Skip to content

Web console and VNC

Everything on this platform is an API, and an API is no help when an instance will not boot far enough to accept an SSH connection. Two hosts exist for that case.

https://console.shelfcs.com

The platform’s web dashboard. Sign in with the cloud username and password issued at onboarding, domain Default, and you are in your own project only.

What it is good for:

  • Watching an instance boot, from its console output.
  • Attaching and detaching volumes when you want to see what you are doing.
  • Reading the actual error behind a failed launch, which is often more specific than the EC2-shaped code the API is obliged to return.
  • Finding your project’s real quota and usage.

What it is not: it is not the way to run infrastructure. Console clicks are unfinished work — anything you want to keep belongs in Terraform against the EC2 API or the Account developer guide.

console-api.shelfcs.com is the web console’s own backend. The browser calls it; you do not.

https://vnc.shelfcs.com

noVNC, reached through a single-use, time-limited URL that the compute service mints for one instance:

cloud console url show <server> --novnc

The URL contains a token, expires quickly, and is not reusable. Do not paste one into a ticket.

This is a graphical console attached to the virtual machine’s display. It works before the network does, which is the point: a machine with a broken /etc/fstab, a firewall rule that locked you out, or a cloud-init failure is reachable here and nowhere else.

[!warning]

nofail in /etc/fstab is what keeps you out of this console in the first place. A volume that is not present at boot, mounted without nofail, drops the machine into emergency mode — and emergency mode wants a root password that a cloud image does not have. Recovering from that means detaching the root disk and mounting it on another instance.

WantEC2 hereInstead
Console text outputGetConsoleOutput — not implementedthe web console, or cloud console log show
Console screenshotGetConsoleScreenshot — not implementedThe VNC console
Serial consoleSendSerialConsoleSSHPublicKey — not implementedThe VNC console

An AWS-shaped tool that reaches for console output receives InvalidAction. This is a real gap in the EC2 layer, not a policy.

  • Both consoles are behind the same ingress as every other endpoint, with the same absence of rate limiting noted on the Service endpoints page.
  • There is no MFA on the cloud login. the identity service’s password is the only factor.
  • There is no SSO. Identity for the storefront is the hosted auth service; identity for the cloud is the identity service; they are two accounts created together at onboarding and they do not share a session.
  • There is no password-reset endpoint for the cloud password yet. A later /v1/onboard call with a different password does not change it.