Glinet Kvm
Operate GL.iNet KVMs (Comet GL-RM1 / GL-RM1PE) from swamp: health, screenshots, ATX power and virtual media. The firmware is a fork of PiKVM's kvmd, and three of its behaviours shape this model. The factory TLS certificate is self-signed, names CN=localhost and expired in 1979, so it cannot be validated or pinned; HTTP goes through curl and the viewer through openssl, with credentials on stdin rather than argv. The video streamer sleeps until a viewer connects, so a bare snapshot request answers 503 whether or not there is a signal; screenshot and health open a receive-only viewer session first and never send input. Without the ATX add-on board, the API still reports power 'off' for a running machine; this model reports the state as unknown and refuses to press a button wired to nothing. health flags available firmware updates, missing HDMI signal, offline USB HID, forgotten virtual media that could hijack the next boot, clock skew, and security posture (2FA off, browser root shell on, untrusted TLS). atx and msd are dry runs unless apply is true.
msd download: accept kvmd's streamed (newline-delimited) responses, so a completed download is reported as done. Verified live with the 1.7 GB Proxmox VE 9.2 ISO.
Global Arguments
| Argument | Type | Description |
|---|---|---|
| host | string | Address of the KVM: a LAN IP or a hostname that resolves from wherever |
| port | number | HTTPS port of the KVM web UI. |
| username | string | Web UI user. GL.iNet KVMs ship with a single `admin` account. |
| password | string | Web UI password. Supply a vault reference, never a literal. If two- |
| timeoutMs | number | Per-request timeout for API calls (uploads and downloads take their own). |
| Argument | Type | Description |
|---|---|---|
| checkVideo | boolean | Wake the streamer with a receive-only viewer session to test for an HDMI signal. Sends no input. |
| checkFirmware | boolean | Ask the device whether newer firmware exists (the device queries GL.iNet). |
| strictSecurity | boolean | Promote security-posture findings (2FA off, web terminal on, untrusted TLS) from info to warn. |
| maxClockSkewSeconds | number | Clock difference tolerated before a clock_skew warning. |
| Argument | Type | Description |
|---|---|---|
| ocr | boolean | Also ask kvmd to OCR the frame and store the text in screenshotMeta. |
| waitMs | number | How long to wait for the woken streamer to produce a frame. |
| Argument | Type | Description |
|---|---|---|
| action | enum | on/off are soft (power button, only if state differs); off_hard holds power; reset_hard pulses reset; click_* press a button unconditionally. |
| apply | boolean | Actually press the button. Without it, report what would happen. |
| Argument | Type | Description |
|---|---|---|
| action | enum | |
| image? | string | Image name on the KVM. Required for upload, download, connect, remove. |
| file? | string | Local path to upload (upload only). |
| url? | string | URL the KVM downloads itself (download only). Better than upload for large ISOs over a slow link. |
| cdrom | boolean | connect: present as a CD-ROM (true) or a writable flash drive (false). |
| transferTimeoutMs | number | Timeout for upload and download. |
| apply | boolean | Actually change the device. Without it, report what would happen. |
Resources
Files
First release. Verified live on two GL-RM1PE (firmware V1.9.1): health, screenshot, msd upload/connect/disconnect/remove (target saw the ISO). ATX presses and msd download are tested against a scripted kvmd only.
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned