Skip to content

Session controls

These are host features. Operator-approved Cloud Connect pilot access connects the machine; the machine’s administrator decides who may sign in and which policies apply.

An administrator can open a separate view-only, video-only peer of an already running desktop from the host’s Admin page. It does not take over the primary viewer’s input, start a stopped desktop, or grant an ordinary member administrator access. One admin observer is supported at a time.

The host must explicitly enable DARPAN_ALLOW_SHADOWING=true, and the viewer must be in DARPAN_ADMIN. Both checks apply to the watch page and its stream. The default is off. This is an admin-only feature, not a public sharing link. The existing watch mode is silent: it has no target consent prompt or viewer notice, so agree on its use with the people sharing the host before enabling it.

The host can record the session’s video automatically for the whole session. On a packaged installation, configure /etc/darpan/darpan.env:

Terminal window
DARPAN_RECORD=true
DARPAN_RECORD_DIR=Recordings/Darpan
DARPAN_RECORD_NOTICE=true

A relative destination is inside each session user’s home directory. Files are H.264 video in Matroska (.mkv), written on the host. The recorder is off by default; the permanent recording notice is on by default when recording is enabled. This records video, not a microphone/audio track. A killed session can leave an incomplete tail, but the preceding video is intended to remain playable. Keep sufficient disk space and manage local file permissions.

Restart the host services after changing their environment; the setting takes effect when a new desktop starts. This is automatic session-wide recording. There is no time/event rule builder, cloud recordings library or automatic retention policy in v1. Ending a browser connection does not end its desktop or recording; use End desktop when you intend to stop the session.

The host administrator can set default limits and override them for individual Linux users. On a systemd host these become MemoryMax, CPUQuota and TasksMax on each desktop’s scope. For example, 200% CPU is up to two CPU cores’ worth of execution, not two percent of the whole machine.

The host Admin page exposes per-user memory, CPU and task limits. Limits apply to the next desktop start; reconnecting to a running desktop keeps its existing scope. An unset per-user field inherits the configured host default. These are CPU/RAM/process limits, not dedicated GPU allocation or isolated GPU VRAM.

Host policies control clipboard and file transfer direction, audio, view-only mode and session lifetimes. Per-user settings cannot enable a transfer the host forbids. AI agents have their own desktops and accounts; owners and administrators can watch, pause and take over an agent from the workspace.

See AI agents and sharing a host.

Limits edited in /admin persist across gateway restarts in the private resource-limits file. A failed save leaves the current values unchanged. Clearing a field restores the host default; changes apply on the next session start. A corrupt saved limits file stops gateway startup so limits cannot silently disappear. Restore the last valid file to recover.