Web console and VNC
Objective
Section titled “Objective”Everything on this platform is an API, and an API is no help when an instance will not boot far enough to accept an SSH connection. Two hosts exist for that case.
The web console
Section titled “The web console”https://console.shelfcs.comThe platform’s web dashboard. Sign in with the cloud username and password issued at
onboarding, domain Default, and you are in your own project only.
What it is good for:
- Watching an instance boot, from its console output.
- Attaching and detaching volumes when you want to see what you are doing.
- Reading the actual error behind a failed launch, which is often more specific than the EC2-shaped code the API is obliged to return.
- Finding your project’s real quota and usage.
What it is not: it is not the way to run infrastructure. Console clicks are unfinished work — anything you want to keep belongs in Terraform against the EC2 API or the Account developer guide.
console-api.shelfcs.com is the web console’s own backend. The browser calls it; you do
not.
The instance console
Section titled “The instance console”https://vnc.shelfcs.comnoVNC, reached through a single-use, time-limited URL that the compute service mints for one instance:
cloud console url show <server> --novncThe URL contains a token, expires quickly, and is not reusable. Do not paste one into a ticket.
This is a graphical console attached to the virtual machine’s display. It works
before the network does, which is the point: a machine with a broken
/etc/fstab, a firewall rule that locked you out, or a cloud-init failure is
reachable here and nowhere else.
[!warning]
nofailin/etc/fstabis what keeps you out of this console in the first place. A volume that is not present at boot, mounted withoutnofail, drops the machine into emergency mode — and emergency mode wants a root password that a cloud image does not have. Recovering from that means detaching the root disk and mounting it on another instance.
What the EC2 API does not give you
Section titled “What the EC2 API does not give you”| Want | EC2 here | Instead |
|---|---|---|
| Console text output | GetConsoleOutput — not implemented | the web console, or cloud console log show |
| Console screenshot | GetConsoleScreenshot — not implemented | The VNC console |
| Serial console | SendSerialConsoleSSHPublicKey — not implemented | The VNC console |
An AWS-shaped tool that reaches for console output receives InvalidAction.
This is a real gap in the EC2 layer, not a policy.
Access, honestly
Section titled “Access, honestly”- Both consoles are behind the same ingress as every other endpoint, with the same absence of rate limiting noted on the Service endpoints page.
- There is no MFA on the cloud login. the identity service’s password is the only factor.
- There is no SSO. Identity for the storefront is the hosted auth service; identity for the cloud is the identity service; they are two accounts created together at onboarding and they do not share a session.
- There is no password-reset endpoint for the cloud password yet. A later
/v1/onboardcall with a different password does not change it.