After a long time struggling, I finally found a solution to this.
But first of all many thanks to all forum posters also trying to get this working and sharing their results – that helped a lot.
The following is a brief description of my setup:
Starting point is my lab cluster with tree nodes (not required, but that’s what I already had):
pvelab1 -
pvelab2 -
pvelab3 -
First, you need a (virtual) server for installing nginx. I am using a debian VM on my proxmox lab cluster for that.
To keep the setup simple I gave that server an IP address within the clusters subnet:
Install all packages needed ...
apt-get install nginx-full openssl php5-fpm php5-curl
Since we need a SSL certificate for this to work, create a self-signed certificate:
mkdir -p /etc/nginx/ssl
openssl genrsa -out /etc/nginx/ssl/server.key 2048
openssl req -new -sha256 -key /etc/nginx/ssl/server.key -out server.csr
openssl x509 -req -days 3650 -in server.csr -signkey /etc/nginx/ssl/server.key -out /etc/nginx/ssl/server.crt
Then configure nginx:
nano /etc/nginx/sites-available/proxmox-gui
ln -s /etc/nginx/sites-available/proxmox-gui /etc/nginx/sites-enabled/
/etc/nginx/sites-available/proxmox-gui contains these lines:
# upstream to proxmox cluster
upstream pvelab {
server backup;
server backup;
# private server with php supprt
server {
root /var/www/html;
index index.php;
location ~ .php$ {
fastcgi_pass unix:/var/run/php5-fpm.sock;
fastcgi_index index.php;
include fastcgi_params;
try_files $uri $uri/index.php;
# public server with ssl
# proxy two pve api methods (vncproxy and vncwebsocket)
# and redirect ererything else to the local server
server {
server_name _;
listen 443;
ssl_certificate_key /etc/nginx/ssl/server.key;
ssl_certificate /etc/nginx/ssl/server.crt;
ssl on;
proxy_redirect off;
location ~* .*/(vncproxy|vncwebsocket)$ {
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_pass https://pvelab;
location / {
proxy_pass http://localhost:5555;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header Host $host;
On debian I needed an additional line in /etc/nginx/fastcgi_params:
fastcgi_param SCRIPT_FILENAME $request_filename;
To complete the nginx/php5-fpm setup restart both:
service php5-fpm restart
service nginx restart
Now we need to copy the noVNC files from our proxmox server(s):
mkdir -p /var/www/html/novnc/locale
scp root@* /var/www/html/novnc/locale/
scp -r root@* /var/www/html/novnc/
The file index.html.tpl (copied in the previous step) needs to be patched.
Save the following as patch file index.html.tpl.patch:
--- index.html.tpl 2017-03-10 08:37:24.000000000 +0100
+++ index.html.tpl 2017-05-13 21:44:01.000000000 +0200
@@ -1,7 +1,7 @@
<!DOCTYPE html>
- <title>[% nodename %] - Proxmox Console</title>
+ <title>noVNC</title>
<meta charset="utf-8">
@@ -14,11 +14,9 @@
<!-- Stylesheets -->
<link rel="stylesheet" href="/novnc/include/base.css" />
- [% IF langfile %]
- <script type='text/javascript' src='/pve2/locale/pve-lang-[% lang %].js'></script>
- [% ELSE %]
<script type="text/javascript">function gettext(buf) { return buf; }</script>
- [% END %]
<script type="text/javascript">
if (typeof(PVE) === 'undefined') PVE = {};
PVE.UserName = '[% username %]';
And apply it with:
patch -d /var/www/html/novnc < index.html.tpl.patch
Now download the PHP API class:
wget -O /var/www/html/pve2_api.class.php
That file also needs to be patched.
Save the following as patch file pve2_api.class.php.diff:
--- /var/www/html/pve2_api.class.php 2017-05-15 10:53:02.572000000 +0200
+++ /var/www/html/pve2_api.class.php 2017-05-15 11:06:13.000000000 +0200
@@ -131,6 +131,14 @@
setrawcookie("PVEAuthCookie", $this->login_ticket['ticket'], 0, "/");
+ # returns the CSRFPreventionToken
+ public function getCSRFPreventionToken() {
+ if (!$this->check_login_ticket()) {
+ throw new PVE2_Exception("Not logged into Proxmox host. No Login access ticket found or ticket expired.", 3);
+ }
+ return $this->login_ticket['CSRFPreventionToken'];
+ }
* bool check_login_ticket ()
* Checks if the login ticket is valid still, returns false if not.
Again apply the patch with:
patch -d /var/www/html < pve2_api.class.php.diff
The last thing remaining is to create a PHP script that returns the noVNC page.
As this is only for demonstration purposes I included everything hard coded.
Save the following as file /var/www/html/index.php:
$nodeaddress = "";
$nodename = "pvelab1";
$nodeport = 8006;
$user = "testuser";
$pass = "testpass";
$auth = "pve";
$vmname = "test";
$vmid = 100;
$pve2 = new PVE2_API($nodeaddress, $user, $auth, $pass, $nodeport);
if ($pve2->login()){
$userauth = sprintf("%s@%s", $user, $auth);
$token = $pve2->getCSRFPreventionToken();
$file = file_get_contents('novnc/index.html.tpl', FILE_USE_INCLUDE_PATH);
$searchTerms = array ( '[% vmname %]', '[% username %]', '[% token %]' );
$replacements = array ( $vmname, $userauth, $token );
print(str_replace( $searchTerms, $replacements, $file));
} else {
print("Login to Proxmox Host failed.\n");
That’s it! You now should be able to start a noVNC session with the URI parameter you already know from the Proxmox GUI:
Open issues:
Right now all the actions in the noVNC window (Reset, Shutdown, ...) show an error.
They seem to need additional API methods, but thats something I will sort out some time later ...
Hope this saves someone some time