Skip to main content

Kerbside, a SPICE VDI proxy

Kerbside is a SPICE VDI protocol proxy: a pure-Python control plane (the REST API and the daemon) that supervises a Rust SPICE proxy. It sits out the front of your cloud and provides VDI access to VMs running inside the cluster, determining what VM to proxy your traffic to based on the password you provide when connecting. Unlike layer 4 proxies that pass through unparsed traffic, Kerbside understands the SPICE protocol itself — the proxy terminates TLS, drives the SPICE link handshake, and is an enforcing SPICE application firewall, on by default.

Kerbside currently knows how to proxy console sessions for Shaken Fist, OpenStack, and oVirt. It will mostly be of interest to operators of those clouds who want to offer users rich native SPICE desktops (high resolution, multi-monitor, USB passthrough, audio) instead of HTML5-transcoded consoles. OpenStack is probably the best documented integration at the moment because there are patches to add deployment support for Kerbside to Kolla-Ansible in the kerbside-patches repository.

Kerbside is currently considered experimental: it works, but it has not yet seen large scale deployment.

Installation

pip install kerbside

This installs the Python control plane and a matching prebuilt kerbside-proxy binary wheel automatically (x86_64 and aarch64). See docs/installation.md for the packaging details, OS-level dependencies, and deployment pointers. If you would rather see it working first, demo/ brings the whole stack up under docker compose and hands you a proxied console.

Documentation

In the docs/ directory:

  • Documentation Index - What Kerbside is, the broker model, and the connection flow
  • Kerbside for oVirt - The first of the per-deployment guides: what Kerbside replaces in an oVirt deployment, and how to set it up
  • Installation - From pip install to a proxied console: what a running Kerbside needs, the compose demo, and where to go for your cloud
  • Configuration - Configuration reference, including the SPICE firewall knobs
  • Console Sources - Configuring sources.yaml for Shaken Fist, OpenStack, and oVirt
  • Proxy Architecture - Internal proxy design, state machine, and firewall
  • Database Schema - Tables, columns, and relationships
  • SPICE Protocol Documentation - Protocol fundamentals, link handshake, per-channel message formats, compression, capabilities, USB redirection, and the VD agent protocol (under docs/spice/)
  • Development - Migrations, building and packaging the Rust proxy, dependency pinning, review tracking, vendored web assets, and debugging
  • Testing - Running the test suite, CI tiers and lane mechanics, Ryll harnesses, the oVirt console probe, Tempest, and load-test images

Project reference files:

  • ARCHITECTURE.md - High-level system architecture
  • AGENTS.md - AI agent guidelines for working on this codebase
  • .claude/ - Claude Code project instructions and skills (database migrations, adding source types)

License

Apache-2.0

Release files for kerbside 0.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for kerbside 0.6.0
File Size Uploaded
kerbside-0.6.0.tar.gz 1.2 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for kerbside 0.6.0
File Interpreter ABI Platform
kerbside-0.6.0-py3-none-any.whl Python 3 none any Details

Total release size: 1.4 MB

Release files / kerbside-0.6.0.tar.gz

Download URL kerbside-0.6.0.tar.gz
Size 1.2 MB
Tags Source
SHA-256 checksum
How to use checksums
5a79e5ffa1f2f598fb0580c37b50ad92b0da444edee25ea738ea8d85629eb32d
BLAKE2b-256 checksum
How to use checksums
6440efdfc71987198e359af100b62e359fd3dc990431e54a381d597f8893e5e0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 7, 2026.

Transparency log

Release files / kerbside-0.6.0-py3-none-any.whl

Download URL kerbside-0.6.0-py3-none-any.whl
Size 214.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
390c98942c8e5e200097cd514baefdbffc5c77886f1fd51b6ce9c9d0527f955a
BLAKE2b-256 checksum
How to use checksums
1a332bbd496dbd478dd80f458466bd7cc1ddcffea819613857c0e5f51066a9dd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 7, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.6.0 This release

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.5

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page