the existing repairs of /etc/network/interfaces and sources.list: read the chosen locale back from debconf (debian-installer/locale) and write it to /target/etc/default/locale. Read back rather than hard-coded — whoever picks French at install time should get French.

Licence and origin

The configuration in this repository is freely available to the project.

The TacticalRMM agent is compiled during the build from amidaware/rmmagent and deliberately not kept in the repository: the Tactical RMM licence permits use on your own and customer networks, but not redistribution. Details in docs/operating.md.