Omahub
← All plugins
K

OmaKasm

by Kiryuuki

Kasm Workspaces Launcher and Active Session Manager for Omarchy Desktop. 1-click workspace provisioning, live session streaming, and agent cluster telemetry.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
727c952
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
727c952
Reviewed
1 month ago

The plugin is a Kasm Workspaces launcher that interacts with a user-configured Kasm server via API. It stores API credentials locally with 0600 permissions and runs a Python script for API calls. No malicious behavior detected; the only minor concern is that SSL certificate verification is disabled, which could expose credentials to MITM attacks if the server is compromised, but this is a common trade-off for homelab setups.

  • SSL certificate verification is disabled (CERT_NONE), which could allow man-in-the-middle attacks if the Kasm server is not trusted.
  • API credentials are stored in plaintext in ~/.config/omarchy/kasm.json (though with 0600 permissions).
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/Kiryuuki/oma-kasm --enable
Productivity #bar #launcher #workspaces

OmaKasm: Kasm Workspaces Launcher and Session Manager for Omarchy

A keyboard-driven Kasm Workspaces launcher, active container stream monitor, and agent cluster telemetry flyout for the Omarchy Desktop Environment.

OmaKasm Preview


Features

  • Workspace Catalog and 1-Click Provisioning:
    • Search and filter across installed workspace images (Browsers, Linux Desktops, Development Tools, Security).
    • 1-click launch provisions the container session via Kasm Developer API and opens the live web stream directly in your browser.
  • Active Streaming Sessions Monitor:
    • Real-time list of running container sessions with status indicators and user assignments.
    • 1-click Resume stream and 1-click Terminate container action.
  • Agent Server and Zone Telemetry:
    • View Docker agent server status, CPU cores, memory allocation, and active container capacity across deployment zones.
  • Configurable Session Defaults:
    • Audio streaming, microphone pass-through, and bidirectional clipboard sharing preferences.
  • In-Panel Credential Manager:
    • Configure Server URL, Developer API Key, and Secret directly inside the flyout with live connection testing.

Keyboard Shortcuts

Key Action
1 Switch to Workspaces catalog tab
2 Switch to Active Sessions tab
3 Switch to Cluster and Agents tab
4 Switch to Settings tab
Up / Down or k / j Navigate workspaces or active sessions list
Enter / Space Launch selected workspace or reconnect to session
x / Delete Terminate selected container session
s / S Toggle Settings tab
r / R Trigger instant telemetry sync
Esc Clear search focus or close flyout

Configuration & API Key Setup Guide

1. Create a Developer API Key in Kasm Workspaces

  1. Open your Kasm Workspaces Admin Web UI (e.g. https://kasm.local or https://192.168.100.108).
  2. Log in as an Administrator.
  3. In the left navigation sidebar, go to Access Management -> Developer API (or API Keys).
  4. Click Add API Key (or edit your existing key).
  5. On the main key settings, ensure the Read Only toggle switch is set to OFF.
  6. In the Permissions tab, ensure the following permissions are added and active:
    • Global Admin: Full administrative access.
    • User: Standard user API actions.
    • Users Auth Session: Session creation and authentication on behalf of users.
    • Sessions Delete: Session termination and container cleanup.
    • Sessions Modify: Session parameter modifications.
    • Sessions View: Active session monitoring.
    • Users Create, Users Delete, Users Modify, Users Modify Admin, Users View: User discovery and credential validation.
  7. Copy your API Key and API Key Secret.

2. Configure OmaKasm in Omarchy Desktop

Open the plugin Settings flyout (4 or s), enter your Server URL, API Key, and Secret, then click Save and Sync Now (or save directly in ~/.config/omarchy/kasm.json):

{
  "baseUrl": "https://192.168.100.108",
  "apiKey": "YOUR_KASM_DEVELOPER_API_KEY",
  "apiSecret": "YOUR_KASM_DEVELOPER_API_SECRET",
  "defaultAudio": true,
  "defaultMicrophone": false,
  "defaultClipboard": true,
  "launchMode": "browser"
}

Persistent Profiles Support

When launching workspaces through OmaKasm, sessions are dispatched under your authenticated user ID with persistent profile mode enabled by default. If your Kasm workspace image or group policy has Persistent Profiles enabled, Kasm automatically mounts your personal persistent storage directory /home/kasm-user into the container. All browser history, downloads, bookmarks, extensions, configurations, and files are permanently preserved across session restarts.

How to Enable Persistent Profiles on Any Workspace in Kasm Admin:

  1. Per-Workspace Configuration:

    • In Kasm Admin, go to Admin -> Workspaces.
    • Edit the desired workspace (e.g. Chrome, Firefox, Ubuntu, VSCode).
    • Set Persistent Profile Path to /data/kasm_profiles/{username}/.
    • Ensure the volume mapping binds /data/kasm_profiles/{username}/ to /home/kasm-user.
    • Save changes. OmaKasm will automatically detect the profile and display the 󰋊 Profile badge.
  2. Global Group-Wide Configuration:

    • In Kasm Admin, go to Access Management -> Groups.
    • Edit your user group (e.g. Administrators or All Users).
    • In the Settings subtab, add or edit the persistent_profile_path setting and set it to /data/kasm_profiles/{username}/.
    • All workspaces launched by users in this group will automatically mount persistent profile storage.

License

Source-Available Non-Commercial License (PolyForm Noncommercial 1.0.0). Free for personal, educational, and homelab use. Commercial sale, distribution for fee, or commercial re-licensing is prohibited without author permission.