Kasmweb-based AI IDE Desktop Environment
1.1K
A fully functional, containerized Ubuntu desktop environment built on Kasmweb. This image comes pre-configured with a comprehensive suite of the latest AI-powered Integrated Development Environments (IDEs) and coding assistants, ready for immediate use.
The following AI IDEs and CLI tools are installed and ready to run:
You can deploy this environment using Docker CLI or Docker Compose.
This method is recommended for persistent storage and easier configuration.
docker-compose.yml:version: '3.8'
services:
aide:
platform: linux/amd64
image: successage/aide:latest
container_name: aide
restart: unless-stopped
ports:
- "6901:6901" # Web VNC Interface
- "2048:2048" # Reserved port for exposing internal services
environment:
- VNC_PW=pass50rd
# Proxy Configuration (adjust as needed)
- HTTPS_PROXY=http://host.docker.internal:8118
- https_proxy=http://host.docker.internal:8118
- HTTP_PROXY=
- http_proxy=
volumes:
# Map your local project directory to the container
- ./project:/home/kasm-user/project
shm_size: 512m # Required for stable IDE performance
security_opt:
- seccomp=unconfined
extra_hosts:
- "host.docker.internal:host-gateway"
privileged: true
entrypoint: ["/dockerstartup/kasm_default_profile.sh","/dockerstartup/vnc_startup.sh","/dockerstartup/kasm_startup.sh"]
command: ["--tail-log"]
working_dir: /home/kasm-user/project
docker-compose up -d
If you prefer a one-line command:
docker run -d \
--platform linux/amd64 \
--name aide \
--restart unless-stopped \
-p 6901:6901 \
-p 2048:2048 \
-e VNC_PW=pass50rd \
-e HTTPS_PROXY=http://host.docker.internal:8118 \
-e https_proxy=http://host.docker.internal:8118 \
-e HTTP_PROXY= \
-e http_proxy= \
-v "$(pwd)/project:/home/kasm-user/project" \
--shm-size 512m \
--security-opt seccomp=unconfined \
--add-host host.docker.internal:host-gateway \
--privileged \
--workdir /home/kasm-user/project \
successage/aide:latest \
/dockerstartup/kasm_default_profile.sh /dockerstartup/vnc_startup.sh /dockerstartup/kasm_startup.sh --tail-log
Once the container is running:
kasm_userpass50rd (or whatever you set in VNC_PW)docker-compose setup maps your local ./project folder to /home/kasm-user/project inside the container, ensuring your code persists even if the container is removed.This image is configured to allow connection to a proxy server running on your host machine (via host.docker.internal).
Important Note on Antigravity: Antigravity enforces strict IP address restrictions. If you require a stable proxy connection to bypass these restrictions or access specific regions, it is highly recommended to set up an automatic forwarding service.
You can use this Privoxy setup to handle the proxy forwarding efficiently.
A strict network environment is required; for example, in areas where Antigravity cannot be used, you must use a proxy with great care.
docker-compose.yml:
version: '3.8'
services:
proxy-sidecar:
image: metacubex/mihomo:latest
container_name: mihomo-sidecar
cap_add:
- NET_ADMIN
devices:
- /dev/net/tun
volumes:
- ./mihomo-config.yaml:/root/.config/mihomo/config.yaml
- /etc/localtime:/etc/localtime:ro
extra_hosts:
- "host.docker.internal:host-gateway"
restart: unless-stopped
ports:
- "2901:6901"
- "2026:2026"
- "2027:2027"
- "4096:4096"
- "2222:22"
- "3721:3721"
- "1985:1985"
- "1986:1986"
environment:
- LC_TIME=C.UTF-8
aide:
platform: linux/amd64
image: aide:latest
container_name: aide
restart: unless-stopped
environment:
- LC_TIME=C.UTF-8
- VNC_PW=pass50rd
- HTTPS_PROXY=
- https_proxy=
- HTTP_PROXY=
- http_proxy=
- NO_PROXY=localhost,127.0.0.1,172.0.0.0/8,10.0.0.0/8
network_mode: service:proxy-sidecar
depends_on:
- proxy-sidecar
volumes:
# Map your local project directory to the container
- ./project:/home/kasm-user/project
- ./app:/app
- ./userdata/.opencode:/home/kasm-user/.opencode
- ./userdata/.config/opencode:/home/kasm-user/.config/opencode
- ./userdata/.config/openspec:/home/kasm-user/.config/openspec
- ./userdata/.config/vibe-kanban:/home/kasm-user/.local/share/vibe-kanban
- ./userdata/.vibe-kanban:/home/kasm-user/.vibe-kanban
- ./userdata/.claude.json:/home/kasm-user/.claude.json
- ./userdata/.claude:/home/kasm-user/.claude
- /etc/localtime:/etc/localtime:ro
shm_size: 512m
security_opt:
- seccomp=unconfined
privileged: true
entrypoint: ["/dockerstartup/kasm_default_profile.sh","/dockerstartup/vnc_startup.sh","/dockerstartup/kasm_startup.sh"]
command: ["--tail-log"]
working_dir: /home/kasm-user/project
deploy:
resources:
limits:
memory: 24G
cpus: '4'
reservations:
memory: 2G
cpus: '0.5'
blkio_config:
device_read_bps:
- path: /dev/vda
rate: 120MB
device_write_bps:
- path: /dev/vda
rate: 100MB
device_read_iops:
- path: /dev/vda
rate: 4500
device_write_iops:
- path: /dev/vda
rate: 4000
#weight: 400
blkio_config is used to limit disk read and write operations; you can comment it out if you don't need it.
mihomo-config.yaml(Case suitable for the Chinese mainland):
log-level: info
mode: rule
tun:
enable: true
stack: system
auto-route: true
auto-detect-interface: true
dns-hijack:
- any:53
# -------------------------------------------------------------------
# 1. 新增:域名嗅探 (救命稻草)
# 当 IP 规则误判时,拆包看域名,强制纠正路由
# -------------------------------------------------------------------
sniffer:
enable: true
force-dns-mapping: true
parse-pure-ip: true
override-destination: true
sniff:
TLS:
ports: [443, 8443]
HTTP:
ports: [80, 8080]
dns:
enable: true
listen: 0.0.0.0:53
enhanced-mode: fake-ip
fake-ip-range: 198.18.0.1/16
# 默认 DNS (电信)
default-nameserver:
- 223.5.5.5
- 223.6.6.6
- 119.29.29.29
# 策略:Google/国外大站 -> 强制 DoH
nameserver-policy:
"domain-keyword:google,youtube,gmail,telegram,twitter,facebook,docker":
- https://8.8.8.8/dns-query
- https://1.1.1.1/dns-query
"domain-suffix:cn,baidu.com":
- 119.29.29.29
nameserver:
- https://dns.alidns.com/dns-query
- https://doh.pub/dns-query
fallback:
- https://8.8.8.8/dns-query
- https://1.1.1.1/dns-query
fallback-filter:
geoip: true
geoip-code: CN
ip-cidr:
- 240.0.0.0/4
proxies:
- name: "HOST_PROXY"
type: socks5
# Mac 专用
server: host.docker.internal
port: 8011
proxy-groups:
- name: "PROXY"
type: select
proxies:
- "HOST_PROXY"
rules:
# 1. 屏蔽 QUIC (UDP 443) - 必须保留
- AND,((NETWORK,UDP),(DST-PORT,443)),REJECT
# 2. 关键词强制代理 (配合 Sniffer 生效)
- DOMAIN-KEYWORD,google,PROXY
- DOMAIN-KEYWORD,gmail,PROXY
- DOMAIN-KEYWORD,youtube,PROXY
- DOMAIN-KEYWORD,facebook,PROXY
- DOMAIN-KEYWORD,twitter,PROXY
- DOMAIN-KEYWORD,telegram,PROXY
- DOMAIN-SUFFIX,sg,PROXY
- DOMAIN-SUFFIX,docker,PROXY
# 3. 局域网直连
- GEOIP,PRIVATE,DIRECT,no-resolve
- DOMAIN-SUFFIX,cn,DIRECT
# 4. 国内 IP 直连
- GEOIP,CN,DIRECT
# 5. 兜底
- MATCH,PROXY
Proxies should be configured according to your specific situation.
Content type
Image
Digest
sha256:c590e6993…
Size
6.4 GB
Last updated
9 months ago
docker pull successage/aide