| Device | Profile | IP | Online | Config | Last seen | chromium-kiosk | Updates | Agent |
|---|
Device
Status
Delivered at the kiosk's next check-in (every 10 minutes); dropped if not picked up within 15.
Versions
Reported at each check-in. Pin kiosk app versions freezes chromium-kiosk and qiosk at the versions this kiosk runs (after you tested them) in its profile, or in its own Updates override if it has one. Pinned kiosks are not upgraded past those versions. The repositories keep only their latest version, so a kiosk installed later may get a newer one; it is then flagged as ≠ pinned.
Install on an existing Debian / Raspberry Pi
Runs the same setup script as the network install: chromium-kiosk's documented apt install, then the KioskManager agent, and reboots into the kiosk. Run it as a user with sudo. Generating a new command invalidates the previous one.
Configuration
Each section comes from the device's profile unless overridden here. Saving bumps the device's config revision; an offline kiosk picks it up when it reconnects.
A profile is a shared set of kiosk, network, Wi-Fi and system settings. Every device uses one profile and can override whole sections. Changing a profile updates all its devices.
npm run build (or npm run build:agent).
1 · Boot stick
A small iPXE image that connects to this server over HTTPS. Its menu boots from the local disk by default, so the stick can stay plugged in. Install kiosk asks for confirmation, then erases the internal disk and installs Debian with chromium-kiosk and the agent, unattended. The PC needs UEFI boot (Secure Boot can stay on) and a network cable.
sudo dd if=kiosk-boot-….img of=/dev/sdX bs=4M conv=fsync.
—
Already have an iPXE stick?
Any iPXE 2.x release USB stick (for example ipxe-x86_64-sb.usb) works: replace the autoexec.ipxe in its root with this file.
Do the same after rotating the enroll key or changing the public URL. There is no need to re-flash.
—
Rotating stops every existing stick until it is re-flashed or gets the new autoexec.ipxe.
2 · Installs in progress
A netbooted PC appears here as kiosk-<mac> with the default profile. It moves to in sync once the install finishes, the PC reboots and its agent checks in. Rename it and pick its profile on the Devices tab.
Install settings
Apply to new installs of Debian 13. Hostname and timezone come from the device and its profile. Everything else is set later through profiles.
The maintenance login on every kiosk, on the text console (Ctrl+Alt+F2) and over SSH. There is no other account. Use it when a kiosk's agent or network is broken. Changing it affects new installs only.
Server
Changes apply immediately, except the listen host/port, which need a restart.