Securely access a Linux host's real X display remotely, in a browser, via noVNC — no VNC client needed.
This image runs x11vnc against your host's existing X display (not a virtual desktop) and serves it over noVNC/websockify on port 6080. Pair it with a reverse proxy (Caddy, nginx, Cloudflare Tunnel, etc.) for TLS and access control — this image intentionally does not handle TLS itself.
This mirrors whatever is on the host's real screen. It is not an isolated virtual desktop. Treat access to this container as equivalent to physical access to the host.
docker run -d \
--name novnc \
-e DISPLAY=$DISPLAY \
-e VNC_PASSWORD=changeme \
-e XAUTHORITY=/root/.Xauthority \
-v /tmp/.X11-unix:/tmp/.X11-unix:ro \
-v $HOME/.Xauthority:/root/.Xauthority:ro \
-p 127.0.0.1:6080:6080 \
prateekrajgautam/novnc:latest
Then open http://localhost:6080/vnc.html and enter your VNC password.
docker-compose.yml:
services:
novnc:
image: prateekrajgautam/novnc:latest
container_name: novnc
restart: unless-stopped
env_file:
- .env
environment:
- DISPLAY=${DISPLAY}
- XAUTHORITY=/root/.Xauthority
volumes:
- /tmp/.X11-unix:/tmp/.X11-unix:ro
- ${XAUTHORITY_HOST}:/root/.Xauthority:ro
ports:
- "127.0.0.1:6080:6080"
.env:
DISPLAY=:0
XAUTHORITY_HOST=/home/youruser/.Xauthority
VNC_PASSWORD=changeme
docker compose up -d
| Variable | Required | Description |
|---|---|---|
VNC_PASSWORD | Yes | Password required to connect over VNC/noVNC. |
DISPLAY | No | X display to mirror. Defaults to :0. |
XAUTHORITY | No | Path inside the container to the Xauthority file. Defaults to /root/.Xauthority. |
| Host path | Container path | Purpose |
|---|---|---|
/tmp/.X11-unix | /tmp/.X11-unix (ro) | X11 socket — required to see the display. |
$HOME/.Xauthority | /root/.Xauthority (ro) | X auth cookie — required for access. |
Both should be mounted read-only. Do not run xhost + on the host as a workaround — it disables X access control entirely.
| Port | Purpose |
|---|---|
| 6080 | noVNC web client (HTTP, no TLS) |
This image does not terminate TLS. Bind it to 127.0.0.1 and put it behind a reverse proxy that handles HTTPS (Caddy, nginx, Traefik, Cloudflare Tunnel, etc.), and add an authentication layer in front (e.g. Cloudflare Access, HTTP basic auth) in addition to the VNC password — full remote desktop control is high-value to protect.
6080 directly to the internet without TLS in front of it.VNC_PASSWORD.Source and full build instructions: see the project repository. To build locally:
docker build -t prateekrajgautam/novnc:latest .
latest — most recent buildContent type
Image
Digest
sha256:6704b6592…
Size
126 MB
Last updated
about 2 months ago
docker pull prateekrajgautam/novnc