Skip to content

Desktop app

LabPod Connect is a lightweight native connection manager and launcher. It opens LabPod, DQueHPC, or another web service in a native window, so you do not have to remember http://<ip>:<port> URLs. A LabPod connection loads the same LabPod web app you would reach in a browser, not a separate interface.

  • Saved connections - register each LabPod workstation, DQueHPC service, or general web service you access. The list persists across launches and labels each connection as LabPod, DQueHPC, or Web.
  • One-click connect - choose a connection in the left sidebar to load it in the main pane.
  • Reorder connections - drag a connection card to a new position in the sidebar list.
  • Reload the pane - recover a selected page after its service restarts without disconnecting or recreating the connection.
  • Open in a browser - use a saved connection’s menu to open its landing page in your default browser, connecting its SSH tunnel first when needed.
  • Test - check that the selected service is reachable before connecting.

For a LabPod connection, logging in, creating workspaces, opening Jupyter, and using the terminal remain the same web UI running inside the pane. Workspace applications stay in that workstation pane. A DQueHPC connection keeps its platform and reported gateway origins in the pane. A Web connection loads the saved service without enabling either product’s workspace-gateway navigation.

The app uses the system’s built-in web renderer (WebView2 on Windows, WKWebView on macOS, WebKitGTK on Linux). Binaries are unsigned at this time.

LabPod Connect is versioned and released independently from the LabPod server. Download the latest desktop bundles from the LabPod Connect releases page.

LabPod Connect updates are separate from LabPod server updates. You do not need a LabPod server root or admin account to update the desktop app. If Connect is installed in a protected location, your operating system may request local administrator approval during installation.

  1. Open Settings in the main workstation window.
  2. Under Software update, click Check now. Connect shows the current version, the latest available version, and when it last checked.
  3. If a newer Connect version is available, review the current and latest versions and click Update and restart.
  4. Confirm the update. Connect downloads the platform package, verifies its release signature, then closes its windows and SSH tunnels, installs the update, and restarts. Progress remains visible during each step. On a protected installation, approve the operating system’s administrator prompt if one appears.

Workspaces run on the LabPod server, so they continue running while Connect updates. Reopen Connect and reconnect when the update finishes. If a check or install fails, use Release page to review or download the release manually.

If the updater is not included in a build, such as a manual local build, Settings displays an explanation and a Release page button for downloading a published build manually.

Connect checks only when you click Check now; it does not perform silent background checks or install an update without confirmation. Development builds cannot install published updates.

Each connection card shows a LabPod, DQueHPC, or Web badge. Open its overflow menu for these actions:

  • Open in default browser opens a direct URL immediately. For an SSH connection, Connect first establishes the tunnel and then opens its primary local URL.
  • Edit changes the saved connection. Disconnect a running SSH tunnel before editing it.
  • Test connection checks the service without replacing the saved LabPod, DQueHPC, or Web profile.
  • Delete removes the saved connection and closes its SSH tunnel after you confirm.

If the selected page gets stuck after its service restarts, use Reload page in the expanded sidebar. The collapsed rail carries the same control as a circular-arrow button whose tooltip reads Reload the page in the right pane. If Settings is covering the right pane, reloading brings the workstation pane back to the front. Selecting a connection or using the collapsed rail’s current workspace detail and files shortcuts also brings that pane forward.

The default browser has a separate login session from the embedded pane, so it may ask you to sign in again. Connect’s saved self-signed-certificate fingerprint is also not installed in the browser; the browser can therefore show its own certificate warning.

  1. Click + (or Add) in the sidebar.
  2. Enter a label, then choose Service:
    • Auto tests only the port you enter. If the port is blank, it tries the known LabPod (24680) and DQueHPC (13570) defaults. A generic web service on port 80 is not detected from a blank port; choose Web service or enter its port. If both product ports or neither answer, enter the port and choose the profile yourself.
    • LabPod defaults to port 24680 and keeps the adjacent workspace-gateway port paired with it.
    • DQueHPC defaults to port 13570 and uses the platform and gateway topology reported by the service.
    • Web service defaults to port 80 and uses only the ports you configure.
  3. Enter the service IP or hostname under Host. You can also paste a complete HTTP or HTTPS URL, including a base path, such as https://service.example.org/tools.
  4. Click Test to verify the service and review what Connect detected.
  5. Click Save.

Choose the saved connection to load it. A LabPod profile opens the LabPod web app, a DQueHPC profile opens its platform and verified gateway destinations, and a Web profile opens only the configured service origin.

  1. For LabPod or DQueHPC, open http://<host>:<port>/api/version in a browser on the same computer. A LabPod server returns JSON with exact name: "labpod" and a non-empty version value. A DQueHPC server returns exact name: "dque", a non-empty version, a nonzero platform_port, gateway_port equal to the platform port plus one, and an HTTP or HTTPS origin-only gateway_origin. An incomplete identity is treated as a Web service, so open its configured root URL instead.
  2. Confirm the Port field contains the configured service port. LabPod defaults to 24680, DQueHPC defaults to 13570, and Web service defaults to 80. Under Auto, a blank port tries only the two product defaults above rather than the standard web port. Under a profile you chose yourself, a blank port still means the standard HTTP port 80 or HTTPS port 443, which is what a reverse-proxied deployment uses.
  3. On macOS 15 or later, open System Settings → Privacy & Security → Local Network and enable LabPod Connect, then retry. Grant the prompt when a newly installed version first contacts a LAN workstation.
  4. Diagnose the installed /Applications/LabPod Connect.app, not a separate local development build. macOS can track local builds and downloaded unsigned copies as different network-permission identities. Avoid keeping multiple copies open while checking the permission.

Test shows the complete native connection error. On Windows and Linux there is no equivalent per-app LAN permission; check the address, routing or VPN, firewall, and server listener instead.

The app supports two ways to reach a service that is not on your local network:

If you can SSH to the workstation, the app can open a tunnel for you:

  1. Click Add, choose a service profile, then click Use an SSH tunnel instead.
  2. Enter the SSH hostname, port, and username. Choose whether the forwarded web service uses HTTP or HTTPS when you select a profile yourself.
  3. Review the port forwards. LabPod and DQueHPC profiles forward their primary port and adjacent workspace-gateway port as a pair. DQueHPC defaults its primary remote service to 13570 and verifies the probed topology before opening the tunnel. A Web profile forwards only the rules you list and defaults its primary remote service to port 80.
  4. For a LabPod, DQueHPC, or Web service profile, click Test, then Save and Connect. Every local forwarded port must be free.
  5. Your SSH host key is verified using trust-on-first-use (TOFU) and stored in your ~/.ssh/known_hosts. A changed key blocks the connection until you explicitly re-verify it.

Auto detection over SSH requires Connect’s key to already be authorized on that SSH host. For a first-time SSH connection, choose the known LabPod, DQueHPC, or Web service profile and web port, then test or connect once to authorize the key. You can edit or add a connection with Auto and test its port after that authorization succeeds; Auto cannot identify an unknown service before it can establish the authenticated tunnel.

Your private key is generated locally per machine and never leaves your device. On first connect, authorize the key once with the account password, which Connect discards immediately, or use the manual key command. An optional passphrase protects the key and is stored in the OS keyring.

If the SSH host requires an expired account password to be changed interactively, Connect shows Change the account password from a terminal first and the exact ssh command to run. Run that command in a terminal, choose the new password when prompted, and then authorize Connect again with the new password. Installing the key manually does not bypass the required password change or restore port forwarding.

If your server is configured with a self-signed HTTPS certificate:

  1. Use an https:// URL when adding the server.
  2. The app pins the certificate’s SHA-256 fingerprint on first connection (trust-on-first-use).
  3. Subsequent connections verify the fingerprint matches. If it changes (e.g. the certificate was renewed), the app warns you and you must re-pin explicitly.
  4. For a LabPod server, get the fingerprint your admin configured with sudo labpod admin tls-fingerprint. For another web service, ask its operator for the fingerprint.

If you clear a saved HTTPS pin on Linux, restart LabPod Connect before you contact that server again. WebKit keeps a previous certificate exception until the application exits; the restart makes the next connection verify and pin the certificate it receives.

The connection list is stored locally on your machine at:

PlatformPath
Windows%APPDATA%\com.labpod.connect\connections.json
macOS~/Library/Application Support/com.labpod.connect/connections.json
Linux~/.config/com.labpod.connect/connections.json

Connect commits connection changes only after it saves the updated file successfully. If a save or delete cannot be written, the previous connection data stays active; a failed delete also leaves a running SSH tunnel connected.

If an older Connect build finds connection data written by a newer, incompatible version, it asks you to update Connect and leaves the file untouched. Do not delete the file to recover from this message, because it can contain newer connection and security settings.

Under Settings → Appearance, choose System (the default, follows your OS setting live), Light, or Dark for LabPod Connect’s own sidebar, Settings, and local status pages. This only affects Connect’s own interface; a LabPod or DQueHPC web app loaded in the workstation pane keeps its own styling.