Go back

Setup and installation of 'Browser based Ubuntu 22.04 GUI Desktop accessible via HTTPS' on GCP

This section describe how to provision and Connect to ‘Browser based Ubuntu 22.04 GUI Desktop accessible via HTTPS’ on GCP cloud platform.

  1. Open ‘Browser based Ubuntu 22.04 GUI Desktop accessible via HTTPS’ marketplace listing on GCP Marketplace.

/img/gcp/ubuntu-browser-2204/marketplace.png

  1. Click Launch.
  • It will take you to the agreement page. On this page, you can change the project from the project selector on top navigator bar as shown in the below screenshot.

  • Accept the Terms and agreements by ticking the checkbox and clicking on the AGREE button. /img/common/gcp_agreement_page.png

  • It will show you the successfully agreed popup page. Click on Deploy. /img/common/gcp_agreement_accept_page.png

  • On deployment page, give a name to your deployment.

  • Tick the existing account radio button and select your existing service account from the "Select a service account" dropdown as shown below.
  • If you don't see the service account in "Select a service account" drop down, then please follow the below steps to add one. if you can see a service account in the dropdown, skip ahead to the next step to select the region for your deployment.
  • below steps are one time only and you need appropriate IAM permissions to execute these steps. If you encounter IAM permission errors, reach out to your organization's IAM admin to execute these steps :
    1. Note Project id : First note down the project-id of the project where you are deploying our solution . Project id can be found by clicking on the project dropdown and copying id from the poped up window.

    2. Activate cloud shell by clicking the shell icon at the top right corner.
    3. In the cloud shell, run below command to switch to the project where you are deploying this solution , replace PROJECT_ID with the actual project id copied in step a.
    4. gcloud config set project "PROJECT_ID"

    5. Then run below command to create new service account, replace highlighted bold text with suitable values.
    6. gcloud iam service-accounts create "your-service-account-name" --description="service account for your-google-cloud-login-emailid " --display-name="your-service-account-name"

    7. Then run below command to associate the newly created service account with your google cloud login id, replace highlighted bold text with values provided in above steps
    8. gcloud iam service-accounts add-iam-policy-binding your-service-account-name@projectid-copied-in-step-a.iam.gserviceaccount.com --member="user:your-google-cloud-login-emailid" --role="roles/iam.serviceAccountUser"

    9. Then run below 3 commands one after the other , replace highlighted bold text with your service account name provided in previous steps.
    10. gcloud projects add-iam-policy-binding PROJECT_ID --member=serviceAccount:your-service-account-name@projectid-copied-in-step-a.iam.gserviceaccount.com --role=roles/config.agent

      gcloud projects add-iam-policy-binding PROJECT_ID --member=serviceAccount:your-service-account-name@projectid-copied-in-step-a.am.gserviceaccount.com --role=roles/compute.admin

      gcloud projects add-iam-policy-binding PROJECT_ID --member=serviceAccount:your-service-account-name@projectid-copied-in-step-a.iam.gserviceaccount.com --role=roles/iam.serviceAccountUser

    11. Once the above steps are done, wait for 60 seconds then refresh the deployment page and you should see the newly created service account in "Select a service account". Continue with the next steps below.
  • Select/Create the service account for this deployment.
  • Select a zone where you want to launch the VM(such as us-east1-)
  • Optionally change the number of cores and amount of memory. (This defaults to 1 vCPUs and 3.75 GB ram.)
  • Optionally change the boot disk type and size. (This defaults to “Standard Persistent Disk” and 20 GB respectively)
  • Optionally change the network name and subnetwork names. Be sure that whichever network you specify has ports 22 (for ssh) and 443 (for HTTPS) exposed.
  • Click Deploy when you are done. ‘Browser based Ubuntu 22.04 GUI Desktop accessible via HTTPS’ VM will begin deploying.

/img/gcp/ubuntu-browser-2204/deployed-01.png

/img/gcp/ubuntu-browser-2204/deployed-02.png

/img/gcp/ubuntu-browser-2204/deployed-03.png

  1. A summary page displays when the compute engine is successfully deployed. Click on the Instance link to go to the instance page .

  2. On the instance page, click on the “SSH” button, select “Open in browser window”.

/img/gcp/desktop-linux/desktop-linux-ssh-option.png

  1. This will open SSH window in a browser. Switch to ubuntu user and navigate to ubuntu home directory.
sudo su ubuntu
cd /home/ubuntu/

/img/gcp/rancher/switch-ubuntu-user.png

  1. Run below command to set the password for “ubuntu” user
sudo passwd ubuntu

/img/gcp/desktop-linux/desktop-linux-passwd.png

  1. Now the password for ubuntu user is set, you can connect to the VM’s desktop environment from any Browser. To do so first note the external IP of the VM from VM details page as highlighted below.

/img/gcp/desktop-linux/desktop-linux-external-ip.png

  1. Then Go to your favorite browser and enter the IP address as https://public_ip_of_vm and hit enter. Make sure to use HTTPS and not HTTP in the URL. The browser will show you SSL warning message. Click on Advance, Accept the risk and continue.

/img/gcp/kali-in-browser/https.png

  1. After accepting the ssl certification warning it will show you the below screen. Please click on Connect button.

/img/gcp/kali-in-browser/novnc-connect.png

  1. On Login screen , enter ubuntu as user name and password of ubuntu user you set in above steps.

/img/gcp/ubuntu-browser-2204/ubuntu-login-screen.png

  1. Now you are connected to out of box ‘Browser based Ubuntu 22.04 GUI Desktop’ environment.

/img/gcp/ubuntu-browser-2204/ubuntu-gui-in-browser.png

Go back