neko — a self-hosted virtual browser that runs in a container and streams to you over WebRTC: share a browser for watch parties, collaborate, or browse in an isolated, disposable session. Deployed as a single host-networked Nomad service.
Needs nomad-pack on PATH. The script only adds the nomploy registry and runs this pack.
Source ↗ Project ↗ ★ 22.4k ⚑ Report an issue
Save as values.hcl, edit, then run:
# The name of the Nomad job.
job_name = "neko"
# The Nomad namespace to deploy into.
namespace = "default"
# The datacenters to deploy to.
datacenters = ["*"]
# The neko container image (one per browser/app, e.g. .../firefox, .../chromium, .../vlc). Pin a tag in production.
image = "ghcr.io/m1k1o/neko/firefox:latest"
# Host port for the neko web UI.
port = 8080
# WebRTC ephemeral UDP port range (inclusive) for media. Opened on the host via host networking.
webrtc_epr = "56000-56100"
# Public IP clients use to reach this node for WebRTC (NAT 1:1). Empty = neko auto-detects (works on a directly-reachable host).
nat1to1_ip = ""
# Password for regular (viewer/control) members. CHANGE THIS.
user_password = "neko"
# Password for admin members. CHANGE THIS.
admin_password = "admin"
# Virtual screen resolution and refresh rate.
screen = "1280x720@30"
# Shared-memory size in bytes for the browser (prevents renderer crashes).
shm_size = 2147483648
# Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true".
constraints = []
# The task resources. A live browser needs real CPU/RAM.
resources = {
cpu = 2000
memory = 2048
}
| Name | Type | Default | Description |
|---|---|---|---|
| job_name | string | "neko" | The name of the Nomad job. |
| namespace | string | "default" | The Nomad namespace to deploy into. |
| datacenters | list | ["*"] | The datacenters to deploy to. |
| image | string | "ghcr.io/m1k1o/neko/firefox:latest" | The neko container image (one per browser/app, e.g. .../firefox, .../chromium, .../vlc). Pin a tag in production. |
| port | number | 8080 | Host port for the neko web UI. |
| webrtc_epr | string | "56000-56100" | WebRTC ephemeral UDP port range (inclusive) for media. Opened on the host via host networking. |
| nat1to1_ip | string | "" | Public IP clients use to reach this node for WebRTC (NAT 1:1). Empty = neko auto-detects (works on a directly-reachable host). |
| user_password key | string | "neko" | Password for regular (viewer/control) members. CHANGE THIS. |
| admin_password key | string | "admin" | Password for admin members. CHANGE THIS. |
| screen | string | "1280x720@30" | Virtual screen resolution and refresh rate. |
| shm_size | number | 2147483648 | Shared-memory size in bytes for the browser (prevents renderer crashes). |
| constraints | list | [] | Placement constraints. On a nomploy cluster: attribute = "$${meta.nomploy_control_plane}", operator = "=", value = "true". |
| resources | object | {
cpu = 2000
memory = 2048
} | The task resources. A live browser needs real CPU/RAM. |
No variables match.
neko runs a full web browser (or other GUI app) inside a container and streams it to your browser over WebRTC, with shared or exclusive control. Use it for watch parties, collaborative browsing, giving someone a throwaway browser, or isolating risky sites away from your own machine.
This pack runs neko as a single host-networked Nomad service (default image: Firefox).
nomad-pack run neko --registry=nomploy \
--var user_password=$(openssl rand -hex 8) \
--var admin_password=$(openssl rand -hex 8) \
--var nat1to1_ip=<node-public-ip>
Open http://<node-ip>:8080 and log in.
| Variable | Default | Description |
|---|---|---|
image |
ghcr.io/m1k1o/neko/firefox:latest |
Browser/app image (chromium, vlc, kde, …). |
port |
8080 |
Host port for the web UI. |
webrtc_epr |
56000-56100 |
WebRTC UDP media port range (host networking). |
nat1to1_ip |
(auto) | Public IP for WebRTC if the node is behind NAT. |
user_password |
neko |
Member password — change this. |
admin_password |
admin |
Admin password — change this. |
screen |
1280x720@30 |
Virtual screen resolution/refresh. |
shm_size |
2147483648 (2 GB) |
Shared memory for the browser. |
resources |
2000 MHz / 2048 MB | CPU and memory (a live browser is hungry). |
WebRTC: media flows over the UDP range
webrtc_epr, which host networking opens directly on the node — allow it through the firewall. Behind NAT, setnat1to1_ipto the node's public address.