Back to tutorials
Key takeaways
- Guacamole translates the RDP, VNC and SSH protocols into HTML5: nothing to install on the client machine, and a single service (HTTPS) exposed to the Internet instead of a spread of ports 3389, 5900 and 22.
- The Docker Compose deployment is built from four containers:
guacd(the daemon that actually speaks the remote protocols),postgreshostingguacamole_db,db-initwhich runs/opt/guacamole/bin/initdb.sh --postgresql, andguacamole, the web application published on port 8080. - Access happens at
http://<your_server_ip>:8080/guacamole/: the/guacamole/suffix is part of the application context and is not optional. - Two passwords must be changed: the three occurrences of
CHANGEME_A_STRONG_PASSWORDindocker-compose.ymlbefore the first start, and the default guacadmin / guacadmin account right after the first login (Preferences, then Users). - Budget at least 2 GB of RAM. In production, put a reverse proxy (Nginx Proxy Manager, Traefik or Caddy) in front of the instance to handle TLS. Two standout features: session sharing in read-only or full-control mode, and video recording of sessions through the
./data/guacd/recordvolume.
What is Apache Guacamole?
Apache Guacamole is a clientless remote desktop gateway. It lets you access your computers (Linux, Windows, macOS) from any device with a simple web browser. It translates standard protocols such as VNC, RDP and SSH into an HTML5 protocol that runs in your browser.
Apache Guacamole is a clientless remote desktop gateway. It lets you access your computers (Linux, Windows, macOS) from any device with a simple web browser. It translates standard protocols such as VNC, RDP and SSH into an HTML5 protocol that runs in your browser.
Why use Guacamole?
- Universal Access: No heavy client to install. A browser is all you need.
- Centralization: Manage all your access (SSH, RDP, VNC) from a single web interface.
- Security: Expose a single service (HTTPS) to the Internet instead of multiple RDP/VNC/SSH ports. It can integrate with existing authentication systems (LDAP, SAML, OpenID).
- Session Sharing: Share a session in read-only or full-control mode, ideal for support or training.
- Session Recording: Record RDP/VNC/SSH sessions as video for auditing or training.
Prerequisites
- A Linux server with Docker and Docker Compose installed. (This is the simplest and most recommended installation method.)
- Root access or sudo privileges.
- At least 2 GB of RAM on the server.
Premium Content
This advanced tutorial is reserved for premium members.
9,90€ / month
- All advanced tutorials
- New content every week
- Progress tracking
- Cancel anytime