Support secure external LTX OAuth

This commit is contained in:
Mikei386
2026-09-13 22:28:56 +02:00
parent 7d02fa1b8b
commit 719bc4ccf7
3 changed files with 15 additions and 1 deletions
+3 -1
View File
@@ -17,6 +17,8 @@ RUN apt-get update && DEBIAN_FRONTEND=noninteractive apt-get install -y --no-ins
&& chmod +x /tmp/ltx-desktop.AppImage \
&& cd /opt/ltx-desktop \
&& /tmp/ltx-desktop.AppImage --appimage-extract >/dev/null \
&& sed -i 's/host="127.0.0.1", port=port/host=os.environ.get("LTX_HOST", "127.0.0.1"), port=port/' \
/opt/ltx-desktop/squashfs-root/resources/backend/ltx2_server.py \
&& rm /tmp/ltx-desktop.AppImage \
&& ln -s /usr/share/novnc/vnc.html /usr/share/novnc/index.html
@@ -31,5 +33,5 @@ ENV DISPLAY=:0 \
XDG_CACHE_HOME=/data/cache \
NO_AT_BRIDGE=1
EXPOSE 8015
EXPOSE 8015 41955
ENTRYPOINT ["/usr/local/bin/ltx-desktop-entrypoint"]
+6
View File
@@ -18,3 +18,9 @@ to Hugging Face in the application.
The image installs a narrow `tar` wrapper that ignores uid/gid metadata in the
official first-run Python archive. This keeps `cap_drop: [ALL]` intact while
allowing the archive, whose entries belong to build user 1001, to be extracted.
The backend uses stable port `41955`. Hugging Face OAuth can therefore run in a
normal client browser through a local SSH tunnel to the container instead of
requiring a browser or storing login credentials inside the VNC desktop.
The container port is published only on Athena's `127.0.0.1`; it is not exposed
on Athena's LAN or WireGuard interfaces.
+6
View File
@@ -23,6 +23,12 @@ services:
NVIDIA_VISIBLE_DEVICES: ${LTX2_GPU_UUID:-GPU-8ad38c6c-5a01-9d8e-1dfa-ed662ad78fbe}
NVIDIA_DRIVER_CAPABILITIES: compute,utility,graphics
CUDA_VISIBLE_DEVICES: "0"
# Stable and intentionally different from the default local macOS app
# port, so OAuth can return through an SSH tunnel without a collision.
LTX_PORT: "41955"
LTX_HOST: 0.0.0.0
ports:
- 127.0.0.1:41955:41955
volumes:
- /data/video/ltx-desktop:/data
networks: