Skip to content

Use the Linux browser and take control

workflowobservedEvidence reviewed 2026-10-06

Chromium runs on Shipyard. Playwright controls it through MCP; noVNC streams the same display to the human. This saves local compute while preserving manual takeover.

In Orca open a browser tab through Shipyard at:

http://127.0.0.1:6080/vnc.html?autoconnect=true&resize=scale&reconnect=true

For a separate Mac browser, keep this tunnel running in a Mac terminal:

Terminal window
ssh -N -o ExitOnForwardFailure=yes -o ServerAliveInterval=30 -L 127.0.0.1:6080:127.0.0.1:6080 shipyard

Then open the same viewer URL. Check for an existing forward first; only one process can own the Mac port. Inside the Linux browser the dashboard address is http://localhost:3003.

Pause the agent before interacting, then tell it to resume with the existing session. This is a cooperative handoff; there is no automatic input lock. Coordinate between agents too. Use the noVNC clipboard panel when cross-machine paste fails. Downloads remain on Shipyard. Do not log out or erase the shared profile to fix a task.

Both Shipyard agent configurations point to http://localhost:8931/mcp. Use localhost exactly because MCP validates the Host header. Existing clients may need reconnect after configuration changes. CDP is on loopback 9222; the viewer is 6080 and VNC is 5901.

Terminal window
~/dev-environment/scripts/browser-session.sh status
~/dev-environment/scripts/browser-session.sh start
# Stop only after coordinating with users of the shared session:
~/dev-environment/scripts/browser-session.sh stop

Start is idempotent. Stop preserves the profile. Browser startup after reboot is manual. Normal password login survived a recorded restart, but Auth0 may request consent and sessions can expire. Unattended authentication is not established.

Chromium runs sandboxed using an executable-specific AppArmor exception for user namespaces. The pinned executable path in browser-session.sh and browser-sandbox.sh must change together during upgrades. Do not use --no-sandbox or weaken the system-wide restriction as a workaround.

Profile: ~/dev-environment/private/playwright-spot; private logs: ~/dev-environment/logs/browser. Do not copy either into this repository. Streaming video/audio, GPU acceleration and passkey integration remain unverified. Browser recovery.